flâneur — a map of the web's best reading

Frameworks for DE-Friendly CTI (Part 5) | by Anton Chuvakin | Anton on Security | Medium

medium.com · saved by 1 readers

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator. In this blog (#5 in the series), we will build a quick “framework-lite” for making CTI to DE flows better. medium.com medium.com medium.com medium.com Let’s review three organizational models of integrating an existing threat intelligence (CTI) team with the detection engineering function for optimum detection work. Some organizations have a clearly defined and separate CTI team, which supplies information to different teams, functions and recipients. Detection engineering (DE), whether inside or outside the SOC (here, specifically this point may not matter), is just one of the recipients. When there are organizational reasons why this setup cannot be radically changed, you should define a concrete interface: requirements, expectations, procedures for threat sharing (including rush or priority ones), artifacts sharing, cadence and some other commo

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator. In this blog (#5 in the series), we will build a quick “framework-lite” for making CTI to DE flows better. medium.com medium.com medium.com medium.com Let’s review three organizational models of integrating an existing threat intelligence (CTI) team with the detection engineering function for optimum detection work. Some organizations have a clearly defined and separate CTI team, which supplies information to different teams, functions and recipients. Det

Explore this link on the map →