Exercise – Adding an AlienVault OTX threat feed to Security Onion
As an example of what threat information can add to overall security monitoring effectiveness, we shall add a threat feed to our Security Onion deployment. As mentioned throughout this chapter, threat feeds, or IOC feeds, by themselves are not threat intelligence; however, adding a threat feed to your SIEM does allow you to perform some rudimentary threat intelligence activities.
As a source of threat IOC information, I have chosen the AlienVault Open Threat Exchange (OTX) service. The reason for this is that their threat feed is constantly updated, accurate, and includes many different sources of information and types of IOCs, but also because their online community and the forums that come with the free subscription to the OTX platform are extremely valuable once you decide to take threat intelligence a step further and want to proactively start mapping threats to your environment.
The AlienVault threat...