Cyber Threats in ESM Flashcards
What is Threat Intelligence?
Threat intelligence is data that is collected, processed, and analyzed to understand a threat actor’s motives, targets, and attack behaviors.
https://www.crowdstrike.com/cybersecurity-101/threat-intelligence/
What is STIX, TAXII and CybOX?
These are different types of data exchange formats to share cybersecurity situational awareness, real time network defense and sofisticated threat analysis.
What TAXII stands for?
Trusted Automated Exchange of Indicator Information (TAXII) is a set of specifications for exchanging cyberthreat information, such as STIX, to help organizations share information with their partners.
What STIX stands for?
Structured Threat Information Expression (STIX) is a language for having a standarized communication for the representation of cyberthreat information. The STIX language has a number of constructs or components, such as Indicator, Exploit Target, Threat Actor, and many more.
What CybOX stands for?
CybOX provides a common structure for representing cyber observables across and among the operational areas of cybersecurity. Cyber observables can be dynamic events or stateful properties. Examples can be, email messages that are received from a specific address, a network connection that is established toward a specific address, the MD5 hash of a file, a registry key, etc.
Mention at least 3 types of indicators that are supported in ESM
These are the supported indicators in ESM
* Indicator Type Watchlist Type
* Email Address
* File Name, File Path
* (Flows) IPv4, IPv6
* (Flows) MAC Address
* Fully Qualified Domain Name
* IPv4, IPv6
* MAC Address
* MD5 Hash
* SHA1 Hash
* Subject
* URL
* Username
* Windows Registry Key
* Windows Registry Value
How do you manually add a Cyber Threat Feed on ESM?
- Click System Properties
- Cyber Threat Feed
- Add
- Create name of feed
- Select Manual Upload
- Set indicator type to append to watchlist (optional)
- Select type of events or flows and how far back this data is analyzed
- Click finish
- Click Upload
- Finally select STIX file
What is a Content Pack on a SIEM?
It’s group of contained use-case driven correlation rules, alarms, views, reports, variables, and watchlists to address specific malware or threat activity.