tag: Threat-Intelligence · 6 items
- Engineer — Skip
- SOC/IR — Learn: The finding that 98% of MISP events lack sector tagging quantifies a real operational gap in shared CTI value; the BERT-based approach achieving F1 0.89 for sector routing is worth tracking as a future tooling direction for CTI triage workflows.
- Leader — Learn: The statistic that nearly all shared CTI events go uncategorized by sector is a useful benchmark for conversations about the operational return on threat intel program investments; no action is required now, but it frames the value case for better-structured intel feeds.
- Engineer — Skip
- SOC/IR — Learn: A dataset of 2,438 verified illicit Bitcoin addresses with HackForums provenance and cybercrime category labels could enrich threat intel feeds or wallet-screening tooling; no immediate detection action required, but worth evaluating the released dataset for integration.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: TTP-R1 automates mapping CTI prose to ATT&CK (sub-)techniques with meaningful F1 gains over LLM baselines; worth tracking if your team annotates CTI at scale, but no detection or hunt action follows from this research paper alone.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: Unit 42’s analysis of identity-based attack patterns offers context for triage judgment and detection prioritization, though no specific IOCs or new TTPs are surfaced in the summary.
- Leader — Learn: The 90% statistic is a potential board-deck data point, but without independent corroboration of the underlying methodology this is vendor-sourced framing rather than actionable risk input.
- Engineer — Skip
- SOC/IR — Learn: GTIG is merging Mandiant and TAG naming systems into a cryptonym-based taxonomy; analysts should update internal runbooks and intel mappings to cross-reference old identifiers (e.g. APT numbers) with new names as GTIG rolls out the change.
- Leader — Skip
- Engineer — Skip
- SOC/IR — Learn: Unit 42’s IR report covers AI-assisted attack patterns and automation trends observed across real incidents; useful for calibrating triage judgment and updating mental models of adversary tempo, but no specific IOCs or detections to act on now.
- Leader — Learn: Annual IR benchmarking data from a major vendor is useful for board deck context and budget justification around AI-related threat trends, though it should be weighed against independent corroboration given the Palo Alto source.