Cyber Threat Knowledge vs. Cyber Threat Action
“Knowledge is only potential power. It becomes power only when, and if, it is organized into definite plans of action, and directed to a definite end.” - Napoleon Hill, Think and Grow Rich (1937)
I’m currently studying detection engineering and threat hunting, or D.E.A.T.H. if we want to sound overly dramatic.
Credit @th3cyF0x ~ 2022
Although I don’t get too involved in low-level technical security operations much these days, I have surrendered to the fact that I will always have a hard time letting go of being technical, which is never a bad thing, in my opinion.
Anyway, the “why” behind this recent deep dive into the world of detection engineering and threat hunting is because I want to get a practical, first-hand look at how to (actually) detect real-world multi-stage attacks that organisations all around the world are being hit with on a daily basis.
I want to see how far we can go with proactive threat defence and find the most effective ways to detect and prevent common attack techniques and procedures. Or at the very least, give us defenders more time to respond.
Currently, the best way to get accurate real-world threat data is by subscribing to and consuming CTI or Cyber Threat Intelligence feeds from several different curated sources ranging from major security vendors and cloud security providers to certain hacking forums and the dark web.
CTI typically provides:
Threat Actor Information
Targeted Attack Vectors
Behavioural Patterns
Contextual Information
Confirmed Indicators of Compromise (IoCs)*
You may be very familiar with this already, but what about Tactical Threat Intelligence (TTI)?
A derivative of CTI, tactical threat intelligence goes beyond attack tactics and techniques.
It distils the verbose collection of active threat information and focuses on real-world indicators of compromise (IoCs) linked to suspicious adversarial activity and attack procedures that can be detected in your organisation.
In other words, CTI is the “what,” “why,” and “how.” TTI is the “who,” “where,” and “when” (when using time-specific or near real-time detection criteria).
TTI uses key indicators such as:
IP address(es)
Domain names/URLs
Malware signatures
File hash strings
Event ID’s and status codes.
A key point I want to make here is that cyber threat information is only valuable when it can be used to generate action, produce results, or change behaviour. If it can’t do any of that, disregard it.
CTI is a great place to start, but CTI alone isn’t action; it’s intelligence and knowledge. How you implement and use this information is where the real value is found.
Tactical threat intelligence is the actionable representation of CTI; it is the unification of threat indicators applied in the context of your network, your organisation, and your unique operating environment.
Here are four key benefits that businesses can takeaway by utilising Tactical Threat Intelligence (TTI).
Effective Real-Time Threat Detection:
TTI provides actionable insights by focusing on the real-time detection of suspicious adversarial activity. This enables organisations (and defenders, more specifically) to identify and respond to threats more quickly, reducing the window of opportunity for attackers and mitigating potential damage.
Improved Incident Response Capabilities:
With TTI, organisations can leverage specific indicators like IP addresses, domain names, and malware signatures to optimise incident response strategies. This information helps isolate and address security incidents as they are discovered and published, minimising the impact on business operations.
Contextual Threat Understanding:
TTI offers detailed contextual information about threats, including the "who," "where," and "when." This context helps technical security teams (SecOps, CIRTs) to understand the specific threat landscape as it relates to their industry and/or environment and enables prioritisation of defence mechanisms against the most relevant threats.
Scalable Threat Hunting Capabilities:
TTI supports targeted threat-hunting activities by translating CTI into actionable threat detection capabilities. This proactive approach to identifying and investigating potential threats at scale significantly strengthens an organisation’s overall security posture and helps preempt future attacks.
Conclusion
For any cyber defence/security operations team to be truly effective at stopping breaches, they must have actionable threat detection capabilities that align to the organisation's context (industry/sector, risk appetite, security posture, known threat actors, etc.).
Cyber threat intelligence is vital for understanding the current and emerging threat landscape and the observed tactics, techniques and procedures (TTPs) used in the wild.
However, the real value always lies in the ability to transform knowledge into action, which is the goal of tactical threat intelligence. It achieves this goal by translating CTI into actionable threat detection insights that can be used immediately for threat hunting and incident response activities, supporting the business with a proactive threat defence strategy.