11
Threat Intelligence Sherif Mansour

Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

  • Upload
    others

  • View
    14

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

Threat Intelligence

Sherif Mansour

Page 2: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

Threat Intelligence is like teenage sex: everyone talks about it, nobody really knows how to do it, everyone thinks everyone else is doing it, so everyone claims they are doing it...

Page 3: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have
Page 4: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have
Page 5: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have
Page 6: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have
Page 7: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

What Can Threat Intel Tell Me?

1. Information about "bad actors” Public Threat FeedsPrivate Threat Feeds

2. Alerting if your org is listed as a bad actor

3. TTP Tactics, Techniques, Procedures

Page 8: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

Information about "bad actors”

• Origins – IPs/ASN/Domains• Compromised Organizations / accounts• Malware signatures etc..

Page 9: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

Alerting if your org is listed as a bad actor

If you find this, you are having a bad day!

Page 10: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

TTP Tactics, Techniques, Procedures

• Learning from other’s grief!• Allows you to check if your org is prepared for

defending, detecting such campaigns

Page 11: Threat Intelligence - OWASP Foundation | Open Source Foundation for Application Security · 2020-01-17 · Advanced Threat Detection By using the OpenlOC framework, you will have

What can go wrong?

• Poor data quality• False positives• Unable to leverage data – difficult to integrate