Showing posts with label Threat Intelligence. Show all posts
Showing posts with label Threat Intelligence. Show all posts

Wednesday, December 18, 2019

Learning From Your Own Malware


The best threat intelligence comes from your own organization’s own endpoints.  One aspect to this is treating every instance of unwanted software such as malware or adware that lands and installs on a machine as an indicator of a gap in controls coverage. 



A control that is present but somehow misconfigured.
A control that is missing or has been disabled.
An error by a user. 

So, when you encounter evidence of malware, a key followup item is to determine just how the malware got there.

Thursday, November 21, 2019

Starting With Not-So-Shiny Cyber Threat Intelligence


Cyber security is interesting in that there is encouragement and peer pressure to start with the most shiny of shiny things. Cyber threat intelligence is no exception. 




When starting a cyber security threat intelligence program, most organizations have some fixed amount of resources and a lot of choices.

Friday, July 26, 2019

The Super Secret Source Of Some Of The Best Cyber Threat Intelligence Available


There is no shortage of threat intelligence companies trying to sell you something. Most of what is sold or even available for free isn’t very good.




So where do you go for some of the best threat intelligence for your organization? Shhh…it still has to be a secret. That best source is the information already residing in your own systems. 


What do I mean?


Want to know where you have gaps in your incident response process? Review your previous incidents. What controls would have prevented the incident that you still don’t have in place?