<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - security-onion</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/security-onion/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2016-07-20T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/security-onion/atom.xml</id>
    <entry xml:lang="en">
        <title>Threat Intelligence and Baselining</title>
        <published>2016-07-20T00:00:00+00:00</published>
        <updated>2016-07-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-and-baselining-sans/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night session Threat Intelligence: Neighborhood Watch for Your
Networks &amp;amp; Why Baselining Matters, delivered by Matthew J. Harmon on July 20,
2016, explores how integrating crowdsourced Indicators of Compromise (IoCs) with
rigorous network baselining practices equips defenders to spot, prioritize, and
respond to threats before they escalate .&lt;&#x2F;p&gt;
&lt;h2 id=&quot;state-of-cyber-security&quot;&gt;State of Cyber Security&lt;&#x2F;h2&gt;
&lt;p&gt;First, Harmon frames the state of cybersecurity emphasizing that breaches are
inevitable against motivated adversaries and introduces the fundamentals of
threat intelligence. He walks through the CIAs 15 Axioms for Intelligence
Analysts, defines IoC types (DNS hosts, IPs, URLs, file hashes), and outlines
the CybOX, STIX, and TAXII standards for packaging and exchanging structured
threat data. A real-world case study shows how to trace a Dyreza banking-trojan
infection from anomalous traffic to phishing emails, package findings into a
STIX header, and share via TAXII. Harmon then compares commercial and
open-source intelligence feedsi ThreatConnect for expert-curated data and
CriticalStack Intel for aggregated TSV-formatted IoCs demonstrating how
organizations can leverage these resources for timely, actionable insight.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;baselining&quot;&gt;Baselining&lt;&#x2F;h2&gt;
&lt;p&gt;Next, the presentation pivots to the critical role of baselining: defenders must
know their normal network behavior to detect deviations. Harmon introduces key
open-source tools Bro (for traffic analysis), PRADS (for asset discovery), SGUIL
(for alert management), and LOKI (for IOC scanning)and shows how they integrate
within the Security Onion distribution. He provides a do-it-yourself lab
outline: install Security Onion, subscribe to CriticalStack feeds, configure Bro
and YARA rules, and deploy a network tap for continuous monitoring. By combining
structured threat intelligence with continuous baselining, organizations can
proactively identify both emerging campaigns and internal anomalies,
dramatically improving detection and response capabilities.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;2016-07-20_Threat_Intelligence_and_Baselining-SANS.pdf&quot;&gt;Threat Intelligence and
Baselining&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence 101: Introduction and Foundations</title>
        <published>2015-10-20T00:00:00+00:00</published>
        <updated>2015-10-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-101/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-101/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-101/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Cyber Security Summit 2015 presentation Threat Intelligence 101:
Introduction and Foundations by Matthew J. Harmon provides an entry level
overview of the role and practice of cyber threat intelligence (CTI). Harmon
begins by framing the inevitability of breaches citing high-profile incidents,
and the principle that attackers need only one success, then introduces CTI as
the structured collection and sharing of Indicators of Compromise (IoCs)
enriched with context to support detection and response.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;foundations&quot;&gt;Foundations&lt;&#x2F;h2&gt;
&lt;p&gt;He then explains the foundational CTI standards, CybOX (the vocabulary of
observables), STIX (the XML based language for packaging observables into
indicators, incidents, TTPs, and courses of action), and TAXII (the protocol for
exchanging STIX packages) and walks through a real-world example: from spotting
anomalous server traffic to extracting email, hash, IP, and URL indicators;
packaging them into a STIX header; and sharing via TAXII to uncover a broader
campaign.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;diy&quot;&gt;DIY&lt;&#x2F;h2&gt;
&lt;p&gt;Finally, Harmon showcases two CTI platforms ThreatConnect (expertcurated
CybOX&#x2F;STIX feeds) and CriticalStack Intel (aggregated open-source IoCs in TSV
for Bro integration) and outlines a hands-on lab using Bro or Security Onion and
CriticalStack feeds. This culmination demonstrates how organizations can do it
themselves by deploying free tools, subscribing to feeds, automating IoC
ingestion, and participating in community-driven neighborhood watch initiatives
to elevate their collective security posture.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57315_2015-10-20_Threat_Intelligence_Intro_And_Foundations-CSSummit.pdf&quot;&gt;Threat Intelligence
101&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
