A recipe for both
- Scott J Roberts
- Instructor: SANS FOR578 Cyber Threat Intelligence
- Author: Intelligence Driven Incident Response
- Metaphor Warning!!!
- What is Ramen?
- What Is Threat Intelligence?
Understand the combination of tools, inputs, process, & people that lead to creating a threat intelligence capability.
“something (such as an instrument or apparatus) used in performing an operation or necessary in the practice of a vocation or profession” ~ Merriam-Webster: Tool (Def 2a)
- Tools
- Tongs
- Ladle
- “Spider”
- Knives & Cutting Boards
- “Base Infrastructure:” Pots & Pans, Stove Top Burner
- Infrared Thermometer
- Aka Kitchen Laser Gun
- TIP: Yeti
- Workbench: Maltego
- Detections: Yara & Snort
- 3rd Party Sources:
-
Passive Total & Shodan
- Key: Fitting Into Your Environment
“something that enters into a compound or is a component part of any combination or mixture” ~ Merriam-Webster: Ingredient
- Broth Base
- 1 cup rough diced red delicious apple (about 1)
- 1 cup rough diced garlic (about 3 heads)
- 1 cup rough diced ginger
- 1 medium yellow onion
- 1/2 rack pork baby back ribs
- 12 cups water
- 1 cup soy sauce
- Noodles
- Broth Extras
- 1 sheet kombu
- handfull rough choped dry shiitake mushrooms
- 1 half a diced sweet potato
- Ends of 1 bunch green onions
- Serving Extras
- Slow Poached Eggs
- Nori/Wakame
- Siracha
- Sweet Potato
- Grilled Sweet Potato
- Your own incidents
- Your teams
- Vendor Reports
- Honeypots
- Peers/Sharing Communities
- 3rd Party Paid Intelligence
“a set of instructions for making something from various ingredients” ~ Merriam-Webster: Recipe (Def 2)
- Steps for Ramen - Bring water (Optional add dry shiitakes and nori) to a simmer
- Add other ingredients (except noodles) and bring to a boil
- Reduce heat and simmer 2.5-3 hours (reduced to about half)
- Prepare noodles and serve with extras
- Intelligence Cycle
- F3EAD
- Lessons Learned & Practice
- Great Cooks Eat (Consume)
- Great Cooks Cook (Create)
- Great Cooks Learn (Growth)
- RFIs
- Short Form Reports
- Long Form reports
- Think about your tools
- Get to know and understand your inputs
- Focus on honing your processes
- Grow your people