CTI
Cyber Threat Intelligence (CTI) provides processed information about attackers, their tools, and their objectives.
Cyber Threat Intelligence (CTI) is processed information about attackers, their tools, and their objectives. It helps a SOC to correctly classify Alerts and expand its detection capabilities.
How it works
CTI exists on four levels. Technical CTI includes indicators like IP addresses, domains, and file hashes. Tactical CTI describes how attacker groups operate, often referencing MITRE ATT&CK. Operational CTI deals with specific campaigns and imminent attacks. Strategic CTI is aimed at senior management and describes trends and risks for a specific industry.
For example, a warning reports that a ransomware group is currently attacking Swiss industrial firms. They are using a specific VPN vulnerability. The SOC checks if this VPN version is in use at any of its clients. It then searches retrospectively for known indicators of compromise. It also adds a detection rule for the described procedure.
What to look out for
- Relevance: Many feeds provide large volumes of indicators with no connection to your industry.
- Timeliness: IP addresses and domains become outdated quickly. Old indicators generate noise.
- Implementation: CTI is only useful if it results in rules, hunts, or other actions.
- Sources: Combine commercial feeds with open-source intelligence from the community.
Switzerland and regulation
The National Cyber Security Centre (NCSC) publishes warnings. It also shares information with operators of critical infrastructure. For financial institutions, information is also exchanged via the Swiss FS-CSC.
Typical mistakes
Many organisations subscribe to multiple feeds. They import all indicators without validation. This approach generates noise and provides little benefit. A better approach is to have a clear objective. Which attackers and techniques are relevant to your industry? This helps formulate the questions that CTI should answer. You should also regularly check how many Alerts a feed has triggered. Then check how many of those were true positives.
How we implement it
We use CTI to enrich every Alert and for our threat hunting activities. As a FIRST member, we exchange information with other incident response teams.