Тёмный

Threat Intelligence Naming Conventions: Threat Actors, & Other Ways of Tracking Threats 

SANS Digital Forensics and Incident Response
Подписаться 71 тыс.
Просмотров 12 тыс.
50% 1

Cyber Threat Intelligence (CTI) analysts must have ways of clustering adversary intrusions to find patterns and make meaningful recommendations to defenders. Incident responders and security personnel must be able to simply interpret those recommendations for actionable results. And yet the ways the community clusters activity and assigns names to it can be extremely confusing and seems inconsistent. Is APT A the same group as FANCY SQUIRREL? If not why not? And does it matter? What is a Threat Group? And how is that different than an Activity Group? Or a Campaign?
This webcast presents concepts to consider when clustering intrusions and making assessments on adversary activity. It also highlights some unanswered questions in CTI for future exploration and some potentially problematic areas for analysts.
Speaker Bio
Robert M. Lee
Robert M. Lee is the CEO and Founder of the industrial (ICS/IIoT) cybersecurity company Dragos, Inc. He is also a non-resident National Cybersecurity Fellow at New America focusing on policy issues relating to the cybersecurity of critical infrastructure. For his research and focus areas, Robert was named one of the Passcode's Influencers, awarded EnergySec's Cyber Security Professional of the Year (2015), and inducted into Forbes' 30 under 30 for Enterprise Technology (2016).
A passionate educator, Robert is the course author of SANS ICS515 - "ICS Active Defense and Incident Response" with its accompanying GIAC certification GRID and the lead-author of SANS FOR578 - "Cyber Threat Intelligence" sans.org/FOR578 with its accompanying GIAC GCTI certification. He may be found on Twitter @RobertMLee

Наука

Опубликовано:

 

2 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 2   
@vikrantvijit1436
@vikrantvijit1436 2 года назад
Thanks a lot for great deeper insights on THREAT Intelligences Landscaping Surfaces.
@SharkFishSF
@SharkFishSF 2 года назад
Bro are you professionally in this field? What work do you do? This channel is very in-depth
Далее
СПРАВКА ДЛЯ УНИВЕРА
00:44
Просмотров 232 тыс.
The Cycle of Cyber Threat Intelligence
1:00:27
Просмотров 111 тыс.
Investigating WMI Attacks
1:00:43
Просмотров 26 тыс.
Introducing the New SANS DFIR “Hunt Evil“ Poster
1:01:27