Threat Intelligence Flashcards
What are the 3 forms of threat intelligence?
Tactical = technical identifiers, signatures, tools that can indicate IOCs ( AV, IPS,LOG Files)
Operational = how threat actors behave, Tactical Threat and Procedures (TTPs)
Strategic = high-level threat information. News feed. Staying up to date
What are OSINT?
Open source intelligence - solution open to all.
We have to be aware of the validity of the info
What is a closed-source intelligence?
Offered by various organizations for a fee.
What is an vulnerability?
A weakness in software that allows attackers access.
What does CVE and NVD stand form?
Common Vulnerabilities and Exposures. (CVE)
National Vulnerability Database
What are public/private information centers?
Information sharing and analyst center or organization (ISAC,ISAO). These facilitate the exchange of data between commercial and governmental entities.
What might be a good reason to search the Dark Web?
If you are researching for any potential data breaches. If you find it then you can then try to mitigate the problem.
What is STIX?
Structured Threat information eXpression.
A standardized way of representing threat intelligence. Its the format that the information is presented.
It is a data structure or a schema. It uses JASON
What is TAXII?
Trusted Automated eXchange of Indicator Information.
A protocol used to exchange STIX data over HTTPS. It is a transportation used to send STIX data.