4.4 CTI Role in Incident Response Part 2
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
4 hours 30 minutes
Hey guys, I hope they're doing good today. We're going to continue review into interactions between an Indian response team under Cyber Threat Intelligence Unit by discussing some scenarios. So let's go.
In the last video, we discussed the theory behind the cyber threat intelligence concerts and applications to the Indian response team. And how can it make their work more effective and more time efficient?
it's time to take really life scenarios and see how the actually intelligence work towards getting these case solved in a much more effective way.
So one of the first stop it sweeties cost was there reactive nous that surrounds all tnc in response processes.
Cyber threat intelligence can help into your response Teams prepare for treads in offense by providing
a comprehensive off to the picture of the threat landscape.
Information about popular tread actor tactics, techniques and procedures
highlights off industry an area specific attack trends.
You think this intelligence Indian response teams can develop and maintain strong processes for the most common in CNN and threats having peace process is available speeds up, Indian discovery creates and containment
the scope definition is a key aspect. One responding to an incidence
These will provide the Indian response team with accurate actions to contain their reported incident.
Basically, when an incident occurs, three items have to be determined.
what the incident might mean for the organization and which action to take
such items must be analyzed with the most precision possible in order to provide an effective Indian response in these matters. Record the future mentions that cyber tracked intelligence directly helps them by
automatically dismissing false positive enabling Team to focus on Jan. In security incidents.
Enriching incidents with related information from across the open and dark Web, making it easier to determine how much of a threat they posed and how the organization might be affected.
And providing details about the threat and insights about the attacker tactics, techniques and procedures
helping the team make fast and effective containment and remediation decisions.
It's common for organizations to take a long time to realize a breach has secured.
According to the parliament 2018 coast off a data breach study organizations in the United States taken average off 196 dates to Detective Rich.
Not surprisingly, a stolen data and property assets often turn up for sale on the dark Web before direct ful owners realize what has happened.
A powerful threat. Intelligence capability can be a tremendous advantage. It can alert you to a bridge by providing early warning that your assets are exposed online and someone is offering your ***. It's for sale.
Obtaining these intelligence in real time is vital because it will enable the organization to contain the incident as quickly as possible and help you identify when and how your network was breached
at the start of their cyber threat. Intelligence journey. Some organization up for a minimal least solution such as a threat intelligence solution. Bear with a variety of free threat feats.
They might believe that this dip the toes in the water approach will many mice upfront coast
Well, these type of implementations, arms sincere and response teams with some actionable intelligence. It actually makes things worse by forcing analysts to way through bast quantities of false positives and irrelevant alerts.
To fully address the primary incision response pain points.
A secret intelligence capability must be comprehensive. Relevant contextual likes an integrated,
and we're gonna hit the past bottom. Here
you can go have some water. Remember it is important for your body or go to the bathroom or go have a good night's sleep. But not before a quick review today we identified multiple real life cases and map out how this I regret intelligence capabilities help each one of them.
We identified multiple real life cases were cyber threat. Intelligence can help by preparing, preparing processes in advance,
defining scopes and containing incidents and re mediate that exposure. And it's tolling at assets.
And lastly, how half cyber tread intelligence is not better than none, since it will create more exhaustion on the security analyst because more information is collected, but it is not being correlated until an incident is happened.
Now you can go in peace to whatever activities you have planned,
or you can click next and go to the next video with me. See you there