<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Why do we need a Cyber Threat Intelligence? - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/why-do-we-need-a-cyber-threat-intelligence/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Tue, 19 Sep 2023 20:52:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>Why do we need a Cyber Threat Intelligence? - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>Why do we need a Cyber Threat Intelligence?</title>
		<link>https://www.osintafrica.net/why-do-we-need-a-cyber-threat-intelligence/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=why-do-we-need-a-cyber-threat-intelligence</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Tue, 27 Dec 2022 18:00:45 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[Analysis or Processing]]></category>
		<category><![CDATA[Cyber Threat Intelligence]]></category>
		<category><![CDATA[Cyber Threat Intelligence Report]]></category>
		<category><![CDATA[Cyber Threat Intelligence tools]]></category>
		<category><![CDATA[Direction or Planning]]></category>
		<category><![CDATA[Intelligence Cycle]]></category>
		<category><![CDATA[Why do we need a Cyber Threat Intelligence?]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=482</guid>

					<description><![CDATA[<p>Imagine a new zero-day vulnerability under exploitation that can impact your organization without a CVE...</p>
<p>The post <a href="https://www.osintafrica.net/why-do-we-need-a-cyber-threat-intelligence/">Why do we need a Cyber Threat Intelligence?</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;"><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="alignnone size-full wp-image-480" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2022/12/template.png?resize=640%2C360&#038;ssl=1" alt="" width="640" height="360" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2022/12/template.png?w=1280&amp;ssl=1 1280w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2022/12/template.png?resize=300%2C169&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2022/12/template.png?resize=1024%2C576&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2022/12/template.png?resize=768%2C432&amp;ssl=1 768w" sizes="(max-width: 640px) 100vw, 640px" />Imagine a new zero-day vulnerability under exploitation that can impact your organization without a CVE score, and your scanner cannot detect it.</span></p>
<p><span style="color: #000000;">Imagine having many devices exposed over the internet with different vulnerabilities not detected by your vulnerability scanner.</span></p>
<p><span style="color: #000000;">Imagine that your employees used the same password on social media and in your organization also. What if the social media was breached? Your password might be on the Dark web or other data leaked sharing forum. Your organization might be compromised if you are not aware of the breached.</span></p>
<p><span style="color: #000000;">Imagine that your competitor company was compromised, and you might be the next.</span></p>
<p><span style="color: #000000;">Imagine that your company confidential information was leaked on the Dark Web, and you need to find the confidential data</span></p>
<p><span style="color: #000000;">Imagine that your employees are putting pictures containing confidential information about your company over the social media such as Twitter, Facebook, LinkedIn and you are not aware of that.</span></p>
<p><span style="color: #000000;">Imagine that the threat actors made the copy of your website, and your employees s are connecting to it without knowing</span></p>
<p><span style="color: #000000;">Imagine that your employees are receiving a lot of phishing emails daily and are responding to it.</span></p>
<p><span style="color: #000000;">There are thousands of reasons that we still can mention, but let’s limit here.</span></p>
<p><span style="color: #000000;">As security expert when you think about all the imaginations cited, you might think about an option to detect and protect your organization against these imaginations.</span></p>
<p><span style="color: #000000;">A Cyber Threat Intelligence or CTI was created to find the solution against such imaginations.</span></p>
<p><span style="color: #000000;">Before talking about the Cyber Threat Intelligence, we should talk about “Intelligence cycle”</span></p>
<p><span style="color: #000000;"><strong>Intelligence Cycle </strong></span></p>
<p><span style="color: #000000;">The intelligence cycle is set of steps that we use to conduct the intelligence. </span></p>
<p><span style="color: #000000;">The Intelligence Cycle is divided in different phases:</span></p>
<p><span style="color: #000000;"><strong>Direction or Planning</strong> – This phase is the first phase and is very important.</span></p>
<p><span style="color: #000000;">In this phase, you set your goals, procedures, prioritize based on the asset evaluation result.</span></p>
<p><span style="color: #000000;"><strong>Collection</strong> – This is where, you will be gathering data to meet your goals set up in the previous phase. You will need to use different tools to achieve this goal.  For example: used of open source or private source to find all the devices that belong to your organization over the internet.</span></p>
<p><span style="color: #000000;"><strong>Analysis or Processing</strong>– After collecting the data, you must process and analyze all the data you have collected.  You need a specific tool to do that, you will need also to interpret the data at this point. Note that if the data collected, processed and analyzed failed, the results will not be accurate. For example: Collecting and analyzed a bunch of date from the Dark Web by entering your company keyword in order to find the relevant data related to your company. If the tool used did not collect correctly the data and the analysis did not meet the requirement from the planning phase, the result would not be relevant.</span></p>
<p><span style="color: #000000;"><strong>Production</strong> – Once you get the analysis and processing parts done, the next step will be to prepare the report with the details following with some recommendations. For example: The cyber threat intelligence report about the data collected, processed and analyzed from the Dark Web, the vulnerability assessment report, the report about the threat actors that can target your organization.</span></p>
<p><span style="color: #000000;"><strong>Dissemination</strong> – When you report is ready, the next step will be to report it to the management level or the C level based on the decision taken in the planning phase.</span></p>
<p><span style="color: #000000;">Some companies might report to different teams. For example: The vulnerability assessment report could be sent to the vulnerability management in order to verify if the vulnerability scanner engine did not detect the findings. This might also help to determine the efficiency of the tool.</span></p>
<p><span style="color: #000000;">The report about data leaked could be sent to the CISO to take the decision based on the recommendation put in the report.</span></p>
<p><span style="color: #000000;"><strong>Feedback</strong> – The last part and where the report will be verified from the management level or C level like the CISO. If the report did not meet the company requirements, the report might be criticized to improve it. For example: When you send a technical report to the CISO about the data breached on the Dark Web, the CISO might not understand all the terms, as the CISO is not a technical person. It is better always to know where the report will be sent and how to meet the company requirements before reporting it.</span></p>
<p><span style="color: #000000;"><strong>Cyber threat intelligence </strong></span></p>
<p><span style="color: #000000;">Cyber threat detection is the process of detecting and analyzing different threats that can impact the organization.</span></p>
<p><span style="color: #000000;">Cyber threat detection without the intelligence cycle will be very difficult, as the data are becoming much bigger over the internal network and the internet, we need to find a proper approach to find the relevant data. That’s one of the reasons, both were merged to bring the idea of cyber threat intelligence.</span></p>
<p><span style="color: #000000;">Cyber Threat Intelligence is the combination of threat detection tool plus the intelligence cycle to detect and analyze threats, vulnerability and risk that can impact an organization.</span></p>
<p><span style="color: #000000;">As you might read at the beginning of this article, the Cyber Threat Intelligence is made of imaginations. The imaginations will help you to find different threats, vulnerabilities and risks that can impact your organization.</span></p>
<p><span style="color: #000000;">With the different explanations provided above, we may provide a general definition for Cyber Threat Intelligence. The Cyber Threat Intelligence is the process of planning, collecting, processing, analyzing, producing, disseminating and providing the feedback about different threats, vulnerabilities and risks that can impact your organization by using different tools (open sources or private sources).</span></p>
<p><span style="color: #000000;">The threats, vulnerabilities and risks could be anywhere where your infrastructure and data reside. It is very important to find and prioritize your assets and data. You need to have a proper data evaluation and asset evaluation in place to achieve this goal.</span></p>
<p><span style="color: #000000;"><strong>Cyber Threat Intelligence Report</strong></span></p>
<p><span style="color: #000000;">As we already mentioned, we need to report the Cyber Threat Intelligence result obtained during the “Production phase”. While creating a report, the report should be based on some frameworks such as Diamond model and Cyber kill chain (Google to find more about the topics).  The frameworks will help you standardize the report and make it much easier to understand.</span></p>
<p><span style="color: #000000;"><strong>Cyber Threat Intelligence tools</strong></span></p>
<p><span style="color: #000000;">As discussed earlier, the Cyber Threat Intelligence consists of collecting and analyzing data to find more relevant data. Let’s give the name of some tools used by the Cyber Threat Intelligence team.</span></p>
<p><span style="color: #000000;">One of the biggest repositories related to Cyber Threat Intelligence tools is <a style="color: #000000;" href="https://osintframework.com/">OSINT Framework</a> , the website contains different tools used by Cyber Threat Intelligence teams, we can also cite other tools such as:</span></p>
<ul>
<li><span style="color: #000000;">Maltego <a style="color: #000000;" href="https://www.maltego.com/">Home</a>page<a style="color: #000000;" href="https://www.maltego.com/"> &#8211; <span style="color: #0000ff;">Maltego</span></a></span></li>
<li><span style="color: #000000;">Recorded Future <span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.recordedfuture.com/">Recorded Future: Securing Our World With Intelligence</a></span></span></li>
<li><span style="color: #000000;">Threat Quotient <a style="color: #000000;" href="https://www.threatq.com/">T<span style="color: #0000ff;">hreatQuotient | ThreatQ | Threat Intelligence Platform</span></a></span></li>
<li><span style="color: #0000ff;"><span style="color: #000000;">Nixintel </span><a style="color: #0000ff;" href="https://start.me/p/rx6Qj8/nixintel-s-osint-resource-list"> Nixintel&#8217;s OSINT Resource List &#8211; start.me</a></span></li>
</ul>
<p><span style="color: #000000;">In conclusion, based all the details explained, the Cyber Threat Intelligence is very important for any organization to protect his own environment. It will help you to be more proactive to protect your organization against different cyber-attacks. If you have not implemented a CTI team it is the time for you to start. </span></p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/why-do-we-need-a-cyber-threat-intelligence/">Why do we need a Cyber Threat Intelligence?</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">482</post-id>	</item>
	</channel>
</rss>
