The Underdog of Cybersecurity: Uncovering Hidden Value in Threat Intelligence

Threat Intelligence (TI) is a knowledgebase of tactical information about threat actors, including IP addresses, domains, URLs, and filenames, some of which may be time-sensitive. Used correctly, TI supports SIEM correlations, threat hunting, reporting, situational dashboards, and proactive planning, though it is not perfect and should be verified. #CozyBear #APT32

Keypoints

  • TI is a knowledgebase of tactical information about threat actors, including IP addresses, domain names, URLs, and filenames, with potential time-sensitivity.
  • TTPs, IOCs and APTs are key TI concepts: TTPs describe methods used; IOCs are indicators; APTs are notable threat groups.
  • TI can be used in SIEM correlations to trigger alerts when logs match TI indicators.
  • Threat hunting often involves comparing security logs with TI to identify known bad actors.
  • TI supports reporting and situational awareness dashboards to provide broader perspectives on suspicious activity.
  • TI data quality varies; attackers may reuse IPs, making TI hit-or-miss at times.
  • Free TI sources may be less well-maintained than paid sources, and validation is important; always verify TI findings.

MITRE Techniques

  • [T1566] Phishing – β€œFor example, if a state-sponsored Russian hacking group is known to perform phishing attacks followed by ransomware and only attack government institutions, that group of information may be considered a TTP.”
  • [T1583] Acquire Infrastructure – β€œIP address is known to be associated with ATT&CK’s threat actor group APT32, then that information can be included in the TI results.”

Indicators of Compromise

  • [IP Address] TI-related indicators used in monitoring – 203.0.113.5, 198.51.100.7, and 2 more IPs
  • [Domain] Domains that may be associated with TI indicators – malicious.example.com, bad.example.org, and 1 more domain
  • [URL] URLs referenced or used as indicators – https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-underdog-of-cybersecurity-uncovering-hidden-value-in-threat-intelligence/, https://github.com/SpiderLabs/zpminternational, and 0 more URLs
  • [File Name] Filenames that appear as indicators – Image 1 Microsoft Sentinel Threat Intelligence Dashboard. Courtesy Microsoft.jpg, OTSMD.jpg, and 2 more filenames

Read more: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-underdog-of-cybersecurity-uncovering-hidden-value-in-threat-intelligence/