Intelligence Reporting and Dissemination IMG Flashcards

1
Q

Define Threat Intelligence Reports

A

Threat intelligence reports are prose documents that include details about various types of attacks, TTPs, threat actors, systems, and information being targeted. These reports include information related to threats that have been collected, aggregated, transformed, analyzed, and enriched to provide actionable contextual intelligence for organizations’ decision-making processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the types of threat reports ?

A
  1. Threat Report Analysis Report
    1. Attack centric
      1. About -> threat group, location, intention, motivation
      2. What they use/detection -> Tactics, tools, Indicators
      3. About target -> Industry, location, Vulnerability
      4. Impact ->
      5. Analytics -> Any corelations, predictions
  2. Threat Landscape Report
    1. Business
    2. Risk
    3. Industry
    4. Organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Generating Concise Reports

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Threat Intelligence Report Template

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Overview of Dissemination

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Preferences for Dissemination

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Benefits of Sharing Intelligence

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Building Blocks for Threat Intelligence Sharing

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Establish Information Sharing Rules

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Information Sharing Model

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Information Exchange Types

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

TI Exchange Architectures

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Intelligence Sharing Best Practices

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Why Sharing Communities are Formed?

A

Threat intelligence sharing community is a network of organizations that exchange intelligence between them.

Sharing communities may be a public–private partnership or industry-to-industry partnership.

The threat intelligence sharing communities are formed for various reasons:

  1. Enhanced depth and breadth of insight
  2. Assurance of confidentiality
  3. Common interests
  4. Awareness of the bigger picture
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Factors to Be Considered When Joining a Community

A

Just read from the book

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Engage in Ongoing Communication

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Consume and Respond to Security Alerts

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Consume and Use Indicators

19
Q

Produce and Publish Indicators

20
Q

External Intelligence Sharing

A

Read from the book

21
Q

Establishing Trust

22
Q

Organizational Trust Models

23
Q

Sharing Strategic Threat Intelligence

24
Q

Sharing Tactical Threat Intelligence

25
Sharing Operational Threat Intelligence
26
Sharing Technical Threat Intelligence
27
Sharing Intelligence Using YARA Rules
28
IT-ISAC
29
Forms of Delivery
30
Machine-Readable Threat Intelligence
31
Standards and Formats for Sharing Threat Intelligence
32
Standards and Formats for Sharing Threat Intelligence (Cont’d) MITRE Standards
33
Standards and Formats for Sharing Threat Intelligence (Cont’d) Managed Incident Lightweight Exchange (MILE)
34
Standards and Formats for Sharing Threat Intelligence (Cont’d) VERIS, IDMEF
35
CISPA
36
Cybersecurity Information Sharing Act (CISA)
37
Integrating Threat Intelligence
38
How to Integrate CTI into the Environment
39
Acting on the Gathered Intelligence
40
Tactical Intelligence Supports IT Operations: Blocking, Patching, and Triage
41
Operational Intelligence Supports Incident Response: Fast Reaction and Remediation
read from the book
42
Strategic Intelligence Supports Management: Strategic Investment and Communications
read from the book
43