Intelligence Reporting and Dissemination IMG Flashcards

1
Q

Define Threat Intelligence Reports

A

Threat intelligence reports are prose documents that include details about various types of attacks, TTPs, threat actors, systems, and information being targeted. These reports include information related to threats that have been collected, aggregated, transformed, analyzed, and enriched to provide actionable contextual intelligence for organizations’ decision-making processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the types of threat reports ?

A
  1. Threat Report Analysis Report
    1. Attack centric
      1. About -> threat group, location, intention, motivation
      2. What they use/detection -> Tactics, tools, Indicators
      3. About target -> Industry, location, Vulnerability
      4. Impact ->
      5. Analytics -> Any corelations, predictions
  2. Threat Landscape Report
    1. Business
    2. Risk
    3. Industry
    4. Organization
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Generating Concise Reports

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Threat Intelligence Report Template

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Overview of Dissemination

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Preferences for Dissemination

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Benefits of Sharing Intelligence

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Building Blocks for Threat Intelligence Sharing

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Establish Information Sharing Rules

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Information Sharing Model

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Information Exchange Types

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

TI Exchange Architectures

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Intelligence Sharing Best Practices

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Why Sharing Communities are Formed?

A

Threat intelligence sharing community is a network of organizations that exchange intelligence between them.

Sharing communities may be a public–private partnership or industry-to-industry partnership.

The threat intelligence sharing communities are formed for various reasons:

  1. Enhanced depth and breadth of insight
  2. Assurance of confidentiality
  3. Common interests
  4. Awareness of the bigger picture
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Factors to Be Considered When Joining a Community

A

Just read from the book

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Engage in Ongoing Communication

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Consume and Respond to Security Alerts

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Consume and Use Indicators

A
19
Q

Produce and Publish Indicators

A
20
Q

External Intelligence Sharing

A

Read from the book

21
Q

Establishing Trust

A
22
Q

Organizational Trust Models

A
23
Q

Sharing Strategic Threat Intelligence

A
24
Q

Sharing Tactical Threat Intelligence

A
25
Q

Sharing Operational Threat Intelligence

A
26
Q

Sharing Technical Threat Intelligence

A
27
Q

Sharing Intelligence Using YARA Rules

A
28
Q

IT-ISAC

A
29
Q

Forms of Delivery

A
30
Q

Machine-Readable Threat Intelligence

A
31
Q

Standards and Formats for Sharing Threat Intelligence

A
32
Q

Standards and Formats for Sharing Threat Intelligence (Cont’d)

MITRE Standards

A
33
Q

Standards and Formats for Sharing Threat Intelligence (Cont’d)

Managed Incident Lightweight Exchange (MILE)

A
34
Q

Standards and Formats for Sharing Threat Intelligence (Cont’d)

VERIS, IDMEF

A
35
Q

CISPA

A
36
Q

Cybersecurity Information Sharing Act (CISA)

A
37
Q

Integrating Threat Intelligence

A
38
Q

How to Integrate CTI into the Environment

A
39
Q

Acting on the Gathered Intelligence

A
40
Q

Tactical Intelligence Supports IT Operations: Blocking, Patching, and Triage

A
41
Q

Operational Intelligence Supports Incident Response: Fast Reaction and Remediation

A

read from the book

42
Q

Strategic Intelligence Supports Management: Strategic Investment and Communications

A

read from the book

43
Q
A