Tactical Threat Intelligence – Hunting Down Threats

FacebookTwitterLinkedInEmail
Description
In this module we examine the typical CTI analyst role and the CKC. The shorter tactical timeframe dictates that the analyst spend a good portion of his/her time chasing down leads on suspicious behavior. This in turn informs the incident response process. The analyst must examine alerts from multiple sources and then use this data to determine which rise to the level of actionable incidents. It's also vital that good lines of communication are open for the sharing of data and notification. Analysts must be aware of the risk associated with attribution and the tendency for cognitive and confirmation bias to exist. This means that the analyst must not be stuck in a predetermined way of thinking and be open to considering alternative possibilities. The video concludes with an overview of the seven steps of the CKC. We'll take a deep dive into the CKC in a later module.
Recommended Study Material

Recorded Future Cyber Daily

 

 

With new threats lurking around every corner, you need to be prepared. Join thousands of your infosec peers and subscribe to the Cyber Daily for free trending threat intelligence insights.

 

 

Learn on the go.
The app designed for the modern cyber security professional.
Get it on Google Play Get it on the App Store

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play
 

Support Cybrary

Donate Here to Get This Month's Donor Badge

 
Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?

Continue
Cancel