Tactical cyber threat intelligence
Tactical cyber threat intelligence helps to various security products to operate, such as Security Information and Event Management (SIEM), firewalls, Intrusion Detection Systems/Intrusion Prevention Systems (IDS/IPS), and so on, with Indicators of Compromise (IoC).
This level of cyber threat intelligence focuses on the what. Traditionally, this type of intelligence was the most common, and many vendors provided so-called feeds, but nowadays, more and more organizations focus on TTPs, as classic indicators have a very short life cycle.
In most cases, these indicators consist of IP addresses, domain names, and hashes. Usually, the hashes are of the following types:
- MD5
- SHA1
- SHA256
Such indicators can be easily shared with the help of cyber threat intelligence platforms, such as MISP, and can be used both for research and detection purposes.
Let's get back to the report we are analyzing. There's a section called...