Intelligence Reporting and Dissemination IMG Flashcards
Define Threat Intelligence Reports
Threat intelligence reports are prose documents that include details about various types of attacks, TTPs, threat actors, systems, and information being targeted. These reports include information related to threats that have been collected, aggregated, transformed, analyzed, and enriched to provide actionable contextual intelligence for organizations’ decision-making processes
What are the types of threat reports ?
- Threat Report Analysis Report
- Attack centric
- About -> threat group, location, intention, motivation
- What they use/detection -> Tactics, tools, Indicators
- About target -> Industry, location, Vulnerability
- Impact ->
- Analytics -> Any corelations, predictions
- Attack centric
- Threat Landscape Report
- Business
- Risk
- Industry
- Organization
Generating Concise Reports
Threat Intelligence Report Template
Overview of Dissemination
Preferences for Dissemination
Benefits of Sharing Intelligence
Building Blocks for Threat Intelligence Sharing
Establish Information Sharing Rules
Information Sharing Model
Information Exchange Types
TI Exchange Architectures
Intelligence Sharing Best Practices
Why Sharing Communities are Formed?
Threat intelligence sharing community is a network of organizations that exchange intelligence between them.
Sharing communities may be a public–private partnership or industry-to-industry partnership.
The threat intelligence sharing communities are formed for various reasons:
- Enhanced depth and breadth of insight
- Assurance of confidentiality
- Common interests
- Awareness of the bigger picture
Factors to Be Considered When Joining a Community
Just read from the book
Engage in Ongoing Communication
Consume and Respond to Security Alerts