<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Diamond Model of Intrusion Analysis - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/the-diamond-model-of-intrusion-analysis/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Fri, 07 Feb 2025 19:46:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>The Diamond Model of Intrusion Analysis - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>What is OSINT ?</title>
		<link>https://www.osintafrica.net/what-is-osint/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-osint</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Fri, 07 Feb 2025 19:19:06 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[Security Awareness]]></category>
		<category><![CDATA[Security Webcast]]></category>
		<category><![CDATA[Cyber Kill Chain]]></category>
		<category><![CDATA[Cyber Threat Intelligence]]></category>
		<category><![CDATA[osint]]></category>
		<category><![CDATA[OSINT Advantages]]></category>
		<category><![CDATA[OSINT FRAMEWORK]]></category>
		<category><![CDATA[OSINT Report]]></category>
		<category><![CDATA[The Diamond Model of Intrusion Analysis]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=857</guid>

					<description><![CDATA[<p>OSINT means Open-Source Intelligence. It is a set of tools that are available for everyone...</p>
<p>The post <a href="https://www.osintafrica.net/what-is-osint/">What is OSINT ?</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><strong>OSINT</strong> means Open-Source Intelligence. It is a set of tools that are available for everyone and everywhere.</p>
<p><strong>OSINT</strong> is used in many different areas such as:</p>
<ul>
<li><strong>Cyber Threat Intelligence</strong></li>
<li><strong>Human Intelligence</strong></li>
<li><strong>Political Intelligence</strong></li>
<li><strong>Journalist Intelligence</strong></li>
<li><strong>And others.</strong></li>
</ul>
<p>O<strong>SINT</strong> allows to collect any type of data available online and analyze it. The <strong>OSINT cycle</strong> is:</p>
<ul>
<li><strong>Data collection</strong></li>
<li><strong>Data Analysis</strong></li>
<li><strong>Report (Documentation and Recommendations)</strong></li>
</ul>
<p>The <strong>OSINT Report</strong> depends on which area you are using OSINT. For example in Cyber Threat Intelligence (<a href="https://www.osintafrica.net/why-do-we-need-a-cyber-threat-intelligence/">Why do we need a Cyber Threat Intelligence? &#8211; osintafrica</a>), OSINT report can be writing following one of the models <strong>CYBER KILL CHAIN or The Diamond Model</strong> of Intrusion Analysis, more details about the models can be found here <strong><a href="https://www.osintafrica.net/three-attacks-frameworks-that-cyber-security-members-should-know/">Three attacks frameworks that Cyber Security members should know osintafrica. </a></strong></p>
<p><strong>OSINT framework</strong> tools are available and easy to find online.</p>
<p>Some of them are:</p>
<p><a href="https://osintframework.com/">OSINT Framework</a></p>
<p><a href="https://start.me/p/wMdQMQ/tools">Tools &#8211; Start.me</a></p>
<p><a href="https://tools.myosint.training/">My OSINT Training&#8217;s Tools</a></p>
<p><strong>Advantages of using OSINT:</strong></p>
<p>OSINT has many advantages such as many <strong>applications are free and accessible online</strong>, <strong>data available anywhere</strong> but the most important for us, are the following:</p>
<ul>
<li><strong>Detect Threats</strong></li>
<li><strong>Vulnerabilities</strong></li>
<li><strong>Information lookup</strong></li>
<li><strong>Data breached identification</strong></li>
</ul>
<p>Anything that has advantages, has inconveniences as well.</p>
<p><strong>OSINT</strong> does have some.</p>
<p><b>OSINT </b><b>Inconveniences:</b></p>
<p>Data can be query by anyone online</p>
<p>PII data accessible online</p>
<p>Vulnerability and threats are identifiable online</p>
<p>Data breached data are accessible on different platform (Dark Web, Hacking forum , OSINT tools and others ..).</p>
<p>OSINT tools can be vectors of attack.</p>
<p>The privacy concerning OSINT , the privacy concerns is quite similar to GDPR regulation requirements, such as collecting only information related to your investigation, having authorization to collect the data (PII or IP) and others.</p>
<p class="graf graf--p">OSINT is very useful, like said before, the tools are available for anyone to use. You can start using it by looking up some information related to your self. Do not forget about Privacy related to OSINT.</p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/what-is-osint/">What is OSINT ?</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">857</post-id>	</item>
		<item>
		<title>Three attacks frameworks that Cyber Security members should know</title>
		<link>https://www.osintafrica.net/three-attacks-frameworks-that-cyber-security-members-should-know/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=three-attacks-frameworks-that-cyber-security-members-should-know</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Sat, 18 Mar 2023 20:34:43 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[Cyber Kill Chain]]></category>
		<category><![CDATA[MITRE ATT&CK]]></category>
		<category><![CDATA[The Diamond Model of Intrusion Analysis]]></category>
		<category><![CDATA[Three attacks frameworks]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=616</guid>

					<description><![CDATA[<p>Almost every day, you may hear from the news that a company was hacked and...</p>
<p>The post <a href="https://www.osintafrica.net/three-attacks-frameworks-that-cyber-security-members-should-know/">Three attacks frameworks that Cyber Security members should know</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="alignnone size-full wp-image-617" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/security-framework.png?resize=640%2C360&#038;ssl=1" alt="" width="640" height="360" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/security-framework.png?w=1280&amp;ssl=1 1280w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/security-framework.png?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/security-framework.png?resize=1024%2C576&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/03/security-framework.png?resize=768%2C432&amp;ssl=1 768w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">Almost every day, you may hear from the news that a company was hacked and the data was leaked.</span></p>
<p><span style="color: #000000;">Most of the attacks happened in passive mode, which means that the companies are not aware of the attack. One of the most efficient ways to detect and respond to any Cyber Threats is to implement some detection and responsive measures.</span></p>
<p><span style="color: #000000;">The three frameworks that are going to be described below, will help you to detect and respond to any threat against your organization.</span></p>
<ol>
<li><span style="color: #000000;"><strong>Cyber Kill Chain </strong></span></li>
</ol>
<p><span style="color: #000000;">The following framework helps the organization to identify the steps used by the attackers to perform an attack.</span></p>
<p><span style="color: #000000;">The framework was developed by Lockheed Martin, the framework is part of the Intelligence Driven Defense model for identification and prevention of cyber intrusions activity.</span></p>
<p><a href="https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html">Cyber Kill Chain® | Lockheed Martin</a></p>
<p><span style="color: #000000;">The framework is divided in 7 steps:</span></p>
<ul>
<li><span style="color: #000000;">Reconnaissance: Finding any weakness that can be used to target the organization (Vulnerabilities, looking for details about the target over the network or gathering information about the target)</span></li>
<li><span style="color: #000000;">Weaponization: After gathering information about the target and finding a weakness, the threat actor tries to leverage it by create a malicious file or programs that will be sent to the target.</span></li>
<li><span style="color: #000000;">Delivery: Sending the malicious file or program to the target (phishing, drive by download)</span></li>
<li><span style="color: #000000;">Exploitation: At this stage the threat actor, exploits the vulnerability.</span></li>
<li><span style="color: #000000;">Installation: The threat actor tris to install a malicious software in order to gain high level privilege.</span></li>
<li><span style="color: #000000;">Command &amp; Control: Establishing a communication with the target’s system</span></li>
<li><span style="color: #000000;">Actions on objectives: The threat actor meets his objective (data exfiltration) by exfiltrating</span></li>
</ul>
<ol start="2">
<li><span style="color: #000000;"><strong>MITRE ATT&amp;CK</strong></span></li>
</ol>
<p><span style="color: #000000;">MITRE ATT&amp;CK is the knowledge base that help different actors to find out the tactics and techniques used by the adversaries to compromise a system.  The framework can be used by anyone without any charge. The framework contains information about mitigation steps to detect any anomaly and protect the infrastructure and any system that might be infected (Enterprise, Mobile, ICT).</span></p>
<p><a href="https://attack.mitre.org/">MITRE ATT&amp;CK</a></p>
<p><span style="color: #000000;">MITRE ATT&amp;CK is divided in 14 phases to find the tactics and techniques used by the threat actor.</span></p>
<ul>
<li><span style="color: #000000;">Reconnaissance</span></li>
<li><span style="color: #000000;">Resource Development</span></li>
<li><span style="color: #000000;">Initial Access</span></li>
<li><span style="color: #000000;">Execution</span></li>
<li><span style="color: #000000;">Persistence</span></li>
<li><span style="color: #000000;">Privilege Escalation</span></li>
<li><span style="color: #000000;">Defense Evasion</span></li>
<li><span style="color: #000000;">Credential Access</span></li>
<li><span style="color: #000000;">Discovery</span></li>
<li><span style="color: #000000;">Lateral Movement</span></li>
<li><span style="color: #000000;">Collection</span></li>
<li><span style="color: #000000;">Command and Control</span></li>
<li><span style="color: #000000;">Exfiltration</span></li>
<li><span style="color: #000000;">Impact</span></li>
</ul>
<ol start="3">
<li><span style="color: #000000;"><strong>The Diamond Model of Intrusion Analysis</strong></span></li>
</ol>
<p><span style="color: #000000;">The model consists of 4 models that help you to identify how the intrusion can occur in the infrastructure.</span></p>
<p><span style="color: #000000;">The model helps to find the “<strong>who,” “what,” “when,” “where,” “why,” and “how.”</strong> Of the attacks in order to detect and mitigate the threat before.</span></p>
<p><span style="color: #000000;">The models:</span></p>
<ul>
<li><span style="color: #000000;">Adversary: The attacker or threat actor behind the attack.</span></li>
<li><span style="color: #000000;">Capabilities: Are the set of skills and tools in the possession of the threat actor</span></li>
<li><span style="color: #000000;">Victim: The infrastructure, system, individuals targeted by the threat actor</span></li>
<li><span style="color: #000000;">Infrastructure: Are the software and hardware used by the threat actor to target the victim.</span></li>
<li><span style="color: #000000;">Social-political – The reason of the attack (financial, espionage, hacktivism)</span></li>
<li><span style="color: #000000;">Technology – How the threat actor can operate and what technologies the adversary used to operate and communicate.</span></li>
</ul>
<p><span style="color: #000000;"><strong> In conclusion</strong>, the three frameworks described here are very useful to detect and respond to different threat. Without referring to one of the frameworks, it will be very difficult almost not possible to mitigate the threat within your environment. Using them will be a step forward to being resilient against any attack.</span></p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/three-attacks-frameworks-that-cyber-security-members-should-know/">Three attacks frameworks that Cyber Security members should know</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">616</post-id>	</item>
	</channel>
</rss>
