Cyberstudy
PDF p.234 In progress

Threat Feeds

Open PDF at p.234 21 flashcards

Summary

PDF p.234

Threat feeds are real-time, continuously updated sources of information about potential threats and vulnerabilities. Integrating threat feeds into vulnerability management practices helps organizations stay aware of the latest risks and respond swiftly.

In plain words

Supplementary — not from your PDF

Threat feeds give continuously updated information about new vulnerabilities, exploits and threat actors, helping you prioritize fixes. They can be open-source (MISP, Cyber Threat Alliance) or paid (IBM X-Force Exchange, Recorded Future, Mandiant). Outputs include behavioural research (narratives about TTPs), reputational data (bad IPs, domains, hashes) and threat data that ties observations to known actors. ISACs share intelligence within an industry. OSINT gathers publicly available information.

Detailed explanation

PDF p.234
  • Definition
    • Threat Feeds: Real-time data sources about vulnerabilities, exploits, and threat actors.
    • Purpose: Enhance threat intelligence, enable quicker identification and remediation of vulnerabilities.
  • Common Platforms
    • AlienVault's Open Threat Exchange (OTX)
    • IBM's X-Force Exchange
    • Recorded Future
  • Benefits
    • Timely Information: Provides up-to-date context about new threats.
    • Focus Remediation: Helps prioritize the most relevant and damaging vulnerabilities.
    • Proactive Approach: Reduces time between vulnerability discovery and remediation.
  • Third-Party Threat Feeds
    • Open-Source Feeds: Free, accessible, cost-effective (e.g., Cyber Threat Alliance, MISP).
    • Proprietary Feeds: Comprehensive, advanced insights, paid subscriptions (e.g., IBM X-Force Exchange, Mandiant's FireEye, Recorded Future).
  • Types of Threat Feed Outputs
    • Behavioral Threat Research: Narrative commentary on attacks and TTPs.
    • Reputational Threat Intelligence: Lists of malicious IP addresses, domains, malware signatures.
    • Threat Data: Correlates observed data with known TTPs and threat actor indicators.
  • Information-Sharing Organizations
    • Examples: Cyber Threat Alliance, Information Sharing and Analysis Centers (ISACs).
    • Role: Enhance collective cybersecurity resilience, promote collaborative threat tackling.
  • Open-Source Intelligence (OSINT)
    • Definition: Collecting and analyzing publicly available information for decision-making.
    • Sources: Blogs, forums, social media, dark web.
    • Tools: Shodan, Maltego, Recon-ng, theHarvester.
    • Framework: OSINT Framework (https://github.com/lockfale/osint-framework).

Important terms

taken from the text above
Threat Feeds
Real-time data sources about vulnerabilities, exploits, and threat actors.
Timely Information
Provides up-to-date context about new threats.
Focus Remediation
Helps prioritize the most relevant and damaging vulnerabilities.
Proactive Approach
Reduces time between vulnerability discovery and remediation.
Open-Source Feeds
Free, accessible, cost-effective (e.g., Cyber Threat Alliance, MISP).
Proprietary Feeds
Comprehensive, advanced insights, paid subscriptions (e.g., IBM X-Force Exchange, Mandiant's FireEye, Recorded Future).
Behavioral Threat Research
Narrative commentary on attacks and TTPs.
Reputational Threat Intelligence
Lists of malicious IP addresses, domains, malware signatures.
Threat Data
Correlates observed data with known TTPs and threat actor indicators.
Open-Source Intelligence (OSINT)
Collecting and analyzing publicly available information for decision-making.
Sources
Blogs, forums, social media, dark web.
Framework
OSINT Framework (https://github.com/lockfale/osint-framework).
ISACs Information Sharing and Analysis Centers OSINT Open-Source Intelligence

Examples & real-world scenarios

Supplementary — not from your PDF
  • Blocking IP addresses from a reputational feed at the firewall.
  • A financial ISAC sharing indicators of a new campaign.
  • Using OSINT to see what information about your organization is publicly exposed.

Scenario

A threat feed reports active exploitation of a VPN flaw. The vulnerability team moves that patch to the top of the list even though it scored lower than others in the scanner report.

Common mistakes

Supplementary — not from your PDF
  • Collecting feeds without acting on them.
  • Mixing up reputational intelligence (lists of bad indicators) and behavioural research (how attacks work).

Practical skills

Supplementary — not from your PDF
  • Use a threat feed to adjust patch priorities.

What I should remember

Key Points PDF p.234
  • Definition
    • Threat Feeds: Real-time data on threats and vulnerabilities.
    • Purpose: Enhance threat intelligence, quick remediation.
  • Common Platforms
    • Examples: OTX, X-Force Exchange, Recorded Future.
  • Benefits
    • Timely Information: Up-to-date threat context.
    • Focus Remediation: Prioritize relevant vulnerabilities.
    • Proactive Approach: Faster remediation.
  • Third-Party Threat Feeds
    • Open-Source: Free, accessible (e.g., Cyber Threat Alliance).
    • Proprietary: Comprehensive, paid (e.g., IBM X-Force Exchange).
  • Types of Outputs
    • Behavioral Research: Attack commentary.
    • Reputational Intelligence: Malicious IPs, domains.
    • Threat Data: Correlates with known TTPs.
  • Information-Sharing Organizations
    • Examples: Cyber Threat Alliance, ISACs.
    • Role: Collaborative cybersecurity.
  • Open-Source Intelligence (OSINT)
    • Definition: Public information analysis.
    • Sources: Blogs, forums, social media.
    • Tools: Shodan, Maltego, Recon-ng, theHarvester.
    • Framework: OSINT Framework.