Threat Intelligence Starter Resources

Creating a threat intelligence capability can be a challenging undertaking, and not all companies are ready for it. Businesses that run successful threat intelligence teams generally:

•    Collect externally available data on threats and correlate it with internal events.
•    Be aware of threats driving proactive security controls.
•    Establish proactive internal hunting for unidentified threats.
•    Invest in employee and customer threat education.
•    Expand security industry peer relationships.
•    Apply methods for collecting and analysing external threat data.

If your company is just starting out with threat intelligence and doesn’t have the time or resources to dedicate an entire department to the task, there are some easy ways to begin integrating threat intelligence into your daily routine without breaking the bank.

The following resources can help build awareness of the threat landscape and prepare your company for defense.

Google Alerts

One of the simplest ways to stay informed of potential threats is setting up Google Alerts. These can be especially useful to monitor attacks or vulnerabilities in your industry. To get the most from Google Alerts, be sure to follow Google search best practices like keeping phrases as short as possible, using quotes, leveraging domain extensions, and avoiding synonyms.

Threat Feeds

If you want to become more proactive in collecting data there are a number of open source threat feeds you can use to stay informed of suspicious IP addresses and domains as a starting point for threat research. For example, abuse.ch provides many feeds, including a ZeuS block list and ransomware tracker, and dan.me contains a full Tor node list that updates every 30 minutes.

Threat Blogs

Being well read is an important habit in life, and doubly so if you’re tasked with defending your company from cyber threats. Here’s a list of some informative blogs that range from general threat intelligence to incident response to geopolitical attacks:

•    CyberWire: Relevant briefings on critical cyber news happening across the globe.
•    Cyber Security Intelligence: Cyber News, Analyse, Directors, Management Reports and a Cyber Database.
•    OODAloop: Articles and analysis on cyber and geopolitical threats.
•    CTOvision: Context for the CTO, CIO, CISO, and data scientist.
•    FireEye: Insights on today’s advanced threats.
•    CERIAS: Articles from strategic thinkers like Gene Spafford and Sam Liles.
•    Dell SecureWorks: Articles focused on incident response and information security.
•    Palo Alto Networks: Articles and research around cyber-crime and vulnerabilities.
•    DomainTools: Content focused on domain data and internet trends.
•    ProtectedBusiness: Tips and techniques for defending your business.
•    Recorded Future: Original threat research and best practices for using threat intelligence.

Threat Reports

While blog posts can keep you informed on daily threat intelligence, sometimes it is necessary to look at an entire quarter or year to get a full view of the threat landscape.

The following cyber threat reports can help you get a grasp on lessons learned and best practices going forward:

•    Checkpoint Security Report: Yearly insights into cyber threats, including malware and botnets.
•    NTT Global Threat Intelligence Report: Analysis of global attack data.
•    Versign iDefense Cyber Threats and Trends: Overview of key cyber security trends.
•    Cisco Midyear Security Report: Threat intelligence and trend analysis report.
•    Symantec Intelligence Report: Annual and monthly intelligence reports.
•    Verizon Data Breach Investigations Report: Incident data from 67 global contributors.
•    Ponemon Institute Cost of Breach Study: Annual report on economics of breach and recovery.
•    CyberEdge Cyber Threat Report: Summary of security threats, response plans, and processes.

Threat Tools

While staying aware of the threat landscape is critical to any company’s threat intelligence strategy, there are some tools that can supplement the data without breaking the bank:

•    Maltego: Data-mining tool renders directed graphs for link analysis and finds relationships between pieces of information from various sources online.
•    Shodan: Search engine allows you to find out which of your devices are directly connected to the internet, where they are located, and if they are being used maliciously.
•    TweetDeck: Social media dashboard (free) that many use to increase their audience on Twitter, can also help companies track multiple twitter handles and add additional security.

For more information and suggestions on commercial cyber security contact Cyber Security Intelligence Ltd

Recored Future:

You Might Also Read:

Turn Threat Data Into Threat Intelligence:

Artificial Intelligence Gives Business Wings:

 

 

« Germany May Go Offensive After Russian Cyber Attacks
Bank Data Breaches Are Up And It's An Inside Job »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

IPCopper

IPCopper

IPCopper specializes in network packet capture appliances for cybersecurity, cybersurveillance and network monitoring, and encrypted data storage.

Ingenio Global

Ingenio Global

Ingenio is a specialist recruitment business for SaaS companies. Our purpose is to source exceptional talent in areas including cyber security for leading SaaS companies in the UK and Ireland.

UNIDIR Cyber Policy Portal

UNIDIR Cyber Policy Portal

The UNIDIR Cyber Policy Portal is an online reference tool that maps the cybersecurity and cybersecurity-related policy landscape.

UK Research & Innovation (UKRI)

UK Research & Innovation (UKRI)

UKRI works in partnership with universities, research organisations, businesses, charities, and government to create the best possible environment for research and innovation to flourish.

CyberSecJobs.com

CyberSecJobs.com

CyberSecJobs.com is a career site and job fair company providing services and resources to the cyber security community.

Aries Security

Aries Security

Aries Security provides a premiere cyber training range and skills assessment suite and develops content for all levels of ability.

InfoLock

InfoLock

Infolock are experts in data governance, providing consulting and advisory services that help organizations effectively secure, manage, and optimize their data.

Conatix

Conatix

Conatix was formed to apply recent advances in AI and other fields of technology to insider fraud, one of the most intractable problems in cybersecurity.

Lightspin

Lightspin

Lightspin is a contextual cloud security platform that continuously visualizes, detects, prioritized, and prevents any threat to your cloud stack.

Alcon Maddox

Alcon Maddox

Alcon Maddox is a niche recruitment and executive search firm specialised in sourcing exceptional Cyber Security sales and commercial leadership talent. Serving clients across the Middle East & Europe

Cyberplc

Cyberplc

Cyberplc is a global cybersecurity consulting firm providing services to government, the public sector and enterprises.

Codenotary

Codenotary

Codenotary provide a comprehensive suite of verification and enforcement services to guarantee the integrity of your software throughout its entire lifecycle.

BioID

BioID

BioID are a German company offering deepfake detection, liveness detection, facial authentication & identity verification as a Service. 

ELK Analytics

ELK Analytics

ELK Analytics is a specialized Managed Security Services Provider (MSSP) that focuses on endpoint security and monitoring & alerting for any type of structured or unstructured data.

Lightpath

Lightpath

Lightpath is revolutionizing how organizations connect to their digital destinations by combining our next-generation network with our next-generation customer service.

WillCo Tech

WillCo Tech

WillCo Tech works to enhance national security and force readiness for military and commercial enterprises with a suite of software capabilities surrounding the human element of cybersecurity.