Introducing CTI
Defining CTI in one chapter is a complex task. Nevertheless, we will try to define what it is and cover the basics needed to understand how it can benefit purple teaming assessments.
CTI was born within military contexts many decades (or, arguably, even centuries) ago. As is often the case in cybersecurity, military concepts are leveraged to improve cyber defense practices. CTI is a good example of such a concept, but just like other military concepts, it has taken time to mature and be correctly applied within organizations.
We will start by dispelling a misconception that developed in the cybersecurity industry due to security vendors and poor marketing campaigns. An IoC is not equal to CTI. Indeed, too many security vendors tried to make organizations think they needed a huge number of IoCs in order to perform CTI. This misconception has become less common as the cybersecurity industry has matured.
Indeed, CTI is way more than just a bunch of indicators...