Threat Intel

  • Collection & analysis of information about threats to gain a better understanding of them

Types of Threat Intel

TypeDescription
StrategicHigh-level information for executives, high-level overview
TacticalTechnical information (such as TTPs) for technical staff
OperationalGeneral information for middle management (i.e.: security managers)

Sources of Threat Intel

  1. OSINT — Collect from external open sources
  2. Human Intel — Collect from human contact
  3. Counter Intel — Mislead the attacker (i.e.: honeypots)
  4. Internal Intel — Collect from internal employees

5-Tuple

Set of 5 attributes used to identify & describe a network connection/data flow.

  1. Source IP Address
  2. Destination IP Address
  3. Source Port
  4. Destination Port
  5. Protocol