Threat Intelligence in a SOC Analyst’s Day
Threat intelligence platforms play a crucial role for cybersecurity analysts to investigate aspects of cyber threats. As a Security Operations Center (SOC) analyst, you should leverage and take advantage of the different threat intelligence platforms to investigate cyber threat artifacts such as IPs, domains, hashes, and so on.
The objective of this chapter is to learn about the meaning of threat intelligence, the role of threat intelligence in SOCs, and how to use the VirusTotal, IBM X-Force, AbuseIPDB, and Google platforms to investigate cyber threat artifacts.
In this chapter, we’re going to cover the following main topics:
- Introduction to threat intelligence
- Investigating threats using VirusTotal
- Investigating threats using IBM X-Force
- Investigating threats using AbuseIPDB
- Investigating threats using Google
Let’s get started!