tag: Dicom · 2 items
- Engineer — Plan: If your organization runs DICOM infrastructure, audit all services for internet exposure: the research confirms 3,979 deployments accept unauthenticated connections with no encryption, and ~50% show zero maintenance activity. Verify DICOM ports are not internet-reachable and enforce TLS and auth for any legitimate external access.
- SOC/IR — Learn: Pure measurement research with no IOCs, TTPs, or active exploitation data; useful background on healthcare attack surface but yields no detection or hunting work today.
- Leader — Learn: Provides credible benchmarking data on medical imaging infrastructure exposure — useful context for healthcare sector risk conversations or vendor assessments, but no board-level action is required absent a breach or regulatory deadline.
- Engineer — Learn: Research introduces a higher-fidelity honeypot for DICOM/PACS environments that outperformed the existing Dicompot tool over a 347-day deployment; worth evaluating if your org runs medical imaging infrastructure and lacks deception coverage.
- SOC/IR — Learn: The study’s finding that 49 medical-related attacks were captured across deployments confirms active threat activity against exposed DICOM services, useful context for healthcare SOC analysts scoping hunt priorities, but no IOCs or ATT&CK mappings are surfaced.
- Leader — Learn: Confirms adversaries are actively probing healthcare imaging infrastructure; useful benchmark data if you’re building a case for deception technology investment in a healthcare environment, but no immediate board-level action needed.