THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Thursday, September 28, 2023
Tactical Threat Intelligence, Technical Threat Intelligence, and Operational Threat Intelligence are some of the different types of Threat Intelligence.
FREMONT, CA: In order to better understand past, current, and future threats, threat intelligence involves collecting, processing, and analyzing data about malicious actors' motives, targets, and behaviors. Evidence-based knowledge about threat actors includes:
● Context, including industry verticals, device types, and geographic regions
● Insights into the likelihood or potential impacts
● Advanced persistent threats are identified using indicators of compromise (IoCs)
● Current or new threats, such as ransomware variants or vulnerabilities reported recently
● Attack mechanisms used by attackers
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Threat Intelligence Types: How They Differ
Technical Threat Intelligence: Open-source intelligence feeds provide security teams with technical threat intelligence. A security team uses technical threat intelligence to monitor for new threats or investigate security incidents.
Additional examples of technical threat intelligence include:
● Malicious actors' attack vectors
● Domains of command and control (C&C)
● Exploitation of vulnerabilities
● Logs of the info stealer
● Data on Common Vulnerabilities and Exposures (CVE)
● Technical threat intelligence is used by security teams to:
● Identify threat actors who bypass detections by conducting proactive threat-hunting
● To investigate security alerts.
● Identify forensic evidence
Tactical Threat Intelligence: Tactical threat intelligence involves identifying the strategies, techniques, and procedures (TTPs) utilized by malicious actors to compromise an organization's IT environment. By gaining visibility into the organization's attack surface, including information about compromised credentials or infected devices, tactical threat intelligence is used by security operations centers (SOCs), IT managers, network operations centers (NOCs), and other senior IT professionals to prevent cyberattacks.
Here are some examples of tactical threat intelligence:
● Blacklists of URLs and IP addresses
● Trends and signatures of malware
● A ransomware attack
● Patterns of network traffic
● Scams involving phishing
● Tactical threat intelligence is used by technical professionals to:
● Ensure that their security technologies and processes are up to date
● Tools for improving security should be fine-tuned
● Check their security controls for gaps
Operational Threat Intelligence: Security teams use operational threat intelligence to prevent or proactively detect attacks by gathering actionable information about threats' nature, motive, timing, and methods. Because operational threat intelligence focuses on human elements rather than technical elements, open-source feeds are rare, posing challenges to cyber attack incident response teams, malware analysts, network defense teams, host analysts, and security managers.
● Sources of operational threat intelligence include:
● On the clear and dark web, there are chat forums
● Malicious actors' social media accounts
● The clear and dark web forums
● Operational threat intelligence is used by security professionals to:
● Respond to planned attacks or prevent them
● For their detection alerts, create rules or signatures
● As part of vulnerability and patch management, prioritizing the installation of security updates.
More in News