Working with IOCs and IOAs
A common mistake that is often made by organizations that start the process of leveraging threat intelligence is to subscribe to a few commercial or open source feeds and turn them on. This approach will see the enterprise quickly become inundated with data. Most of this data will be unusable for the organization. The reality is that analysts and other stakeholders should work through crafting what data is relevant to their organization and use sources that can provide the best data to fit that relevance.
In this case, we will focus on OSINT sources. There are several commercial organizations, such as CrowdStrike and AlienVault, that make IOCs and IOAs available to the community. Other sites are strictly focused on servicing the cybersecurity community without a commercial component. The following are some resources that analysts can leverage:
- AlienVault Open Threat Exchange (OTX): This site, available at https://otx.alienvault.com/, aggregates...