Showing posts with label threat intelligence. Show all posts
Showing posts with label threat intelligence. Show all posts
Saturday, April 22, 2017
OODA Framework for TI / DFIR / CSIR Process Engineering
THE OODA Loop (https://en.wikipedia.org/wiki/OODA_loop) can be used to develop workflows for TI / DFIR / CSIR, including leveraging TIMP implementations, like MineMeld (https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/minemeld).
Sunday, January 15, 2017
How Many Threat Intelligence (TI) Feeds Are Enough?
MSSPs aside (as they can more easily achieve economies of scale), how many TI feeds should an internal SOC leverage?
Well, that depends on the quality of information. With that said, several open source & commercial / subscription feeds would not hurt for cross-reference purposes.
Here are some feeds worthy of consideration:
Well, that depends on the quality of information. With that said, several open source & commercial / subscription feeds would not hurt for cross-reference purposes.
Here are some feeds worthy of consideration:
- US-CERT
- CTIN
- Optiv
- Facebook ThreatExchange
- Crowstrike
- AlienVault
- SSLBL
- ZeuS Tracker
- Palevo Tracker
- Malc0de
- Binary Defense Systems
- Carbon Black / Bit9
- ThreatQuotient
- Anomali / ThreatStream
- ThreatConnect
Labels:
commercial,
MSSP,
open source,
SIEM,
SOC,
threat intelligence,
TI,
US-CERT
Subscribe to:
Posts (Atom)