Using IoC unconventionally. Part 2. Threat Landscape

More in Indicators & C2
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…
Using IoC in a Non-Standard Way. Part 2. Threat Landscape 🧘♀️
Earlier, we discussed how to use indicators of compromise for Threat Hunting. This time, we’ll talk about the threat landscape and how to use IOC feeds to build it. Let us remind you that the information security threat landscape is the set of actual and potential threats, vulnerabilities, and risks that can affect the security of an organization’s information systems.
Considering the relationship between IOC feeds and building an information security threat landscape, the following approach can be proposed. Over a given period of time, you can monitor incoming alerts triggered by indicators across all types of security tools. Then, having obtained a list of alerts, you can perform analytics on them: which malware families and threat groups the identified indicators are associated with, what vulnerabilities they exploit, etc. By studying this data, you will gain an initial understanding of who is targeting you specifically and how. Additionally, by examining the techniques implemented by the identified groups and families, you will obtain a current threat landscape.
The main advantages of this approach are its reliance on confirmed events and the ability to predict the next steps of specific attackers. However, there are also disadvantages: being tied to existing detections and limiting the analysis coverage to alerts from security tools. If a detection for a specific technique or threat is missing or fails to trigger, such activity may go unnoticed.
🤔 When analyzing real alerts, an analyst can answer a number of questions based on observed activity:
🔵 Which threat groups are targeting our organization? Are the threats associated with them relevant to us?
🔵 Which malware families have already been detected in our infrastructure, and what techniques do they implement?
🔵 What attack techniques have been used against us at different stages of the Cyber Kill Chain?
🔵 What vulnerabilities have attackers attempted to exploit? Are they relevant to us?
There is also a second approach to building it. It involves searching for potential threats without waiting for alerts, relying on data from TI systems and analytical reports. In this case, the focus shifts: instead of tracking specific attacks on the organization, the focus is on current attack patterns targeting companies in a particular economic sector or region. The logic is that if your organization operates within a specific industry in a specific country, then attacks characteristic of that industry and country will also pose a danger to you.
The volume of data in this approach is significantly larger, but along with this, visibility expands — covering both actual and potential risks. The analyst gains the ability to identify threats in advance, before incidents occur in their own infrastructure. And here, they can answer virtually the same questions, but on a broader scale:
🔴 Which threat groups relevant to our economic sector/region are most active?
🔴 Which malware families are part of these groups’ arsenals and could potentially be used against us in the future?
🔴 What malicious techniques are characteristic of these groups at different stages of an attack? To what extent do they overlap with our current security tool detection coverage?
🔴 What vulnerabilities are being actively exploited in our economic sector/region? Are they relevant to us?
In practice, these two approaches are not opposed to each other but are used together. By combining actual alerts with threat information for the industry / region, an analyst can:
🔴 Identify which malicious techniques are relevant to the organization;
🔴 Determine which techniques remain undetected and require coverage;
🔴 Assess which threats are already relevant and which are highly likely to manifest in the future;
🔴 Map the vulnerabilities exploited by threat groups against the actual state of the infrastructure.
Building and analyzing a threat landscape is a good way to plan proactive measures for protecting information systems, develop a quality risk management strategy, and improve the overall level of information security in an organization.
#ioc #detect #tip
@ptescalator
More in Indicators & C2
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…






