Key Concepts- Appendix A Flashcards
Types of CTI
Strategic
Informs senior decision-makers of changes in the threat landscape
Operational - (Dark Web chatter)
Details of impending operations against an organisation
Tactical
IoCs and TTPs used by threat actors
Intelligence Sources
IoCs
Social Media
HUMINT
Dark Web
Client data (logs)
Geopolitics
Info-sharing platforms
Calculate Risk
Threat and Risk
Risk= Vulnerability X Threat X Impact
What is an organisation tested on in an intelligence-led engagement?
Ability to prevent, detect and respond to realistic threats
Diamond Model
Adversary, Capabilities, Infrastructure, Victim
Relationship axis of the Diamond Model?
Socio-political between adversary and victim
Technology between infrastructure and capabilities
Principles of Intelligence
Centralised
Reporting
Objective
Systematic
Sharing
Continuous
Accessible
Timely
Cyber Kill Chain
Reconnaissance
Weaponisation
Delivery
Exploitation
Installation
Command and Control
Actions on Objectives
F3EAD cycle
Find, Fix, Finish, Exploit, Analyse and Disseminate
Intelligence Preparation of the Battlefield (5) SCDMC
Identify scope of required information
collection
Decisions trees
data management
identify courses of action