1.5: Threat Actors and Vectors Flashcards
CVE
Common Vulnerabilities and Exposures
Community managed lists of vulnerabilities.
Sponsored by DHS and CISA(Cybersecurity and Infrastructure Security Agency)
NVD
US National Vulnerability Database
summary of CVE’s, Also sponsored by CISA and DHS.
AIS
Automated Indicator Sharing
Way to share important threat data freely.
STIX
Structured Threat Info eXpression
Describes cyber threat info, includes abilities, capabilities, and response info.
TAXII
Trusted Automated eXchange of Indicator Info
Securely shares STIX data.`
IOC
Indicators of Compromise
event that indicates an intrusion.
ex: unusual amount of network activity, uncommon login patterns.
TTP
Tactics, techniques and procedures
What are adversaries doing and how are they doing it.