<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>I Told You So, Volume 1 - stix-taxii</title>
    <subtitle>Archive, Volume 1: conference talks and papers on security and risk, 2010 to 2018.</subtitle>
    <link rel="self" type="application/atom+xml" href="https://blog.itys.net/vol1/tags/stix-taxii/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2015-10-20T00:00:00+00:00</updated>
    <id>https://blog.itys.net/vol1/tags/stix-taxii/atom.xml</id>
    <entry xml:lang="en">
        <title>Threat Intelligence 101: Introduction and Foundations</title>
        <published>2015-10-20T00:00:00+00:00</published>
        <updated>2015-10-20T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-101/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-101/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-101/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The Cyber Security Summit 2015 presentation Threat Intelligence 101:
Introduction and Foundations by Matthew J. Harmon provides an entry level
overview of the role and practice of cyber threat intelligence (CTI). Harmon
begins by framing the inevitability of breaches citing high-profile incidents,
and the principle that attackers need only one success, then introduces CTI as
the structured collection and sharing of Indicators of Compromise (IoCs)
enriched with context to support detection and response.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;foundations&quot;&gt;Foundations&lt;&#x2F;h2&gt;
&lt;p&gt;He then explains the foundational CTI standards, CybOX (the vocabulary of
observables), STIX (the XML based language for packaging observables into
indicators, incidents, TTPs, and courses of action), and TAXII (the protocol for
exchanging STIX packages) and walks through a real-world example: from spotting
anomalous server traffic to extracting email, hash, IP, and URL indicators;
packaging them into a STIX header; and sharing via TAXII to uncover a broader
campaign.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;diy&quot;&gt;DIY&lt;&#x2F;h2&gt;
&lt;p&gt;Finally, Harmon showcases two CTI platforms ThreatConnect (expertcurated
CybOX&#x2F;STIX feeds) and CriticalStack Intel (aggregated open-source IoCs in TSV
for Bro integration) and outlines a hands-on lab using Bro or Security Onion and
CriticalStack feeds. This culmination demonstrates how organizations can do it
themselves by deploying free tools, subscribing to feeds, automating IoC
ingestion, and participating in community-driven neighborhood watch initiatives
to elevate their collective security posture.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57315_2015-10-20_Threat_Intelligence_Intro_And_Foundations-CSSummit.pdf&quot;&gt;Threat Intelligence
101&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Threat Intelligence: Neighborhood Watch for Your Networks</title>
        <published>2015-07-23T00:00:00+00:00</published>
        <updated>2015-07-23T00:00:00+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/"/>
        <id>https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/</id>
        
        <content type="html" xml:base="https://blog.itys.net/vol1/posts/threat-intelligence-neighborhood-watch/">&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;&#x2F;h2&gt;
&lt;p&gt;The SANS @ Night session Threat Intelligence: Neighborhood Watch for Your
Networks by Matthew J. Harmon introduces the concept of crowdsourced cyber
threat intelligence as a critical component of modern defense. Harmon defines
threat intelligence as the collection of Indicators of Compromise, DNS hosts, IP
addresses, email addresses, URLs, and file hashesi, enriched with contextual
information about campaigns, tactics, techniques, and procedures (TTPs) to
produce actionable insights. He stresses that confidence in data varies from
unvetted open-source feeds to expert-curated platforms and that standardized
formats like CybOX for observables, STIX for structured information, and TAXII
for automated exchange enable seamless sharing across organizational boundaries.&lt;&#x2F;p&gt;
&lt;p&gt;Through a step-by-step case study, Harmon demonstrates how to apply these
standards in practice: identifying excessive traffic on a server, back-tracing
it to a phishing email with a malicious ZIP attachment, extracting MD5 hashes
and C2 IPs, and packaging them into a STIX header with appropriate Course of
Action blocks. He then compares two data-sharing solutions: ThreatConnect, which
offers high-confidence, expert-vetted intelligence via CybOX&#x2F;STIX&#x2F;TAXII; and
CriticalStack Intel, which aggregates over a hundred open-source IoC feeds in
simple tab-separated values for rapid integration with Bro (the network analysis
framework). To reinforce the concepts, Harmon outlines a hands-on lab deploying
Bro or Security Onion, subscribing to Intel feeds, and using bro-cut to validate
detectionsunderscoring the power of a community-driven neighborhood watch to
elevate collective security posture.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;presentation&quot;&gt;Presentation&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;a href=&quot;&#x2F;attachments&#x2F;57226_2015-07-23_Threat_Intelligence_Neighborhood_Watch-SANS.pdf&quot;&gt;Threat Intelligence: Neighborhood Watch for your
Networks&lt;&#x2F;a&gt;
&lt;a href=&quot;&#x2F;attachments&#x2F;57925_2017-06-21_MJH_Internet_of_Everything-SANS_Script.pdf&quot;&gt;Threat Intelligence: Neighborhood Watch for your Networks,
Script&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
