Threat intelligence

From HandWiki
Revision as of 17:19, 6 February 2024 by Importwiki (talk | contribs) (fixing)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Threat intelligence is the "cyclical practice" of planning, collecting, processing, analyzing and disseminating information that poses a threat to applications and systems. Threat intelligence collects information in real-time to showcase the threat landscape for identifying threats to a computer, application or network. This information is gathered from a number of resources and compiled into a single database enabling visibility into vulnerabilities and exploits actively being used on the internet (in the wild) by threat actors. Threat intelligence is not to be confused with vulnerability management.

Platforms exist that enable the automation of threat intelligence. These platforms are commonly referred to as "TIPs" or Threat Intelligence Platforms. Security analysts utilize these platforms for their collection of data and automation.

A threat intelligence platform is typically used by Security Operations Center Teams (SOC) for day to day threat response and events as they occur. Generalized Threat Intelligence teams use the platform to make educated predictions based on actors, campaigns, industry targets as well as platform (network, application, hardware) targets. Management and Executive teams use the platform for reporting and share data at high levels to better understand their threat posture.

A TIP is a packaged product that obtains information from multiple resources and automates intelligence by managing, collecting and integrating with various platforms. Anomali provides a threat intelligence model based on their intelligence platform. Some have defined threat intelligence as including data of sensors or honeypots deployed across the internet and the darkweb, these traps provide advance metrics on the state of the internet and intent of adversaries. Examples of such companies technologies include Lupovis.io,[1] Orpheus-Cyber,[2] Flashpoint,[3] and others. Other types of threat intelligence might include automated darkweb scanning, mass internet scanning, or tactics techniques and procedures gathering, which attempts to tie together adversary strategies in order to increase the defender's understanding and provide them with situational awareness.

See also

References

External links