[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: RE: [cti-users] How does CybOX data is generated?
Hi Alexander, There are many different types of analysts
J. What you are describing I would classify as more of an incident response
role – specifically performing ‘hunting’ where they inspect logs looking for anomalies, and monitoring tools that are performing a ‘detection’ role (with the rules that you have been describing). There are also nowadays threat analyst roles, which are designed to understand the threats that an organisation faces, and try to understand and
research which threat actors are most likely trying to target the organisation, and to track them. Their purpose is to eliminate most of the unnecessary threat intelligence and distil it down to the small amount of threat intelligence that is most likely to
affect the organisation. The incident response role then takes that reduced set of data and tries to find it within the org. It’s a combination of the two functions that makes the overall process stronger. The Threat Analyst works out who we should be looking for, and the
Incident Responder tries to find them. Cheers Terry MacDonald Senior STIX Subject Matter Expert SOLTRA | An FS-ISAC and DTCC Company +61 (407) 203 206 |
terry@soltra.com From: alexander kipnis [mailto:alexander.kipnis85@gmail.com]
Hi, Thanks for the detailed answer. Correct if I am wrong, but as far as I understand the cyber analyst work is going through logs of some detection systems and identifying abnormal behavior, then creating CybOX observables and generalizing them to STIX Indicator and so on? Further more, it means that cyber analyst crafts these observables by hand (or with some algorithms)? I thought there are some rules like YARA that generate the observables and the analysts try to identify patterns of generalize it to bigger threats. Cheers, Alexander On Mon, Feb 29, 2016 at 12:14 AM, Terry MacDonald <terry@soltra.com> wrote:
|
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]