ThreatConnect: Recent Episodes

None

Smarter Security for Maximum Impact

View Details

As a cybersecurity vendor, I like to take a larger view of the market when it comes to the competition. Competitor or not, we’re all on the same side: fighting the good fight against attackers – and hopefully whatever solution is chosen by cybersecurity teams helps them stay ahead and maintain whatever advantage that vendor offers.

That’s why it’s so important that cybersecurity teams understand what they’re getting when they spend hard-to-get budget on new resources. Recently, one of our competitors wrote up an “us vs. them.” I’d like to set the record straight on some of their claims so that prospects have an accurate, high-integrity view when selecting a vendor.

This blog is not a condemnation of the competition – it’s a fact-by-fact correction of what they said.

In fact, here’s a link so you can check their work!

1. “Superior Intelligence, Enhanced with Context”Anomali claims to provide a “comprehensive solution” for intelligence, yet they don’t define what comprehensive means. It’s true that ThreatConnect offers more than 125 OSINT feeds and blogs out of the box, many of which aren’t available in a machine-readable format anywhere else (and we’re adding more all the time!). OSINT is valuable, but context is king in CTI. That’s why we use AI to classify data within OSINT feeds by industry, MITRE ATT&CK techniques, and other relevant factors such as industry and geographic relevance —bringing them closer to the level of premium feeds.

Anomali also claims to “eliminate alert fatigue.” I wish! If a cybersecurity vendor could eliminate alert fatigue, it would revolutionize cybersecurity, and we’d all be able to retire early. Realistic alert fatigue is about volume: the key isn’t eliminating alerts but making sure the right ones get surfaced with the right context.

How ThreatConnect Solves This:

  • AI-Powered Context: We don’t rely on third-party data quality itself. We make sure it’s tuned and contextualized for you. ThreatConnect enriches all intelligence sources with both proprietary analytics and real-world attack context so you can filter what’s relevant more easily and make decisions faster.
  • Aligned Intelligence: ThreatConnect tailors CTI to your unique intelligence requirements, ensuring only relevant intelligence is surfaced—unlike Anomali’s reliance on third-party feeds with minimal alignment.
  • Polarity: Polarity is a brand new way to deliver intelligence to wherever it’s needed at the moment of investigation and action. It allows analysts to contextualize whatever they’re looking at and gain insights from both threat intelligence and operational data (e.g. SIEMs) without ever leaving the tool they’re in.

Bottom Line:

Results speak louder than claims, so don’t take our word for it; see this quote from one of our customers:

“We received 200,000,000 SIEM events per month or 50,000,000 per week. With ThreatConnect’s intelligence-driven automation capabilities, those events get narrowed down to 12 incidents per month, or 3-4 per week.”

-Fortune 300 Financial Institution

Relevant and contextualized intelligence helps more than reduce alert fatigue in Detection; it helps the entire CTI function more impactfully to support every other function, too (Response, Hunt, Vuln Management, etc.).

Further, thanks to Polarity, analysts can conduct adaptive threat analysis directly in their workflow, prioritizing threats without additional integrations. Intelligence can be customized to your unique requirements.

(P.S. If anyone knows a way to completely eliminate alert fatigue, let me know—I have my eye on a ski-in/ski-out cabin with a hot tub…)

2. “Advanced AI for Adaptive Threat Analysis”—or Just a Black Box?Anomali touts their machine-learning engine, Macula, for threat scoring and classification. That’s great, but AI isn’t useful if you can’t check its work. It’s a human optimizer, not a human replacer. A black-box ML model without transparency is a liability, not an asset.

At ThreatConnect, we believe AI should enhance, not replace, human analysis. That’s why:

  • We’ve marked over 11 million indicators as safe, backed by clear citations and scoring explanations.
  • We provide full visibility into how our AI-derived conclusions are made.
  • Just checking the facts here: Anomali says that our analytics are a paid add-on. We don’t believe that critical insights should be paywalled. All of our analytics – AI or otherwise – are included in our base subscription. Also if I’m throwing shade, our integrations are also all included: you want another SIEM integration? You better be ready to pay Anomali extra.
  • Polarity’s AI-powered summaries provide instant context for large datasets, streamlining investigations without reliance on opaque AI models. In addition, you can leverage your own compliant-ready AI models without needing to rely on the vendor’s.

Bottom Line: ThreatConnect doesn’t just score threats—we add context that analysts can verify. And we don’t charge extra for analytics or integrations.

“Our incident response time from soup-to-nuts went from 7 hours to 37 minutes, and is still decreasing … ThreatConnect enabled us to quantify ROI and to define business requirements for onboarding technology.”

-Forbes 2000 Hospital & Healthcare System

3. “Streamlined Automation and Integration”—or a Customization Dead End?Anomali tries to have it both ways: they say ThreatConnect Playbooks are too rigid, yet they also require “too much customization.” Which is it?

Customization is crucial for modern security teams that must adapt to evolving tech stacks. Many of our customers are former Anomali users who hit a wall—they found Anomali couldn’t adapt or scale to their needs.

Here’s how we do it better:

  • Fully Customizable Playbooks: ThreatConnect supports automation at scale without the roadblocks of pre-built, inflexible workflows.
  • Elastic Workflows: Unlike Anomali, which struggles with scaling automation, our workflows adapt to handle increased intelligence volumes seamlessly.
  • World-Class Customer Success Team: Our team includes former practitioners (like CTI analysts and red-teamers) who help customers optimize their security operations. We’re also staffed with security engineers who do this sort of thing for fun (seriously, you should see some of their home labs). They’re here to help make sure even your most bespoke use cases are operationalized quickly.

Bottom Line: We adapt to both your technological and tradecraft needs, helping you mature by sitting alongside you as you deal with those growing pains.

“To reduce the load of our security and IT staff, we introduced over 60 workflow automations with ThreatConnect Playbooks, saving over $1.3 million per year in labor costs.”

-Fortune 2000 Healthcare Organization

4. “Secure Intelligence Sharing”—Our Approach vs. Their “Trusted Circles”Anomali criticizes ThreatConnect’s approach to intelligence sharing, claiming we are “too open.” But let’s be clear: we do everything they do and more. Our data model allows private, secure community sharing exactly like their Trusted Circles.

However, relying solely on sharing groups usually depends on one or two very well-resourced “sharers” while everyone else simply consumes due to lack of resources or maturity. We solve this problem with a global intelligence network that’s anonymized and automated on an opt-in basis to ensure everyone can benefit from intelligence sharing regardless of resources.

We collect intelligence from billions of network events and investigations, automatically aggregating insights across our platform.

  • If you find an indicator, we can show you whether others are investigating it, whether it’s been seen in the wild, or whether it has been debunked as a false positive.
  • Unlike Anomali, our intelligence-sharing model doesn’t only depend on manual submissions (although we do support that!), reducing analyst burden while increasing reliability.
  • MSSP-Ready: ThreatConnect’s data model is purpose-built to enable MSSPs to control data-sharing granularity, balancing customer privacy with intelligence effectiveness—unlike Anomali’s rigid “Trusted Circles.”

Bottom Line: “Trusted Circles” only work if people contribute. ThreatConnect’s data-sharing model ensures everyone benefits without extra effort. In addition, Trusted Circles were not built specifically to address the needs of MSSPs.

“ThreatConnect It took a 2-5 minute task and turned it into a 2-second task.”

-Fortune 500 Retailer

5. “Advanced Threat Modeling and Analysis”—Marketing Hype vs. Real TradecraftThreat modeling is a core CTI skill. Anomali claims to have a more advanced approach, but their writeup focuses on data aggregation—not real tradecraft.

ThreatConnect enables users to operationalize frameworks like MITRE ATT&CK in a structured, repeatable way. This isn’t just about collecting intelligence—it’s about making it actionable.

Additional Differentiators:

  • Novel ATT&CK Use Cases: Going beyond traditional threat modeling, we apply ATT&CK to new use cases like security gap analysis and financial risk modeling.
  • Modeling Assistance: We robustly map intelligence from structured data provided by partners and parse unstructured data to add labels and context, increasing its discoverability and usability to make it actionable.
  • Intel Process Optimization: ThreatConnect’s workflows integrate human decision-making with automated response, reducing manual effort.
  • Comprehensive Threat Intelligence: Unlike Anomali, which relies on third-party feeds, ThreatConnect’s CAL enhances intelligence with real-world data and performance analytics.

Bottom Line: Anomali talks about advanced modeling, but ThreatConnect does this better and, most importantly, actually helps analysts use it for real needs.

“ThreatConnect provides a comprehensive view of emerging risks and helps us correlate and analyze them to improve the speed of detection and response. It also allows our teams to collaborate more effectively, greatly enhancing our overall security posture and operational efficiency.”

-Global Advertising Agency

The Real Bottom Line: ThreatConnect is Built for Cyber Defenders for Analysts, Not Marketing HypeAnomali’s writeup attempts to blur the lines between fact and fiction, but the truth is simple:

  • ThreatConnect delivers true intelligence enrichment, not just black-box ML scoring.
  • We include all analytics and integrations at no additional cost.
  • Our automation scales with your needs, while Anomali customers often hit limitations.
  • We make intelligence sharing effortless and anonymous, ensuring insights flow without manual work.
  • We help CTI teams apply real-world tradecraft, not just aggregate data.

Want to see the difference for yourself? Schedule a demo today.

The post Debunking Anomali’s Claims: Why ThreatConnect is the Superior Threat Intelligence Platform appeared first on ThreatConnect.

View Details

You’re a CTI Analyst tasked with investigating a potential phishing campaign targeting your organization. An alert flags a suspicious email containing a URL that may be linked to a known threat actor. It would be best to determine the URL’s risk level, identify related indicators, and quickly distribute actionable intelligence to your security team. Toggling between tools, constructing complex queries, and manually piecing together context slows you down, putting your organization at risk.

This is where ThreatConnect, Polarity, and the new AI-based TQL Generator step in to transform your workflow. Together, they empower analysts to automate, enrich, and retrieve threat intelligence faster and more accurately.

The Role of Automation in Threat IntelligenceAutomation is the backbone of modern threat intelligence. The sheer volume of threat data and the speed at which threats evolve make manual processes unsustainable. ThreatConnect and Polarity tackle this challenge head-on by automating workflows, enriching data, and delivering real-time context. With the addition of ThreatConnect’s TQL Generator, analysts can now simplify data retrieval through natural language queries.

ThreatConnect: Streamlining Intelligence WorkflowsPlaybooks: Automate and Orchestrate with EaseThreatConnect’s Playbooks are a powerful tool for automating repetitive tasks and orchestrating complex workflows. Using an intuitive no-code, drag-and-drop interface, analysts can design automations that respond to specific triggers, such as new threat indicators or high-risk alerts, without writing a single line of code.

Key features include:

  • Pre-built Templates: Start with ready-made Playbook templates for common use cases, such as phishing response, malware analysis, and alert triage.
  • Third-Party Integrations: Connect with tools like VirusTotal, Slack, and SIEM platforms to streamline workflows.
  • Customizable Workflows: Tailor actions, triggers, and decision points to fit your organization’s needs.
  • Debugging and Monitoring: Test and refine Playbooks before deployment using real-time visual feedback.
  • Scaling: Ensure that automation volume and extensibility doesn’t become a risk to your update.

For example, a Playbook might automatically analyze a suspicious URL, enrich it with data from VirusTotal, and cross-reference internal logs for related incidents. If flagged as malicious, it can update a firewall rule to block the domain and notify the SOC team within minutes.

Intelligent Enrichment: Turning Data Into ContextThreatConnect’s Intelligent Enrichment automatically enhances raw indicators with valuable context, making them actionable. No custom scripts or integrations required.

  • External Sources: Query platforms like VirusTotal or AbuseIP for information on IPs, domains, and file hashes.
  • Internal Insights: Add proprietary intelligence from your organization, such as whether the indicator has been seen in your network before.
  • Prioritization: Automatically tag indicators with attributes like severity, confidence, and relevance to help analysts prioritize responses.

For example, imagine your team identifying a suspicious domain during an investigation. ThreatConnect’s Intelligent Enrichment automatically queries external sources like VirusTotal and AbuseIP, revealing the domain’s connection to phishing campaigns. Simultaneously, it checks your internal threat library and uncovers previous incidents involving the domain, tagging it with attributes like “High Confidence,” “Phishing Threat,” and its association with a known actor like APT28. With these insights instantly available, your team can prioritize the domain as high-risk and take immediate action to block it across your systems.

Custom WorkflowsCustom workflows empower organizations to standardize processes and ensure teams follow mature, consistent best practices. By combining manual and automated functions into a unified workflow, these tools optimize both people and technologies, streamlining threat response and operational efficiency.

  • Automatically escalate high-confidence indicators.
  • Share enriched intelligence with partners or ISACs.
  • Trigger Playbooks for immediate response to new threats.

For example, when a phishing email is reported with an embedded suspicious URL, a ThreatConnect Custom Workflow can be triggered to automate the response. The URL is enriched with data from VirusTotal, cross-checked against internal logs for previous activity, and flagged as malicious. Simultaneously, the workflow ensures manual oversight where needed while automating critical actions: updating the firewall blocklist, notifying the SOC team with detailed context, and sharing findings with an ISAC for broader threat awareness. This approach ensures a swift, coordinated response while maintaining consistency and operational maturity.

Polarity: Amplifying Context in Real-TimePolarity is the ultimate companion for threat analysts, delivering enriched intelligence in real-time as they work. By overlaying contextual data directly into analysts’ tools, Polarity eliminates the need to toggle between platforms, significantly boosting productivity.

Key Benefits of Polarity: A Closer LookInstant Overlay

Polarity seamlessly integrates with the analyst’s workflow, displaying enriched threat intelligence within their existing tools, such as email clients, SIEM dashboards, and web browsers. As analysts interact with data—whether it’s a suspicious email, an IP address, or a domain—Polarity instantly overlays relevant context, such as historical associations or known threat actor activity.

For example, while examining a flagged phishing email, Polarity might instantly highlight the URL’s connection to a known malware campaign, saving the analyst valuable research time.

Data Fusion

Polarity aggregates intelligence from multiple sources, including internal threat libraries, external threat feeds, and live data from platforms like ThreatConnect. This unified view eliminates silos and ensures analysts have a holistic understanding of the threat landscape.

Imagine you’re investigating a phishing campaign; Polarity might merge data from internal logs, ThreatConnect-enriched indicators, and open-source feeds to present a full picture of the threat.

Collaboration

Polarity fosters team collaboration by enabling analysts to annotate and share contextualized insights in real-time. Shared overlays ensure all team members work with the same intelligence, improving alignment during incident response.

Take, for example, a scenario in which one analyst can annotate a malicious domain while investigating it as part of a broader attack campaign, instantly sharing this context with the SOC team.

Polarity acts as a real-time guide, amplifying the effectiveness of ThreatConnect workflows and empowering analysts to focus on decision-making rather than data hunting.

Introducing the TQL Generator: Simplifying Data RetrievalWhile ThreatConnect and Polarity enhance workflows and enrich data, the TQL Generator revolutionizes data retrieval by making it as simple as typing a question.

The Problem

CTI analysts often need to extract specific intelligence from large datasets. Constructing precise queries in ThreatConnect Query Language (TQL) can be challenging and time-consuming, especially for those unfamiliar with its syntax. Mistakes in query construction can delay investigations and lead to incomplete results.

The Solution

The TQL Generator simplifies this process by translating natural language inputs into TQL syntax automatically.

How it works:

1. Input: The analyst types a natural language query: “Find all incidents related to APT28 and their known aliases.”

2. Translation: The TQL Generator converts the input into the appropriate TQL syntax.

3. Output: ThreatConnect executes the query, and retrieves enriched intelligence, including indicators, associated incidents, and relevant context.

By enabling faster, error-free queries, the TQL Generator allows analysts to focus on interpreting data and driving actionable decisions.

A CTI Analyst’s SuccessReturning to our CTI analyst investigating the phishing campaign, here’s how these tools transform their workflow:

  • ThreatConnect automatically enriches the suspicious URL with data from external sources, identifying it as linked to a known threat actor.
  • Polarity overlays additional context in real time, showing related incidents and highlighting key connections without leaving the analyst’s dashboard.
  • Using the TQL Generator, the analyst quickly retrieves all incidents and indicators related to the identified actor, helping map out the full scope of the campaign.
  • A ThreatConnect Playbook updates the organization’s firewall to block the malicious domain, alerts the SOC team, and shares intelligence with an external ISAC for broader threat awareness.

What would have taken hours—or even days—is now resolved in minutes, reducing organizational risk and ensuring a proactive response.

The combination of ThreatConnect, Polarity, and the TQL Generator redefines what’s possible in threat intelligence. Together, they enable analysts to automate workflows, enrich data, retrieve insights effortlessly, and collaborate in real-time.

Want to transform your threat intelligence workflows? Explore ThreatConnect’s automation solutions and learn how Polarity enriches context in real-time. Simplify threat data retrieval with the TQL Generator today!

The post Automating Threat Data Retrieval: How ThreatConnect, Polarity, and the TQL Generator are Changing the Game appeared first on ThreatConnect.

View Details

When a critical alert lands on your desk, every second counts. Whether you’re triaging flagged IPs, investigating APT activity, or gathering intelligence for a report, the pressure to act quickly and accurately can feel relentless. The reality is clear: manual investigations are too slow, and incomplete data leaves room for error. You need tools that cut through the noise, streamline processes, and give you actionable insights—fast.

ThreatConnect TI Ops 7.8 introduces tools that help streamline investigations and eliminate bottlenecks. Bulk indicator searches, plain-language query generation with the TQL Generator, and integrated AbuseIP enrichment provide the insights we need faster. Features like Intel 360 enable better collaboration, ensuring our intelligence is actionable and validated. With these updates, we can focus on prioritizing and responding to threats more efficiently, improving outcomes while reducing manual effort.

Unleashing the Power of Actionable SearchAs a security analyst, you may receive escalated alerts from your SIEM and other tools, including hundreds of flagged IP addresses and domains tied to potential malicious activity. Investigating data manually can be overwhelming (and boring!), and delays could give attackers more time to cause harm (and burn out analysts in the process!).

With Actionable Search, you can bulk import indicators that you get from other tools or colleagues and immediately see enriched data for each one. Advanced filters allow you to refine results based on dates, threat scores, and other critical criteria, helping you focus on the most pressing threats. Duplicate indicators are automatically removed, giving you a clean and actionable dataset.

Key Features:

  • Bulk IOC Searches: Quickly analyze hundreds of indicators at once.
  • Advanced Filtering: Pinpoint the most relevant threats with precision.
  • Comprehensive Enrichment: Access detailed insights about each indicator for faster decisions.

By automating time-consuming tasks, Actionable Search gives you the context to act swiftly, helping you protect your organization with confidence and efficiency. Upcoming features will enable bulk actions like tagging, updating owners, adding notes, and exporting results in one step. Also, look for unstructured imports from PDFs and DOC files and a unified view of IoCs across multiple owners to enhance collaboration and visibility.

Simplifying Queries with the TQL GeneratorAnalysts need to search for a lot of stuff: APT insights, the latest vulnerabilities, which indicators georesolve to China in the past three months with a malware tag, etc. Crafting queries in various formats like SQL, SPL, etc. can feel daunting, especially if you need to familiarize yourself with the syntax.

That includes our own ThreatConnect Query Language (TQL): until now! With the new TQL Generator, you can type your query in plain language, such as “Find all Malware related to APT28 that has activity causing it to be updated in the last week.“ The feature automatically translates your input into the correct TQL syntax, runs the query, and delivers the data you need in seconds.

Why You’ll Love It:

  • Ease of Use: Eliminate the hassle of learning complex syntax.
  • Time Savings: Execute accurate queries instantly.
  • Improved Access: Quickly uncover the intelligence needed to make informed decisions.

The TQL Generator removes barriers to querying, allowing you to focus on what matters—analyzing data and acting on threats. We are looking for future iterations of the feature to include adversary alias information and more.

Built-In Enrichment with AbuseIP ThreatConnect 7.8 includes a new, built-in AbuseIP integration that ensures you have easy access to critical IP intelligence. Without creating manual playbooks or searching multiple websites, you can assess IP addresses with confidence using data such as confidence scores, ISP details, and geographical locations.

This streamlined access allows you to make faster decisions, improving your team’s ability to identify and respond to potential threats.

Enhanced Collaboration with Intel 360Feedback and validation are critical components of the Evolved Threat Intelligence Lifecycle, ensuring that intelligence is actionable, relevant, and continually improved. ThreatConnect 7.8 introduces Intel 360, an ongoing initiative designed to facilitate this crucial step by enabling interactive feedback on intelligence reports.

With Intel 360, users can provide ratings and comments on reports, offering valuable insights that foster collaboration and enhance the quality of intelligence over time. This interactive mechanism helps analysts validate findings, refine intelligence products, and build trust across teams.

By incorporating Intel 360 into your workflow, ThreatConnect ensures that feedback isn’t just an afterthought—it’s a core part of the intelligence process, empowering your team to work with the most accurate and impactful insights. This release includes the ability for stakeholders to review Reports available to them in ThreatConnect. This makes it easier to collect feedback from people accessing finished intelligence. In a future ThreatConnect release, we intend to add more functionality to the Intel 360 featureset including the ability to collect metrics related to feedback submitted, adjust the priority of Intelligence Requirements based on stakeholder feedback, and support for additional object types beyond Reports. One of the goals of this effort is to ultimately help ThreatConnect users measure the effectiveness of the threat intelligence they are producing to ensure they are spending their time and resources on the things that will be the most impactful to their organizations.

ATT&CK v16 UpdateThreatConnect has enhanced its platform with the MITRE ATT&CK 16.0 update, which includes 19 new techniques like “Adversary-in-the-Middle: Evil Twin” and “Event Triggered Execution: Udev Rules,” 33 new software entries, and more. Customers can leverage these updates through features like the ATT&CK Visualizer, Document Import, the new Doc Analysis Playbook, and other features to help visualize relationships and streamline intelligence processes.

Other Key Enhancements

  • Hourly Updates for ThreatConnect’s Automated Threat Library (ATL): Multiple blogs now updated hourly for quicker access to critical insight
  • Details Page Updates: Easily copy and share data without reverting to legacy views, improving workflow efficiency.
  • Hyperlinks in Reports: Add and manage hyperlinks in various report sections, enhancing usability and clarity.

Why ThreatConnect 7.8 is Built for YouWith its focus on usability, efficiency, and actionable insights, ThreatConnect 7.8 addresses your daily challenges. Tools like Actionable Search and the TQL Generator eliminate tedious processes, giving you more time to focus on strategic tasks. Features like AbuseIP integration and Intel 360 help you collaborate and act confidently.

Stay one step ahead of threats and empower your team to work smarter. Explore ThreatConnect TI Ops Platform 7.8 today!

The post Higher Fidelity Investigations with Actionable Search, TQL Generator, and More in TI Ops 7.8 appeared first on ThreatConnect.

View Details

Phishing remains one of the most effective and pervasive attack methods for cybercriminals, with threats evolving in sophistication and becoming increasingly difficult to detect. To stay ahead, security teams need tools that deliver contextualized intelligence and seamless workflows to tackle these challenges. ThreatConnect and Polarity provide an integrated solution to address phishing threats effectively, empowering analysts to move from detection to resolution with greater speed and precision.

In addition to tackling traditional phishing methods, this blog will also explore how these solutions help address emerging threats, such as the exploitation of QR codes, providing security teams with the tools they need to defend against a wide range of phishing tactics.

Unified Threat Intelligence in ContextThreatConnect aggregates intelligence from sources like abuseIP, OSINT feeds, and proprietary databases, providing enriched insights into phishing indicators such as domains, IP addresses, and malicious links. Polarity enhances this by overlaying critical intelligence directly within the analyst’s workflows, eliminating the need to toggle between tools. This unified context helps analysts quickly assess risks and prioritize their response.

Streamlined Detection and EnrichmentPhishing thrives on exploiting ambiguity, but ThreatConnect and Polarity bring clarity. Analysts gain instant insights into suspicious elements by enriching artifacts like email headers or embedded URLs with actionable threat intelligence. Polarity further simplifies workflows by presenting this information in real-time, directly where analysts work, ensuring nothing is missed.

Automation Meets Human InsightThreatConnect’s playbooks automate repetitive tasks like blocking malicious senders or isolating phishing emails, allowing analysts to focus on higher-value activities. Polarity complements these automations with human-centric overlays, providing analysts with critical context for decision-making and collaboration.

AI and Collective Analytics for Smarter DecisionsUsing CAL and Polarity’s AI-driven insights, phishing indicators are cross-referenced with community-driven data and predictive analytics. This helps detect ongoing threats and anticipates future phishing tactics, enabling proactive defense.

Integrated Workflows for EfficiencyThreatConnect and Polarity integrate with tools like email gateways, SIEMs, and SOAR platforms. This ensures security teams can operate without disruption, leveraging all available intelligence to maximize efficiency and effectiveness.

Polarity’s New QR Code Recognition FeatureQR codes have become ubiquitous, seamlessly blending into our daily lives through mobile payments, restaurant menus, and promotional campaigns. However, their widespread adoption has created an opportunity for threat actors to exploit this seemingly innocuous technology for malicious purposes. Cybercriminals have weaponized QR codes to distribute malware, conduct phishing campaigns, and facilitate other harmful activities, preying on users’ trust and the often-hidden nature of the embedded content.

One common tactic is embedding malicious URLs within QR codes, leading unsuspecting users to phishing sites designed to steal login credentials, financial information, or other sensitive data. Additionally, attackers use QR codes to initiate unauthorized actions, such as downloading malware onto a victim’s device or activating harmful scripts that compromise system security. Even more sophisticated threats involve QR codes disguised as legitimate payment gateways, enabling attackers to reroute transactions to fraudulent accounts.

These risks are further amplified by the challenge of decoding QR codes without specialized tools. Users cannot visually inspect a QR code’s content, making it easy for attackers to hide malicious payloads. Security analysts face the daunting task of identifying and mitigating such threats, often under time-sensitive conditions where every second counts.

With this feature, Polarity enables analysts to extract and analyze the information embedded in QR codes, such as URLs, contact details, or other data. Polarity overlays actionable intelligence directly within the workflow, helping analysts:

  • Recognize malicious indicators within seconds.
  • Reduce the time spent deciphering QR codes.
  • Make informed decisions faster.

How It Works:

  1. Analysts trigger Polarity’s Focus Mode using the button or shortcut keys.

  2. They use the reticule to highlight the QR code.

  3. Polarity extracts the embedded information and cross-references it against its intelligence framework.

Within moments, analysts receive actionable insights on whether the QR code contains malicious indicators, allowing them to respond swiftly and accurately.

Defend Against Phishing with ConfidenceThe combined power of ThreatConnect and Polarity delivers an advanced, intelligence-driven approach to phishing threats, from email-borne attacks to QR code exploits. By equipping security teams with cutting-edge tools, real-time insights, and seamless integrations, these solutions empower organizations to defend proactively and efficiently.

Request a Demo Today to see how ThreatConnect and Polarity can strengthen your defenses against phishing threats.

The post How ThreatConnect and Polarity Empower Teams to Combat Phishing Threats appeared first on ThreatConnect.

View Details

With 2024 in our rearview mirror, let’s take a moment to reflect. Like always, threats are evolving, and security challenges are becoming… more challenging: escalations in targeted ransomware attacks, emerging techniques like adversary-in-the-middle phishing, and a stream of vendors throw all of their offerings into the mix that now need to be integrated into your tech stack. The only constant is change (and the need to operationalize threat intelligence!) Here’s a look back at the solutions we delivered to make your job easier and your defenses stronger.

Polarity: Bridging Insights Across Systems with ThreatConnectSwitching between tools during critical investigations is a frustration many security teams know all too well. That’s why ThreatConnect acquired Polarity in 2024—to deliver actionable intelligence directly into analysts’ workflows and eliminate the inefficiencies of context switching. Together, we’ve transformed how teams access and utilize threat intelligence, integrating real-time insights into their existing processes.

Polarity’s Federated Search enabled seamless querying and correlation of data across multiple systems, all within the same interface. This innovation didn’t just save time; it redefined efficiency, empowering teams to focus on the threats that matter most. With the introduction of the CAL integration, Polarity users gained direct access to 2.2 billion indicators, along with feed metadata and analytics. Backed by machine learning and natural language processing, CAL brought real-time insights, automated summaries, and reputation scoring into Polarity, enhancing threat prioritization and decision-making.

By combining Polarity’s federated search capabilities with ThreatConnect’s intelligence ecosystem, we made context switching a thing of the past. These advancements empowered security teams to move beyond reactive responses, enabling them to adopt truly proactive cybersecurity strategies with unprecedented efficiency.

Breaking Down Silos: Helping You Make Faster, Smarter DecisionsWhen attackers escalate their tactics, like chaining vulnerabilities across systems or using living-off-the-land techniques to evade detection, you need a clear, unified view of the threat landscape. This year, we tackled the problem of fragmented data with tools that bring everything together.

  • Clear Context was all about bringing the key insights you need—indicators, tags, relationships—into one view. No more hunting for information; everything was right where you needed it, so you could focus on action, not navigation.

  • The ATT&CK Visualizer brought adversary behaviors to life, mapping tactics and techniques to the MITRE ATT&CK framework. Whether it was ransomware operators targeting overlooked controls or emerging threats in your sector, you could identify gaps and prioritize defenses with confidence.

  • The Tags Across Owners Card made it easier to see the bigger picture by pulling contextual tags from multiple sources into one place.

These updates were all about helping you spend less time searching for answers and more time acting on them.

Reporting That Doesn’t Make You Want to Tear Your Hair OutWe know reporting can feel like a grind—especially when you’re trying to research or respond to a threat while at the same time trying to report on your progress and get the intel out. It has to be accurate, timely, and clear, but it doesn’t have to be so tedious.

  • Reporting Templates let you standardize and automate your reports for Groups, Cases, or whatever you need. No more reinventing the wheel every time you start a new one.

  • The WYSIWYG Editor gave you an intuitive way to create polished, stakeholder-ready reports. Whether it was detailing how a supply chain attack unfolded or summarizing your organization’s threat posture, you could focus on the story while we took care of the formatting.

Speeding Up Investigations With Tools That Work for YouInvestigations can be tough. You’re on the clock, trying to spot patterns and make connections (“Oh sweet mercy, is this double extortion ransomware??”), but the tools you have might slow you down. This year, we introduced features to help you move faster without losing precision.

  • Enhanced Search gave you advanced filters and quick-access actions to cut through the noise and get straight to the intel that mattered most.
  • With Polarity’s Federated Search, you could query multiple systems at once—no more jumping back and forth between tools. It saved time and, honestly, a lot of headaches.
  • The Match Drawer for Intelligence Requirements helped align your work with your team’s strategic goals, making it easier to prioritize what really matters.

We know your time is valuable, and we hope these updates helped you get the job done faster and with less stress.

Scaling Operations With AI and AutomationThis year, we saw attackers leverage tools like generative AI to create more convincing phishing lures and scale their operations. To help you stay ahead, we leaned into AI, too, to level the playing field.

AI Insights transformed the way teams analyzed intelligence reports. By summarizing key takeaways in seconds, this feature reduced the time spent on manual reviews and allowed analysts to focus on actionable recommendations. The consistency and accuracy delivered by AI ensure that critical insights are not overlooked. Also, now in Beta, are AI search summaries and AI report summaries.

The Automated Security Controls Mapping in the ATT&CK Visualizer helped teams identify gaps in their defenses. This feature prioritized vulnerabilities by mapping security controls to specific MITRE ATT&CK techniques and provided clear guidance on where to focus resources.

In 2024, enhancements were made to MITRE ATT&CK Classification in ATL, Doc Import, Browser, and Playbooks, enabling users to strengthen their security strategies.

Advancing Sector-Specific Intelligence With Industry ClassificationThreats don’t look the same for every organization (banks don’t usually struggle with ICS/SCADA attacks). In 2024, we took a big step forward in tailoring intelligence to your specific needs with Industry Classification. By leveraging AI to classify intelligence by NAICS codes, we made it possible for you to tag intelligence with industry-specific context.

What does that mean for you? It means cutting through the noise and focusing on the threats that matter most to your sector. Whether it’s supply chain vulnerabilities for manufacturing or targeted phishing in finance, this enhancement gave analysts the clarity to prioritize and act faster.

This wasn’t just about making things easier; it was about empowering you with the precision to make smarter, more confident decisions.

Building a Seamless Threat Intelligence EcosystemWe know your tools need to talk to each other, especially when trying to track fast-evolving threats across different environments. That’s why we focused on integrations to create a more connected ecosystem.

  • Recorded Future and CrowdStrike integrations enriched your workflows, giving you the context you needed to make decisions faster.
  • Elastic Security and Microsoft Copilot integrations ensured you could operationalize intelligence seamlessly, whether you were responding to a phishing campaign or preparing for a tabletop exercise.

By connecting your platforms, we made it easier to turn intelligence into action right when and where you needed it.

Looking Ahead2024 was a year of innovation, and we’re so grateful to have been part of your journey. From tackling targeted ransomware to breaking down silos in your workflows, we’ve worked hard to deliver tools that make your life easier and your defenses stronger.

As we head into 2025, we’re excited to keep pushing the boundaries of what’s possible in threat intelligence. Thank you for trusting us to be part of your cybersecurity story. We look forward to another year of collaboration, innovation, and progress.

The post ThreatConnect’s 2024 Year in Review: Let’s Celebrate What We’ve Accomplished Together appeared first on ThreatConnect.

View Details

ISO 27001 has long set the standard for managing information security. Still, the 2022 updates bring a critical shift: organizations must now effectively process and analyze threat intelligence to stay ahead of increasingly sophisticated threats. These updates go beyond compliance, challenging organizations to integrate actionable intelligence and streamline security operations.

For many, this introduces new complexities—fragmented data, resource constraints, and the pressure to operationalize intelligence in real-time. This can be especially challenging for organizations that might not have an existing, fully mature threat intelligence program.

That’s where ThreatConnect makes the difference.

With its TI Ops Platform built around the Evolved Threat Intelligence Lifecycle, ThreatConnect simplifies compliance and empowers organizations to move beyond the basics, strengthening their overall security posture. This blog will break down the key updates in ISO 27001:2022 and show how ThreatConnect enables you to meet and exceed these new requirements, even if you don’t already have a mature intel program.

What is ISO 27001?ISO 27001:2022 is the internationally recognized Information Security Management Systems (ISMS) standard. It establishes a framework for managing sensitive information securely. The 2022 update introduces new elements, with a key focus on the processing and analysis of threat intelligence. This shift underscores the importance of actionable insights—prioritizing the quality of intelligence over sheer volume—to strengthen risk management and incident response.

What is the New Requirement? (5.7)The updated Annex A, Control 5.7, introduces “Threat Intelligence” as a formal requirement. This control mandates organizations to collect, analyze, and act upon intelligence related to threats that could impact their operations. By doing so, organizations can proactively identify risks and develop robust defenses.

What is Required for Compliance?To meet the requirements of ISO 27001:2022 Annex A Control 5.7, organizations must:

  • Periodically Review Threat Landscapes: Stay updated on reports from authoritative sources, such as government agencies and industry groups.
  • Identify Threat Sources: Map potential adversaries, including insiders, competitors, and cybercriminals.
  • Analyze Emerging Trends: Evaluate novel attack vectors and evolving tactics based on past incidents and current intelligence.
  • Build Resilient Defenses: Implement measures that mitigate security threats effectively.

Organizations are advised to incorporate three levels of threat intelligence:

  • Strategic Intelligence: High-level trends in the threat landscape, including actor profiles and attack motivations.
  • Tactical Intelligence: Insights into the tools, techniques, and procedures (TTPs) used by adversaries.
  • Operational Intelligence: Detailed, actionable data such as technical indicators of compromise (IOCs) for specific threats.

Effective threat intelligence must be relevant, contextual, perceptive, and actionable to drive informed decision-making.

Challenges in Meeting ISO 27001:2022While ISO 27001:2022 introduces critical advancements, many organizations face common hurdles in meeting the updated requirements:

  • Fragmented Data Sources – Threat intelligence is often scattered across multiple platforms, making it difficult to correlate and derive actionable insights.
  • Limited Resources – Small or overstretched teams may need more expertise and bandwidth to process and analyze large volumes of threat data effectively.
  • Operationalization Gaps – Turning intelligence into action is challenging due to disconnected workflows and insufficient integration with security operations.
  • Reliance on Manual Processes – Manual efforts in collecting, analyzing, and reporting intelligence are time-consuming, error-prone, and unsustainable as threat volumes grow.

These challenges slow compliance efforts, increase vulnerability to evolving threats, and weaken overall security posture. Overcoming them requires centralized intelligence, automation, and streamlined workflows—key capabilities a TIP like ThreatConnect can deliver.

How a Threat Intel Platform (TIP) HelpsA Threat Intelligence Platform (TIP) simplifies the journey to ISO 27001:2022 compliance by addressing organizations’ core challenges in managing and operationalizing threat intelligence. Key capabilities include:

  • Centralizing Intelligence: A TIP consolidates data from diverse sources, such as open-source feeds, commercial providers, government advisories, and internal logs, into a single, unified platform. This gives security teams a holistic view of the threat landscape, making identifying and analyzing risks easier.
  • Prioritizing Risks: TIPs use advanced algorithms, scoring systems, or contextual data to prioritize threats based on their relevance and potential impact. This ensures resources are allocated efficiently, focusing efforts on the most critical risks.
  • Automating Workflows: By automating repetitive tasks like data ingestion, enrichment, and reporting, TIPs significantly reduce the manual effort required for compliance. This improves response times and seamlessly integrates intelligence into incident response processes.
  • Enhancing Contextual Awareness: A TIP directly integrates threat intelligence into existing workflows and tools, such as SIEMs or SOAR platforms, providing real-time insights where needed. This contextualized intelligence enables faster, more informed decision-making.

Commercial TIP vs. Building Your Own (BYOTIP)Building your own Threat Intelligence Platform (BYOTIP) might seem like a viable solution, but it introduces significant complexity, cost, and maintenance overhead. Developing an in-house platform requires extensive resources, including skilled developers, analysts, and engineers, to design, build, and maintain the system. Additionally, BYOTIPs often need more commercial platforms’ scalability and advanced features, such as automated enrichment, dynamic integrations, and continuous updates.

In addition, if you don’t already have a mature threat intelligence team, a BYOTIP introduces its own complexity because it might lack embedded tradecraft critical for ISO 27001 compliance.

In contrast, a commercial TIP, like ThreatConnect, is purpose-built to address these challenges out of the box. It provides a scalable, ready-to-use solution with prebuilt integrations, advanced analytics, and ongoing support. Organizations can fast-track their compliance efforts by choosing a commercial TIP, reducing operational burdens, and improving their security posture instead of managing complex development projects.

Why ThreatConnect is the Best TIP for ISO 27001:2022 ComplianceWhen it comes to navigating ISO 27001:2022, ThreatConnect stands out as the optimal choice for a Threat Intelligence Platform (TIP). Unlike other solutions, ThreatConnect doesn’t just help you meet compliance requirements—it transforms your approach to security by integrating intelligence, automation, and risk-based decision-making into a unified platform.

  • CAL – The Brain Behind ThreatConnect – At the heart of ThreatConnect is the CAL, a unique capability that turns raw data into actionable insights. CAL enriches your threat intelligence by aggregating and analyzing data across the ThreatConnect community. This provides contextualized intelligence that helps you prioritize threats based on their relevance to your organization’s environment. By using CAL, you gain deeper visibility into the global threat landscape while focusing your efforts on the risks that matter most.
  • Risk-Based Decision-Making – ThreatConnect seamlessly integrates threat intelligence with risk quantification to align security efforts with business priorities. You can demonstrate to stakeholders and auditors how threat intelligence directly supports risk mitigation and compliance goals. Instead of generic threat data, ThreatConnect empowers you to make decisions based on threats that pose the most significant risk to your assets.
  • Automation and Orchestration – Automation is critical for streamlining ISO 27001 compliance, and ThreatConnect excels in this area. The platform automates key workflows, such as data ingestion, enrichment, and response actions, freeing valuable time and resources. With prebuilt integrations to leading security tools and platforms, ThreatConnect enables seamless orchestration across your security stack, eliminating silos and ensuring intelligence flows smoothly into your operations.
  • Polarity Integration for Real-Time Contextual Insights – Through Polarity, ThreatConnect delivers contextualized intelligence directly into user workflows. Polarity’s Federated Search capability allows analysts to surface relevant intelligence in real-time, reducing the need to switch between tools and accelerating decision-making. This ensures that your team has the correct information at the right time to act decisively against emerging threats.
  • Scalability and Support for Your Security Maturity – Unlike many other TIPs, ThreatConnect grows with your organization. Whether you’re just beginning to implement threat intelligence or seeking to mature your program, ThreatConnect’s platform is designed to support your journey. The platform helps you go beyond compliance by advancing your security maturity with features like advanced analytics, predictive insights, and enhanced reporting.
  • Unified Platform for Efficiency and Effectiveness – ThreatConnect offers a unified platform that eliminates the need for disparate tools and manual processes. By centralizing threat intelligence and integrating it with other security functions like incident response and vulnerability management, the platform ensures that your efforts are coordinated and efficient. This not only simplifies compliance but also strengthens your overall security posture.

Elevating Security: Beyond ComplianceISO 27001:2022 isn’t just about meeting regulatory requirements—it’s an opportunity to elevate your approach to security. The updated standard demands a smarter way to process, analyze, and act on threat intelligence, and ThreatConnect provides the tools to do it efficiently and effectively.

With the Evolved Threat Intelligence Lifecycle, ThreatConnect helps you unify intelligence, prioritize risks, and operationalize insights across your security workflows. This simplifies compliance and enhances your organization’s ability to anticipate, respond to, and mitigate emerging threats.

By choosing ThreatConnect, you’re not just checking the compliance box—you’re building a security program designed for resilience, scalability, and long-term success. Ready to take your threat intelligence and security operations to the next level? Request a demo today!

The post Navigate ISO 27001:2022 Compliance with ThreatConnect appeared first on ThreatConnect.

View Details

A rapidly evolving cyber threat landscape demands that organizations adopt more than reactive defenses—they need proactive, intelligence-driven strategies. The Threat Intelligence Maturity Model (TIMM) serves as a roadmap for organizations to assess, plan, and advance their cyber threat intelligence (CTI) capabilities, regardless of their journey.

The Five Levels of Threat Intelligence MaturityThe TIMM provides a structured framework to guide organizations through the evolution of their CTI programs. Let’s take a closer look at each stage of maturity:

Maturity Level 1

1. Initial (Getting Started):Organizations at this level are just beginning their CTI journey. Data collection is ad-hoc, often scattered across spreadsheets or emails. Threat data needs to be refined, creating challenges in deriving actionable insights. The focus here is on aggregating internal and external threat data, organizing it in a central repository, and laying the foundation for future growth.

Maturity Level 2

2. Managed (Warming Up):At this stage, organizations begin formalizing processes and adopting essential tools to manage threat intelligence. Teams are moving beyond purely reactive responses by using vetted threat intelligence feeds to block threats at the perimeter. Documentation of workflows and establishing a system of record for CTI data mark significant progress.

Maturity Level 3

3. Defined (Expanding Capabilities):CTI teams have started producing operational and tactical intelligence while automating repetitive tasks like data enrichment. Organizations define key use cases at this level, such as improving threat detection and building a unified threat library. Automation and visualization tools begin to play a critical role in enabling proactive threat identification.

Maturity Level 4

4. Quantitatively Managed (Operationally Established):Organizations at this level have robust, documented workflows, multiple threat intelligence data sources, and a well-structured approach to strategic analysis. Teams track and act on persistent threat actors, contribute to information-sharing communities, and align intelligence outputs with broader security operations. Measuring CTI program effectiveness becomes a key focus.

5. Optimizing (Driving Strategic Impact):Maturity Level 5

At the pinnacle of maturity, organizations fully operationalize CTI, leveraging automation, AI-driven analytics, and codified workflows to deliver actionable intelligence at scale. CTI becomes a strategic asset, informing C-level decisions and supporting incident response, risk management, and offensive security efforts. Teams at this level are proactive, hunting threats before they materialize and continuously refining their operations to stay ahead of adversaries.

Why the Maturity Model MattersThe TIMM provides a clear pathway for organizations to grow their CTI programs in alignment with their resources and needs. It acknowledges that not all organizations will reach the highest level of maturity—and that’s okay. The key is to use the model to identify opportunities for improvement, whether it’s automating repetitive tasks, improving data analysis, or integrating intelligence into broader security strategies.

Ready to Advance Your Threat Intelligence Program?No matter where your organization stands today, the Threat Intelligence Maturity Model can help you plan your next steps. By understanding the distinct stages of maturity, you can identify gaps, prioritize investments, and build a CTI program that delivers measurable value.

Download the complete Threat Intelligence Maturity Model whitepaper to explore actionable insights and practical guidance for maturing your CTI program. Let’s take your threat intelligence to the next level.

The post Unlocking the Potential of Cyber Threat Intelligence: A Guide to the Threat Intelligence Maturity Model appeared first on ThreatConnect.

View Details

Security teams face constant pressure to sift through vast data to identify threats, assess risks, and respond promptly. Imagine a scenario where a Cyber Threat Intelligence (CTI) team is investigating a sophisticated phishing campaign targeting their organization. Clues are minimal, and time is critical. This is where the Microsoft Copilot for Security integration with ThreatConnect becomes a game-changer.

The ChallengeOne morning, reports came in about a potential phishing attack. Several employees have received suspicious emails that appear legitimate but contain malicious links. These emails are highly targeted, mimicking internal communications with an unknown threat actor behind them. The CTI team’s objectives are clear:

  • Identify the indicators of compromise (IOCs) in the phishing emails.
  • Determine if the threat aligns with known adversary patterns.
  • Produce actionable intelligence to inform the incident response team’s strategy.

Faced with limited information and the need for a quick response, the CTI team turns to the integrated Microsoft Copilot for Security within ThreatConnect.

How the Microsoft Copilot Integration Enhances the InvestigationStep 1: Rapid IOC IdentificationUsing Copilot’s natural language processing capabilities, the team inputs:

“What does ThreatConnect know about the domain ‘secure-update-notice.com’?”

Copilot rapidly searches ThreatConnect’s intelligence data, providing a concise summary:

  • The domain has been flagged in recent phishing campaigns.
  • It’s linked to a threat actor group known as “Silver Falcon.”
  • Related IOCs include specific IP addresses and malware hashes.

Step 2: Investigating Threat Actor GroupsTo gain a broader understanding of the adversary, the team uses a skill command:

/tcGetGroups adversary called “Silver Falcon”

Copilot retrieves comprehensive information on Silver Falcon, including their tactics, techniques, and historical campaigns. This provides immediate context, suggesting that the phishing attack may be part of this group’s larger, coordinated effort.

Step 3: Generating Advanced TQL QueriesThe team needs to uncover related indicators within their data. Instead of manually crafting complex queries, they use Copilot to generate a ThreatConnect Query Language (TQL) query:

/tcGenerateBasicTQL indicators associated with “Silver Falcon” from the past 30 days

Copilot generates a ready-to-use TQL query, saving valuable time and enabling the team to pull relevant intelligence for analysis quickly.

Step 4: Summarizing Intelligence for StakeholdersTo communicate findings efficiently, the team requests a summary from Copilot:

“Summarize key findings related to the phishing attack and Silver Falcon.”

Copilot generates a precise summary, highlighting the critical aspects:

  • The phishing campaign is targeting financial sector organizations.
  • Silver Falcon employs sophisticated social engineering tactics.
  • Recommended mitigations include blocking identified domains and IPs and enhancing team member awareness.

The Impact of Microsoft Copilot IntegrationUsing the Microsoft Copilot Integration for ThreatConnect, the CTI team completes the investigation with impressive efficiency:

  • Time Savings: Cut the time to gather and analyze data from hours to minutes.
  • Increased Accuracy: Reduced the risk of missing critical indicators or connections.
  • Effective Communication: Enabled concise summaries for quick team alignment.
  • Swift Response: Empowered the security team to implement countermeasures promptly.

Why This Integration Matters for CTI TeamsThe integration of Microsoft Copilot’s AI with ThreatConnect brings several benefits to CTI teams:

1. Faster Analysis and Investigation: Natural language queries and skill commands provide rapid access to relevant intelligence without manual searches.

2. Task Automation: Automated generation of queries and summaries alleviates the workload on analysts, allowing them to focus on complex issues.

3. Improved Collaboration: AI-driven summaries and reports make sharing insights with broader teams and decision-makers easier.

4. Enhanced Threat Intelligence: The ability to process and summarize large datasets enables the team to generate richer, more actionable intelligence.

Empowering Cybersecurity with AIThis case demonstrates the transformative power of integrating Microsoft Copilot with ThreatConnect for any CTI team. As they work to stay ahead of emerging threats, this integration accelerates their processes, enhances data quality, and provides an AI-powered ally to help make informed, timely decisions.

Microsoft Copilot for Security, integrated with ThreatConnect, offers a powerful and efficient solution for organizations looking to elevate their security operations. Visit the ThreatConnect Marketplace to explore the integration and see how it can strengthen your cybersecurity defenses.

The post Solving Complex Threats with Microsoft Copilot Integration for ThreatConnect appeared first on ThreatConnect.

View Details

As a CTI analyst, you know that advanced threats often evade traditional security tools, leaving gaps that can put your organization at risk. Whether starting from scratch or seeking to elevate your current threat-hunting program, the challenge is real: you need to hunt for these hidden threats proactively, but building a structured, effective program takes both strategy and the right resources. You’re likely working against limited time and increasing threats, and without a clear framework, hunting can feel like finding a needle in a haystack.

To address this, shifting from purely reactive security to a proactive, hypothesis-driven approach is essential. Here are five foundational tips to guide you in setting up or leveling up your threat-hunting practice, enabling you to identify and neutralize threats before they cause harm.

1. Define Clear ObjectivesFirst, clarify what you aim to accomplish. Are you trying to reduce “dwell time”—the period adversaries go undetected in your network—or are you focused on mitigating specific threats? Setting clear objectives helps you establish priorities, measure success, and align your program with organizational security goals.

2. Use Hypothesis-Driven HuntingUnlike reactive methods, threat hunting thrives on educated guesses. Based on abnormal behaviors you observe, like unexpected access or unusual login times, develop hypotheses around specific attack scenarios. Hypothesis-driven hunting enables your team to actively pursue potential threats, focusing on areas where risks are highest.

3. Integrate Threat Intelligence for ContextThreat intelligence adds critical context by offering insights into adversaries’ tactics, techniques, and procedures (TTPs). With platforms like ThreatConnect, you can integrate real-time intelligence directly into your workflow, using enriched data to develop more accurate hypotheses and stay ahead of emerging threats.

4. Leverage Automation and Advanced ToolsAs your team grows, automation becomes essential. Automated data enrichment and federated search tools like Polarity allow you to instantly access and correlate threat data across multiple sources, reducing time spent on manual processes and improving accuracy in identifying potential threats.

5. Commit to Continuous ImprovementThreat hunting is a dynamic process. Review your findings regularly, refine your methods, and adapt to evolving adversarial tactics. Changing your program ensures your team remains agile and prepared to tackle new threats.

ThreatConnect’s Threat Intelligence Operations platform and Polarity are game-changers for SOC teams looking to enhance their threat-hunting capabilities. ThreatConnect’s TI Ops Platform provides a centralized hub for managing and operationalizing threat intelligence, allowing analysts to easily correlate data, prioritize investigations, and generate hypotheses based on enriched context-driven insights.

Paired with Polarity’s federated search, which gives analysts instant access to threat intelligence across multiple sources, these tools streamline the hunting process, enabling your team to uncover hidden threats faster and more accurately.

ThreatConnect and Polarity empower analysts to conduct deeper investigations, automate repetitive tasks, and focus on the highest-priority threats.

Want to Learn More?Download Operationalizing Threat Hunting: A Complete Guide for more detailed guidance. This resource provides a step-by-step framework, helping you build and mature a proactive, resilient threat-hunting program that meets today’s challenges head-on.

The post Five Quick Tips to Enhance Your Threat Hunting Program appeared first on ThreatConnect.

View Details

Unlock Enhanced Threat Detection with ThreatConnect and CrowdStrikeIn today’s fast-paced cybersecurity landscape, security teams face many alerts and struggle to filter through false positives to prioritize critical incidents. The integration of ThreatConnect and CrowdStrike Falcon Insight XDR offers a powerful solution to this challenge, empowering security operations teams with high-fidelity threat intelligence and seamless integration across their security tools.

Why the ThreatConnect + CrowdStrike Integration MattersThis integration combines CrowdStrike’s Falcon Intelligence and Solutions, like Falcon Insight XDR, with ThreatConnect’s TI Ops Platform. This combination provides a “single source of truth” for threat intelligence, reducing noise and improving response times. By leveraging multiple intelligence sources, security teams can make more informed decisions and act faster, ranging from CrowdStrike to community and open-source feeds.

Key Benefits Faster Threat and Vulnerability Analysis: Enhance the utility of CrowdStrike Falcon Intelligence by incorporating it directly into the ThreatConnect platform, streamlining workflows, and improving response efficiency. * Amplified Power of CrowdStrike Solutions: Operationalize high-fidelity intelligence to optimize the performance of Falcon Insight XDR and other CrowdStrike tools, helping to reduce false positives and increase actionable insights. * Optimized Threat Intel Feeds: The ThreatConnect platform curates and refines CrowdStrike’s threat intelligence feeds to ensure your organization’s detection and response tools receive the most relevant data for enhanced security outcomes. * Rapid Time-to-Value*: With pre-built, out-of-the-box apps, integrating ThreatConnect and CrowdStrike can be done in no time, allowing you to start leveraging the combined power of these platforms immediately.

Use CasesThe integration addresses critical use cases for cybersecurity operations, including:

  • Building a unified Threat Library with CrowdStrike Falcon Threat Intelligence
  • Enhancing threat detection and prevention capabilities across multiple security solutions
  • Accelerating incident response and threat-hunting activities with enriched, actionable intelligence

How to Get StartedIf you’re already a customer of ThreatConnect and CrowdStrike, integrating with ThreatConnect’s pre-built apps from the Crowdstrike Marketplace is easy. If you still waiting to become a CrowdStrike user, learn more here.

About ThreatConnectThreatConnect is a leading platform enabling organizations to streamline and operationalize their threat intelligence operations. By combining AI-powered insights with automation, ThreatConnect helps enterprises detect and mitigate threats faster and more efficiently.

The post Unlock Enhanced Threat Detection with ThreatConnect and CrowdStrike appeared first on ThreatConnect.

View Details

In the current cybersecurity environment, organizations face a barrage of alerts concerning suspicious activities that can quickly overwhelm their security teams. CTI Analysts must navigate this complexity while ensuring they can accurately identify genuine threats amidst false positives. This challenge is especially pronounced in industries where the stakes are high and the need for precision is critical. This is where ThreatConnect’s CAL integration with Polarity becomes a valuable asset.

Global, Ground-Truth Insights on Threats in the WildNone of us is as smart as all of us. The insights an analyst gets at another company or organization can give advance warning of threats targeting you. CAL captures billions of these insights, anonymizes them, and gives you the benefit of experience gained by tens of thousands of analysts.

This indicator was recently reported in real SIEMs across the globe, and other analysts have looked at it in the past week. No one has identified it as a false positive. It’s probably worthy of attention!

Timely and Actionable InsightsCAL aggregates large datasets from various intelligence sources and combines them with its own analytics to uncover actionable insights relevant to the analyst’s context. The analyst can quickly identify new areas for deeper investigation, ensuring they focus on genuine threats. This capability enhances their efficiency and allows them to respond more effectively.

CAL also compiles data from hundreds of blogs, intel feeds, government bulletins, and other sources into a single dataset. All of these indicators are made machine-readable and available to analysts through Polarity.

Reducing Alert FatigueAlert fatigue is a common challenge in cybersecurity. CAL helps mitigate this by consolidating billions of indicators into a single score, which presents the criticality of each IoC. Using this score, analysts can rapidly assess which indicators need immediate attention and which can be deprioritized, reducing the risk of overlooking significant threats and wasting time on false positives.

CAL has identified this indicator as an active and critical threat.

AI-Based Indicator ClassificationCAL uses machine learning and other techniques to automatically classify every indicator that it collects, including insights like:

  • Suspicious Host Classification: Identifies hosts that have resolved to known malicious IPs or have shown suspicious activity patterns.
  • Dynamic DNS and Tor Exit Node Detection: Flags indicators related to anonymization services, like dynamic DNS and Tor nodes, that are often associated with malicious behaviors.
  • Cloud Infrastructure Detection: Distinguishes indicators tied to cloud service providers like AWS, Google Cloud, or Azure to identify infrastructure that might be used for hosting attacks.
  • Malicious IP Resolution: Tracks indicators resolving IP addresses known for hosting malware or phishing content.
  • Frequency of Resolution: Detects hosts that rapidly resolve to different IP addresses, which can be an indicator of malicious command and control (C2) infrastructures.
  • Suspected DGA – The host may have been generated by a domain generation algorithm (DGA), a tactic frequently employed by malicious actors to create multiple domains to leverage during cyber attacks.

Automatic classifiers can inform whether to investigate, escalate, act, or deprioritize.

A Practical ApplicationPolarity customers can more quickly and efficiently identify critical threats that could have been missed without ThreatConnect’s CAL integration. CAL enables analysts to respond effectively to evolving threats by streamlining their workflow and providing essential insights. For organizations seeking to enhance their threat intelligence capabilities, ThreatConnect CAL provides efficient and informed cybersecurity operations.

CAL is available to all Polarity customers.

Want to Learn More?For more information on CAL and Polarity, download the CAL integration solution brief. Want to learn more about Polarity by ThreatConnect? Take an interactive tour or request a demo to see how Polarity modernizes security operations.

The post ThreatConnect CAL™: New, Unique Intelligence for Polarity appeared first on ThreatConnect.

View Details

Security teams face constant challenges in managing vast amounts of threat data and quickly identifying what matters most. ThreatConnect’s TI Ops 7.7 release addresses these needs with new features like Enhanced Search and Clear Context, designed to streamline threat detection and analysis. By enhancing search precision and consolidating critical information, these updates help teams work more efficiently and respond to threats faster.

Let’s dive into how these features can make a real difference in your daily security operations.

Explore these updates with our TI Ops 7.7 interactive demo

Enhanced Search: Precision in Threat DetectionThe latest Enhanced Search improvements provide meaningful capabilities for threat intelligence analysts, with new tools to efficiently navigate datasets, prioritize alerts, and focus on significant threats. By offering advanced filtering and contextual information, this feature helps security teams quickly identify and respond to the most pressing threats.

Key Features:

  • Highlighted Matches: The latest Enhanced Search updates now highlight the matches within search results, making it easier to see which fields contain relevant data.
  • Advanced Filtering Options: Users can filter search results by matched columns, such as Artifacts, Attributes, Descriptions, Tags, and more. This allows for comprehensive pattern searches and targeted investigations.
  • Context Menu Actions: Quick access to relevant actions such as adding items to the exclusion list, exploring in graph view, visualizing ATT&CK tactics, and viewing details directly from the search results.

Streamlined Threat Analysis with Clear Context FeaturesThreat analysis tools can often be fragmented, requiring users to navigate through multiple clicks and pages to find necessary information. Clear Context addresses this by consolidating critical data into easy-to-find locations. New Clear Context features introduce significant updates into the 7.7 release, aimed at enhancing user experience by providing easily understandable and actionable context for threat analysis.

New Clear Context Features:

  • Unified View – Indicator Details Drawer: This feature displays key information such as the earliest date added, owner, last modified date, and more, all in one place.
  • Consistent Group Details Drawer UI: Updates to the Group Details Drawer make it consistent with the Indicator Drawer UI, providing clarity and reducing navigation complexity.

Additional Features in 7.7 ReleaseWait, there’s more! The 7.7 release includes several other valuable features:

  • Intelligence Requirements – Date Filtering: Improved filtering capabilities allow users to filter intelligence requirements by date added and last modified, helping focus on the most recent and relevant data.
  • Graph Updates: Users can now add associations to groups and indicators directly within the graph, enhancing visual representation and decision-making.
  • Reporting Template Updates: Allows for the presetting of Group Templates with selected attribute types and filters to associate groups and indicators.

TI Ops 7.7 brings practical improvements that help security teams work smarter. Enhanced Search allows for more precise threat detection, while Clear Context reduces the time spent navigating data, letting analysts focus on response. Alongside other updates like Intelligence Requirements filtering and Graph enhancements, these features equip teams to better manage and act on threat intelligence.

If you are ready to see how ThreatConnect can help your organization operationalize threat intelligence, please contact sales@threatconnect.com or request a custom demo today.

The post ThreatConnect TI Ops Platform 7.7: Boost Your Security Team’s Efficiency appeared first on ThreatConnect.

View Details

The Power of Force Multiplication“Threat intelligence is like the Force: it should flow through everything.”

-Andy Pendergast, Co-Creator of the Diamond Model of Intrusion Analysis and Co-Founder of ThreatConnect

“Remember, a Jedi can feel the threat intelligence flowing through them.”

-Obi-Wan Kenobi (probably)

ThreatConnect is launching a new product to complement our Threat Intelligence Operations (TI Ops) platform. It provides real-time, contextual access to threat intelligence across every tool security analysts use. Read on to learn more.

Close your eyes and reach out with your feelings: imagine a SOC analyst, buried under alerts, struggling to connect the dots: “Is this a threat? Do I need to escalate? Do I need to take action? Is it a wild goose chase?” The answers are there, but the needed intel and insights are spread across so many different intelligence sources that it feels impossible to find the right context to make a decision. Now imagine if, instead, the intelligence the analyst needed flowed as easily through them as the Force for a Jedi Master.

Making threat intelligence an essential part of the cybersecurity organization has been at the heart of ThreatConnect since our founding; CTI should flow through everything: reducing false positives in the SOC, speeding MTTR in Incident Response, and helping threat hunters stay on target. It’s part of why we introduced the Evolved Intelligence Cycle.

Intel production is the beginning of cyber defense, not the end.

Threat intelligence exists to inform action: it’s as much about the Consumers of intel as historically it’s been about the Producers. For a long time, the critical “Dissemination and Integration” bridge step has been a challenge. How does an intel analyst get the right intel into the right hands at the right time? How does a SOC analyst receive that intel where and when they need it? How do you let the threat intelligence flow through you?

That’s where the new Polarity Intelligence Edition comes in. Unlike legacy TIPs, which focus primarily on feed aggregation, the pairing of our TI Ops platform with the new Polarity Intelligence Edition makes it easier for the entire cybersecurity organization (SOC, IR, threat hunting, etc.) to access intelligence when and where it’s needed – without even needing to log in to a separate platform!

Bridging Intel Producers and Intel ConsumersWhat good is intelligence if it can’t be operationalized? Unused intelligence wastes time and effort and does nothing to improve organizational security posture. Traditional threat intelligence platforms (TIPs) focus on feed aggregation, which provides a single view of the truth, but it often sits there unused. That intel can be deployed to tools like SIEMs, but not every analyst works inside the SIEM, or the information in the SIEM doesn’t give them fast enough answers. Further, as highlighted below, it’s not always presented in an easily actionable way. The result is that smart, valuable analyst resources are wasted, and threats fall through the cracks.

Problems with other traditional solutions include:

  • Sharepoint, Google Drive, email, and even legacy threat intelligence platforms create massive gaps in consistency and accuracy
  • RFIs and other “pull” style implementations take time to fulfill and require active participation from the consumer.
  • Threat Intelligence Browser Extensions can provide context on IOCs, CVEs, and other intelligence but are often focused on the intelligence from a single provider and are always limited to operating within the browser and thus cannot help when working in other desktop applications.
  • SOAR tools are designed to automate, not disseminate, and leveraging them to provide threat intelligence requires a tremendous amount of configuration. Plus, they offer limited access to more targeted, relevant intel.
  • Federated search tools that purport to solve this problem require considerable setup and investment in large data lake infrastructure.

On top of that, users may need CTI insights whenever and wherever they work – none of those solutions can do that. The end result is that:

  • Traditional methods of disseminating threat intel leave gaps,
  • Manual processes slow down and complicate intel production,
  • Response times are slowed down, and
  • Existing tools require complex setups and only provide partial solutions.

This is not the way.

Introducing Polarity Intel EditionThreatConnect offers the only TI Ops platform that effectively streamlines all steps in the Evolved Intel Cycle. With Polarity Intel Edition, we now offer new capabilities dedicated to usable dissemination that are able to fully close the loop.

Thanks to ThreatConnect’s recent acquisition of Polarity, we’re excited to announce Polarity Intel Edition: a low-friction way to consume intelligence when they need it, literally while doing their analysis on their screen. In CTI terms, Polarity Intel Edition allows our customers to fully close the intel cycle with minimal effort. It’s specifically designed to smooth the way for intel consumers like SOC analysts, incident responders, and threat hunters to take advantage of what is produced by CTI teams. It integrates seamlessly with our TI Ops Platform so the intel can flow freely and easily. It delivers real-time insights, access to many popular intel integrations, and a lighting-fast setup right out of the box.

Specifically, Polarity Intel Edition provides:

  • Federated Search across your essential threat intelligence and enrichment data for insights and contextualization (e.g. ThreatConnect, Premium Intel Providers, VirusTotal, Shodan, etc).
  • Frictionless access to the aggregated intel in our TI Ops platform, including our AI-powered Automated Threat Library, which brings in hundreds of blogs and government bulletins and turns them into human- and machine-readable threat intelligence.
  • Ground truth inside our Collective Analytics Layer includes data like reported false positives, measures of analyst interest and real-world observations, malware classification, DNS, historical geolocation, and more. Paired with the Automated Threat Library, it’s the perfect way to get started with intelligence or supplement a mature program.
  • The AI Assistant in Polarity interfaces with approved GenAI LLMs to gain insights faster and generate summaries on intel.
  • Directly add new and update existing threat intelligence inside our TI Ops platform.

Let’s dive a little deeper into the specific capabilities.

It’s Real TimePolarity: Intel Edition provides a real-time data overlay of in-context intelligence that flows to your analysts wherever, whenever, and to whomever it’s needed. This saves time, allows for on-demand searching and correlation, and ensures that no one misses out on impactful CTI. This works whether you’re on the web or using desktop or native applications. It also means there’s no need to go through multiple interfaces to access popular intel sources like Flashpoint, Recorded Future, VirusTotal, Silent Push, Greynoise, Mandiant Threat Intel, and many more.

Our real-time overly highlight indicators of compromise with the most relevant intelligence.

It’s FastWhile there might be similar solutions out there, Polarity is the only one that requires almost no setup. We offer 50 integrations (with more available in our Enterprise edition!) that can be turned on with a simple “on” switch (literally). This helps analysts integrate large, relevant datasets with a very low learning curve.

Integrations are ready to go right out of the box.

It Has AI that Actually Does Something UsefulAs part of this low-cost offering, we’re also including AI summaries. That means a busy analyst can get a quick report of all the data available on an indicator from all of our popular intelligence integrations. It’s like having an intern run out, collect data from dozens of different sources, come back, and compile it into a report (hopefully without any mistakes) – except this LLM-based intern does it in seconds.

All of the intel sources are consolidated via AI into an easily human-readable summary.

It Closes the Intel CycleIf you’ve chatted with me over the years, you’ll know that one of my favorite slices of pie in the intel cycle is Feedback and Validation; it’s also one we often hear from customers. As a customer told me once, “Our most valuable intelligence feed is our own SOC and IR teams.” Polarity: Intel Edition allows users to send indicators, insights, tags, and more back into ThreatConnect so that those insights can add ground truth to your single source of truth.

Report false positives, adjust threat ratings, and organize indicators in ThreatConnect’s TI Ops platform directly from the Polarity overlay.

I Want to Learn the Ways of the ForceTo sum up, the new Polarity Intel Edition (PIE) revolutionizes how your team consumes and acts on threat intelligence. With real-time, in-context data overlays and AI-powered summaries, PIE ensures that crucial intel flows seamlessly into the hands of those who need it, precisely when they need it.

Whether you’re a CTI analyst producing heroic intelligence but don’t have an easy way to share that story, whether you’re a SOC or IR analyst looking to improve efficiency and reduce false positives, or whether you’re a team leader who wants to help your team improve key metrics like MTTR, sign up for a demo now!

Beyond the BasicsIf Polarity Intel Edition has whet your appetite for the industry’s first Contextual Intelligence and Response Platform that does real-time data augmentation across all your tools, then the full edition of Polarity is an easy upgrade. Take a look here to learn more.

Learn MorePolarity Intel Edition is now available as a cost-effective add-on module for all ThreatConnect TI Ops customers and for organizations using legacy threat intelligence platforms. Learn more at https://threatconnect.com/polarity-intel-edition/ or register to attend an informational webinar on October 2, 2024, at 9:00 AM PT / 12:00 PM ET / 5 PM BST.

The post ThreatConnect Launches Polarity Intel Edition to Streamline Intelligence for SecOps Teams appeared first on ThreatConnect.

View Details

Organizations must adopt a practice of continuous improvement to maintain relevant and agile intelligence requirements, which are crucial in today’s rapidly evolving cyber threat landscape. Here are the top five best practices for refining and updating your intelligence requirements to stay ahead of evolving threats.

  1. Regularly Monitor and Assess the Threat Landscape and Adjust RequirementsCyber threats are dynamic and constantly changing. New vulnerabilities are discovered every day. Threat actor tactics, techniques, and infrastructure change with increasing frequency. To keep intelligence requirements up-to-date, organizations should evaluate and update their requirements on a regular schedule, i.e., quarterly, bi-annually, or annually. This involves:

  2. Staying Informed: Stay current with the newest threat intelligence reports, security bulletins, and industry news to stay ahead of potential cybersecurity risks.

  3. Threat Analysis: Regularly analyze emerging threats and their potential impact on your organization.
  4. Updating Requirements: Adjust intelligence requirements to address new threats, ensuring your organization can proactively respond.

  5. Align Intelligence Requirements with Organizational ChangesAs organizations grow, e.g., through mergers and acquisitions, and evolve, e.g., increased outsourcing of business activities, their risk profiles and strategic priorities change. Intelligence requirements must reflect these changes. To achieve this:

  6. Regular Reviews: Conduct periodic intelligence requirements reviews to ensure they align with current business operations and objectives.

  7. Stakeholder Input: Engage with different departments to understand their unique threat concerns and adjust requirements accordingly.
  8. Dynamic Adjustments: Be ready to make swift adjustments as the organization adopts new technologies or enters new markets.

  9. Foster Stakeholder Engagement and CollaborationEffective intelligence requirements involve input from stakeholders. Fostering collaboration across departments ensures comprehensive coverage of potential threats. Best practices include:

  10. Cross-Functional Teams: Create teams with members from security operations, IT, marketing, HR,, and other relevant departments to review and update intelligence requirements.

  11. Regular Meetings: Meet to discuss emerging threats and gather insights from different perspectives.
  12. Shared Responsibility: Promote a culture where cybersecurity is seen as a shared responsibility across the organization.

  13. Ensure Compliance and Regulatory AlignmentThe regulatory landscape for cybersecurity is continuously evolving. Regularly updating intelligence requirements ensures compliance with new standards and reduces the risk of penalties. Key steps include:

  14. Compliance Audits: Conduct regular audits to identify gaps in compliance with regulations like PCI DSS, ISO27001/2, DORA, etc.

  15. Regulatory Updates: Stay informed about changes in regulatory requirements and adjust intelligence requirements to meet these standards.
  16. Documentation: Maintain thorough documentation of compliance-related adjustments to intelligence requirements.

  17. Utilize Feedback and Lessons LearnedContinuous improvement thrives on feedback and learning from past experiences. Incorporating lessons learned into intelligence requirements helps fine-tune them. Effective strategies include:

  18. Post-Incident Analysis: Conduct a thorough review after a security incident to identify gaps in intelligence requirements and make necessary adjustments.

  19. Feedback Loops: Establish feedback mechanisms where employees can report on the effectiveness of current intelligence requirements and suggest improvements.
  20. Training and Awareness: Regularly train employees on the importance of intelligence requirements and how they can contribute to continuous improvement.

ThreatConnect AdvantageThreatConnect’s Intelligence Requirements feature supports continuous improvement of intelligence requirements. It allows organizations to seamlessly integrate threat intelligence with their operational workflows, ensuring that intelligence requirements are always relevant and actionable. Organizations can:

  • Centralize Threat Intelligence: Consolidate and manage threat intelligence from various sources in one place, making it easier to stay informed about the latest threats.
  • Automate Updates to Requirements: Automatically adjust intelligence requirements based on the latest threat data and organizational changes, reducing the manual effort required to keep them current.
  • Facilitate Collaboration: Foster cross-functional collaboration by providing a platform where stakeholders from different departments can contribute insights and updates.
  • Incorporate Feedback: Utilize feedback loops and post-incident analyses to continually refine and improve intelligence requirements.

Adopting these best practices to continuously improve intelligence requirements ensures they remain relevant, effective, and aligned with the evolving threat landscape and organizational changes. Organizations can maintain a strong and dynamic threat intelligence capability by consistently monitoring, aligning with organizational priorities, promoting stakeholder collaboration, ensuring compliance, and integrating feedback. This proactive approach enables them to stay one step ahead of cyber adversaries and effectively safeguard their assets.

Want to Learn More?We offer a variety of ways you can learn more about the ThreatConnect TI Ops Platform. Take an interactive tour, check out our website, or request a demo to learn more about how ThreatConnect can help you operationalize your threat intel program. To find out more about Intelligence Requirements, check out this guide.

The post Top 5 Best Practices to Continuously Improve Your Intelligence Requirements appeared first on ThreatConnect.

View Details

In the rapidly evolving threat landscape, vulnerability management is a daunting task. Every month thousands of new vulnerabilities emerge, creating a significant challenge for threat intelligence and vulnerability management analysts. The new integration between ThreatConnect and VulnCheck promises to address these challenges by offering a unified, intelligent approach to accelerating identification and analysis, and improving the precision of prioritizing vulnerabilities for remediation.

The Growing Challenge of Vulnerability Management, the Importance of Prioritization, and the Role of Threat IntelWith an average of 25,000 new vulnerabilities each month, analysts must sift through vast amounts of data to identify which vulnerabilities pose the most significant threats to their organizations. This process is time-consuming and often leads to wasted resources, gaps between vulnerability disclosure and remediation, and analyst burnout.

Effective vulnerability management isn’t just about identifying vulnerabilities; it’s about prioritizing them. Not all vulnerabilities are created equal—some pose immediate threats, while others may never be exploited. Analysts need tools that help them get the necessary insights to quickly determine which vulnerabilities are the most critical to address.

Threat intelligence plays a crucial role in vulnerability management. By understanding the tactics, techniques, and procedures (TTPs) of threat actors, analysts can better assess the risk associated with specific vulnerabilities. This intelligence helps prioritize remediation efforts and allocate resources more effectively.

Introducing a New Integration between ThreatConnect and VulnCheckThreatConnect is a leading threat intelligence platform that offers comprehensive tools for managing and analyzing threat data. It provides a centralized hub for cybersecurity teams to collaborate, investigate threats, and automate responses.

VulnCheck offers unparalleled visibility into the vulnerability ecosystem. It provides detailed intelligence on vulnerabilities and exploits, helping organizations stay ahead of threat actors and enables them to proactively reduce their attack surface.

The integration between ThreatConnect and VulnCheck combines the strengths of both platforms. VulnCheck’s vulnerability and exploit intelligence are seamlessly integrated into the ThreatConnect TI Ops Platform, providing a unified view of the threat landscape. This integration enhances the precision with which analysts can identify and prioritize critical vulnerabilities.

Key Benefits of the Integration Unified Vulnerability Intelligence – One of the most significant benefits of the ThreatConnect and VulnCheck integration is the unified view of vulnerability intelligence. Analysts no longer need to collect and process data from disparate sources manually. Instead, they get out-of-the-box insights that streamline their workflows and improve accuracy. * Novel Insights and Detailed Analysis* – The integration offers in-depth details on vulnerabilities and threat actor activities. Analysts gain novel insights into emerging threats and exploits, enabling them to make more informed decisions and prioritize remediation efforts more effectively.

  • Automated Monitoring and Early Warning Indicators – Automation is a game-changer in vulnerability management. The integration automates the monitoring of emerging threats and exploits, providing early warning indicators that help analysts stay ahead of potential attacks. This proactive approach reduces the time between vulnerability disclosure and remediation.

Ready to learn more?To learn more about the VulnCheck integration with ThreatConnect TI Ops, please visit the ThreatConnect Marketplace. Contact ThreatConnect to speak to an expert today to get a personalized demo of the TI Ops Platform and to see the integration in action. To learn more about VulnCheck and get a demo, reach out to speak with one of their vulnerability experts today.

The post Achieve Faster, More Precise Vulnerability Prioritization with ThreatConnect and VulnCheck appeared first on ThreatConnect.

View Details

Enhancing Cybersecurity with CAL Automated Threat Library (ATL) Industry Classification.

In the constantly changing field of cybersecurity, it is crucial to effectively manage and interpret large volumes of open-source intelligence (OSINT). ThreatConnect’s CAL Automated Threat Library (ATL) addresses this challenge by using natural language processing (NLP) to classify ATL Reports by industry using NAICS codes*. This classification, available through standard tags and keyword suggestions, significantly improves threat detection, intelligence requirements (IRs), and decision-making within the ThreatConnect platform.

*North American Industry Classification System

Streamlining Cybersecurity with Industry ClassificationThe CAL ATL industry classification system efficiently organizes large volumes of OSINT into machine-readable components. Users can quickly filter and focus on relevant intelligence by applying industry-specific tags to ThreatConnect objects like Groups. This functionality aids in building precise IRs and facilitates searching and browsing within the platform.

The Role of NAICS Codes in Threat IntelligenceIntegrating NAICS codes addresses the critical problem of effectively categorizing and prioritizing OSINT. With the vast amount of data generated daily, analysts often need help determining which threats are most relevant to their specific industry. NAICS codes provide a standardized method to classify this data, enabling more efficient filtering and focus on industry-specific threats.

Leveraging a classification system like NAICS allows customers to scope their interest between a broad sector and a specific subsector, letting them be as broad or specific as they want for their purposes. This precise classification allows for faster response times, better resource allocation, and improved overall security posture by promptly addressing the most pertinent threats.

Navigating the Complexities of Industry ClassificationClassifying content by industry is a challenging task due to several factors. One significant complexity is the overlap between categories when discussing industries in broad terms. For instance, technology and IT often intersect, making it difficult to draw clear boundaries.

The dynamic nature of industries adds another layer of complexity. As industries evolve and terminology changes, what once fit into one category may shift into another. A prime example is the publishing industry, which used to include software publishing when software was distributed on physical disks.

Granularity levels also play a crucial role in classification. While some classifications may group everything under broad categories like technology, others might differentiate between specific sectors such as microchips or IT services.

Localization further complicates the picture, as different countries have groupings and standards. For example, a company classified under one industry in the U.S. might fall under a different category in Europe or Asia.

Moreover, various taxonomies exist for classifying industries, each with its own criteria and focus. Some of the most notable ones include the North American Industry Classification System (NAICS), International Standard Industrial Classification of All Economic Activities (ISIC), Global Industry Classification Standard (GICS), European Union NACE, Australian and New Zealand Standard Industrial Classification (ANZSIC), Japan Standard Industrial Classification (JSIC), and the UK Standard Industrial Classification of Economic Activities (UK SIC).

Understanding and navigating these complexities is essential for accurate and effective industry classification.

Industry-Specific Tagging Using NLPCAL ATL employs NLP to analyze ATL Reports and associates them with relevant NAICS codes. These tags, covering a broad range of industries from agriculture to public administration, enable users to make quick decisions on selecting or excluding ATL resources, focusing on high-priority tasks.

Practical Applications CAL ATL Report Groups and Tags: Users can pivot on tags to explore related reports within the platform. For instance, viewing an industry tag in a report’s details screen reveals all associated reports, enhancing threat intelligence connections. * Intelligence Requirements:* When creating IRs, users can include or exclude NAICS keyword suggestions, ensuring their intelligence gathering aligns with a broad sector or specific industry needs. This targeted approach enhances the relevance and accuracy of IR results.

Use Case: Protecting Financial Institutions

Consider a financial institution that must protect against threats specific to the banking sector. With CAL ATL’s industry classification, the institution can tag incoming OSINT with the relevant NAICS codes, such as those for banking and finance. This allows analysts to quickly filter and identify threats to their sector, such as phishing schemes targeting bank customers or malware designed to infiltrate financial systems.

The institution can prioritize its resources, implement targeted defenses, and respond swiftly to emerging threats by focusing on industry-specific intelligence. This use case illustrates how CAL ATL’s industry classification system enhances the ability to detect, triage, and mitigate threats within a specific sector, ultimately bolstering the institution’s cybersecurity posture. CAL ATL’s industry classification also helps organizations gain perspective on strategic intelligence within an industry sector so they can also pivot resources and investments to meet a changing security landscape.

Enhancing Threat Intelligence with NAICS Codes

Integrating NAICS codes into the CAL ATL framework streamlines cybersecurity efforts by categorizing intelligence reports into industry sectors and subsectors. This detailed classification supports targeted threat detection, alert triage, and response strategies, empowering organizations to focus on industry-specific threats and vulnerabilities.

ThreatConnect’s CAL ATL industry classification, powered by NLP and NAICS codes, revolutionizes the management of OSINT. Organizing intelligence into industry-specific tags and keywords facilitates more efficient threat detection, response, and threat hunting. This robust classification system ensures organizations can leverage precise, relevant intelligence to bolster their cybersecurity defenses.

Want to Learn More?

We offer various ways to learn more about the ThreatConnect TI Ops Platform: Take an interactive tour, check out our website, or request a demo to learn how ThreatConnect can help you operationalize your threat intel program.

The post Enhancing Cybersecurity with CAL™ Automated Threat Library (ATL) Industry Classification appeared first on ThreatConnect.

View Details

In an era where cyber-attacks happen faster and are growing, staying ahead of adversaries is a necessity but very challenging. Quickly assessing suspected malicious files and URLs is vital for reducing the time it takes to detect and respond to cyber threats. Understanding the adversary’s tactics, techniques, and malware infrastructure can significantly improve your organization’s defenses. Organizations must understand how their enemies operate and the type of malware they use and leverage this knowledge to bolster defenses. Yet, the manual process of analyzing files and URLs is cumbersome and inefficient, leaving security analysts overwhelmed.

ThreatConnect and VMRayEnter ThreatConnect and VMRay. We’re pleased to announce an upgraded integration as well as a brand new integration between ThreatConnect’s Threat Intelligence Operations (TI Ops) Platform and VMRay. The combined solutions enable security operations and cyber threat intelligence (CTI) teams to scale their file and URL analyses, converting raw data into actionable intelligence, and help them better understand adversaries and take proactive actions to fortify defenses.

By combining ThreatConnect’s robust TI Ops platform with VMRay’s advanced malware sandboxing and URL analysis, security teams can scale their analysis efforts dramatically and produce custom intelligence tailored to threats targeting their organization. This means stronger, more proactive defenses that adapt as quickly as adversaries do.

The Power of Integrated SolutionsAutomation is at the heart of this integration. Playbook automation in ThreatConnect streamlines file and URL analysis processes, ensuring that your security team can handle large volumes of data without being bogged down by manual tasks. The latest version of the VMRay Platform App for ThreatConnect automates the submission of files and URLs for analysis and processes the results, saving analysts hours of effort. The data—whether it’s file hashes, IP addresses, domains, or URLs—is seamlessly integrated into the ThreatConnect Platform, providing enriched context for better decision-making.

Utilize new intel from VMRay analyses to enhance your detection and prevention tools. By incorporating this data into ThreatConnect, you can optimize tools like SIEMs, endpoint protection, and network and cloud security. How? The new VMRay Threat Intelligence Job App automates the ingestion of threat intelligence from files and URLs analyzed by the VMRay Platform into ThreatConnect TI Ops. This ensures that analysts always have the latest insights from ongoing attacks, allowing them to leverage this intel for enhanced threat detection, prevention, and response.

But wait, there are even more benefits!Enriching context is crucial for understanding the bigger picture. With these integrations, analysts get detailed insights into malware families, indicators of compromise (IOCs), phishing emails, and threat actors, all within one platform. The automated enrichment of intel adds context, improving its fidelity. This is particularly useful in phishing attack analysis, where understanding the context can make the difference between an overlooked threat and a crucial insight.

Leveraging context from ThreatConnect and VMRay to triage, prioritize, and respond to alerts more effectively. This ensures that security defense tools—like SIEM, XDR, EDR, and NDR—are operating at their full potential.

With new intel from VMRay analyses, threat hunting becomes far more effective. This integration enables your team to actively search for malware within your environment, improving overall security posture.

Take your cyber defense to the next levelTo learn more about the latest integrations between ThreatConnect and VMRay, visit the ThreatConnect Marketplace. If you’d like to learn more about ThreatConnect’s TI Ops Platform, check out our interactive tour or reach out to one of our experts. To learn more about VMRay’s Advanced Malware Sandbox and URL Analysis Platform, reach out to a VMRay expert today.

The post The Benefits of Intelligence-Powered Cyber Defense with ThreatConnect and VMRay appeared first on ThreatConnect.

View Details

Cybersecurity teams are under constant pressure to maintain real-time visibility into potential threats across various categories, including digital risks, third-party risks, vulnerabilities, and cyber-physical threats. The challenge lies in trying to monitor all these categories in real time for emerging and active threats. Monitoring, analyzing, and responding to cyber threats is resource-intensive and complex without the right integrated solutions. Traditional manual methods fall short, leading to an impact on resources and inefficiencies.

We’re very pleased to announce a new integration between ThreatConnect’s TI Ops Platform and Dataminr Pulse for Cyber Risk. This combination offers a powerful synergy to enhance an organization’s real-time cyber threat detection and response capabilities.

The Power of ThreatConnect with Dataminr Pulse for Cyber RiskDataminr has created a revolutionary real-time AI platform for detecting cyber and physical threats from over 1 million unique public data signals (including surface, deep, and dark web) and is recognized as one of the world’s leading AI companies. Dataminr Pulse for Cyber Risk gives businesses the ability to create finely-tuned threat feeds that only deliver relevant alerts that provide the earliest signs of cyber risk. When integrated with ThreatConnect, cybersecurity teams can leverage the combined power of these platforms to enhance their threat intelligence and response capabilities and shift to an even more proactive stance for protecting from cyber threats. ThreatConnect’s Alerts Engine App integration with Dataminr’s Pulse for Cyber Risk allows for a seamless connection, enrichment, analysis, and response to threats, all in a single platform. This unified approach ensures that analysts have the context they need to act on threats effectively and efficiently.

Continuous Visibility into Threat Activity and Centralized Threat ManagementOne of the most significant benefits of integrating ThreatConnect with Dataminr Pulse for Cyber Risk is its real-time visibility into threat activity. Organizations can monitor digital risks, third-party risks, vulnerabilities, and cyber-physical threats. Pulse Alerts are enriched with unified threat intelligence and context in the TI Ops platform, enabling improved alert monitoring, analysis, triage, and prioritization. With real-time alerts, actionable threat intel data, and automated enrichment, security teams can promptly handle threats as they happen.

Accelerating Incident ResponseIncident response is critical to cybersecurity, as rapid response to threats minimizes the impact on an organization’s digital assets. The integration of ThreatConnect with Dataminr Pulse for Cyber Risk enhances incident response capabilities by leveraging workflows and automation. This approach ensures a fast and consistent response to active threats, enabling teams to contain and mitigate incidents swiftly. The unified platform provides the tools needed to coordinate and execute incident response plans effectively.

Prioritize Vulnerability RemediationCybersecurity teams are tasked with triaging hundreds of vulnerabilities weekly, requiring significant resources to assess and prioritize remediation efforts. ThreatConnect and Dataminr Pulse for Cyber Risk simplify this process by providing a unified source of threat and vulnerability intelligence. Automated contextualization enables teams to identify and prioritize the most critical vulnerabilities that need immediate attention. This focused approach ensures that resources are allocated efficiently, reducing the risk posed by unaddressed vulnerabilities in an organization’s most critical assets.

Gain Actionable Insights and Improve Organizational ResilienceThe combination provides cybersecurity teams with actionable insights that drive informed decision-making. The integrated solution offers a comprehensive view of the cyber threat landscape by aggregating and analyzing data from over one million unique public data sources, including audio, video, images, scanners, sensors, and more. Analysts can leverage these insights to develop proactive strategies, anticipate potential threats, and implement effective defense measures. The ability to make data-driven decisions enhances the overall security posture to protect the organization and its reputation.

Want to learn more?To learn more about the Dataminr Pulse for Cyber Risk integration with ThreatConnect TI Ops, please visit the ThreatConnect Marketplace. To hear and see how this powerful combination enables security teams to work more efficiently and effectively to protect their organizations, contact ThreatConnect to speak to an expert today and get a personalized demo. To learn more about Dataminr Pulse for Cyber Risk and get a demo, reach out to speak with a Dataminr expert today.

The post Elevate Your Threat Detection and Response with ThreatConnect and Dataminr appeared first on ThreatConnect.

View Details

With the release of ThreatConnect RQ 7.9, organizations have access to new, powerful tools designed to improve cyber risk management. This release focuses on addressing common challenges in risk communication, enhancing technical risk analysis, and providing an improved user experience across RQ.

The Challenge of Qualitative Risk MeasuresOne longstanding challenge is effectively communicating qualitative risk to stakeholders. Traditional heat maps, while useful, rely on subjective inputs that lack quantitative data. This can lead to misunderstandings and under- or over-valuation of potential risks.

Introducing the Data-Driven Heat MapTo overcome this challenge, RQ 7.9 introduces a data-driven heat map that brings rigor to a qualitative risk communication tool. This feature allows users to visualize scenarios calculated by RQ in well-known and used matrix heat maps, providing a more accurate representation of cyber risks.

Key Features of the Data-Driven Heat Map Scalable: The heat map can display financial scales or qualitative scales, offering flexibility in how risks are presented. * Customizable: You can choose to show annualized loss expectancy (ALE) or single loss expectancy (SLE) and probability of attacker success (P(s)) or loss event frequency (LEF). The qualitative scale for loss magnitude can also be customized. * Enhanced Clarity*: By incorporating data-driven insights, the heat map offers a clearer and more objective view of risk scenarios, making it easier to communicate with stakeholders.

Advancing Technical AnalysesBuilding on the foundation laid in previous RQ versions, RQ 7.9 adds new options to the Technical Analysis options – Technical Assets and Technical Risks. These enhancements provide deeper insights into your enterprise’s technical risk landscape.

Exploring Technical AssetsIn RQ, a Technical Asset is defined as any piece of software or hardware that an attacker could exploit, such as workstations, servers, databases, containers, and network devices. Each technical asset receives a risk score ranging from 0 to 1000, with lower scores indicating higher security.

  • Detailed Endpoint Information: Provides a summary of each endpoint’s information, technical risk score assessment, and Common Vulnerabilities and Exposures (CVEs) findings.
  • Four Analysis Factors: Endpoint risk scores are calculated based on vulnerability data, application security data, subnet analysis, and partner scoring.
  • Practical Applications: These risk scores are invaluable when evaluating CVEs on RQ’s Short-Term Recommendations screen, providing actionable insights for mitigating technical risks.

Assessing Technical RisksThe Technical Risks screen lists all potential CVEs within your enterprise environment, offering crucial details for each CVE:

  • EPSS Score and Ranking: Evaluate each CVE’s exploitability with the Exploit Prediction Scoring System (EPSS), which predicts the likelihood of exploitation.
  • CVSS Score and Timeline: Access the CVSS score, publication date, and last asset date as provided by NIST’s National Vulnerability Database (NVD).
  • Comprehensive Risk Evaluation: These metrics collectively contribute to the technical risk score for a legal entity’s assets, offering a holistic view of an organization’s vulnerabilities.

A New Integration with Microsoft Defender for EndpointWith the integration of Microsoft Defender, RQ 7.9 enhances its capabilities in analyzing technical risks to endpoints. This integration offers several benefits:

  • Automated Risk Assessment: Automatically evaluate technical risks for endpoints protected by Microsoft Defender, ensuring continuous monitoring and timely responses to emerging threats.
  • Unified Security Posture: By combining RQ’s advanced risk quantification with Microsoft Defender’s endpoint protection, organizations can achieve a more cohesive and robust security strategy.

Streamlined Navigation and Improved User ExperienceIn RQ 7.9, the Output Analysis option on the side navigation bar has been replaced with three new options to facilitate quicker access to essential information.

  • Financial Analysis Enhancements: The Financial Analysis screen now includes Lower Bound and Upper Bound columns in the RQ-ALE section of the Loss Breakdown by Type and Application table.
  • Model Risk to Business Assets: A new Total row in the Financial Analysis table provides a comprehensive view of potential financial impacts.
  • FAIR Scenario ‘What If’ Analysis Enhancements: The loss table’s characteristics now include rows for 10%, 25%, 50%, 75%, 90%, and 95%, offering a more granular analysis of risk scenarios.

Want to learn more?If you’re interested in learning more about these great new features in RQ 7.9, reach out to one of our cyber risk experts at threatconnect.com/request-a-demo or experience them for yourself with our interactive demo.

The post Evolve Your Cyber Risk Management with ThreatConnect Risk Quantifier 7.9 appeared first on ThreatConnect.

View Details

We announced today that ThreatConnect has acquired Polarity (you can read the press release here). Polarity’s solution augments security analysts’ daily workflow with context and insight needed for decision and action in their course of analysis regardless of the application they are in. We’re excited to have the Polarity team join the ThreatConnect family and have some awesome plans for the combination of our Threat Intel Operations Platform together with Polarity.

Aligned Vision and Practical ExecutionThreatConnect’s vision statement is to “Change the way security works by turning intelligence and insights into action.” Adding Polarity immediately helps us further this vision. Their technology helps security analysts speed decision-making by putting context from both external threat intelligence and internal insights from asset, identity, and security controls on security analyst’s screens exactly when they need it in the course of their work. Make no mistake though, this combination goes well beyond vision – there is already tremendous validation from more than a dozen shared customers that this is a powerful combination that enables them to do their jobs better. The common sentiment they’ve shared is that someone would have to “pry Polarity out of their hands” before they’d give it up. Additionally, we’ve worked with and known the founders and leaders of Polarity for years, and we’re aligned with speeding decision-making for security teams to turn the asymmetric advantage back to the defenders.

What is Polarity?Perhaps I’ve gotten ahead of myself, it may be you’re not familiar with Polarity. Let’s address that. Polarity is a federated search tool and much more that can search hundreds (yes, hundreds) of sources simultaneously to provide SOC, CTI, IR, Hunt, and other analysts enriched data immediately to help guide analysis and decision. The special sauce is that the analyst isn’t required to go to “yet another tab” or type in a query in another console; the Polarity client reads what’s on the screen, parses out IOCs, known text strings, etc, or, most popularly, runs queries on whatever is grabbed in a selective screen capture. It bypasses the need for a “single pane of glass” by providing context wherever the analyst needs to be working. Because it can query what’s on the screen, independent of (but not agnostic to) all applications the user needs to query from, it removes the need for context switching between applications, toggling between browser tabs, etc. It doesn’t just populate search results but integrates with ThreatConnect TI Ops, SOAR tools, ticketing systems, or other automation tools to take action on information or initiate a deeper investigation immediately. It can also work with the latest commercial and open-source GenAI LLMs to summarize and synthesize results further speed decision-making.

Immediate Value to Our Customers – like Right NowBy coming together, we’re removing the biggest barrier to truly operationalizing threat intelligence – the interaction between CTI teams (TI Producers) and the operational defenders and controls in the SOC, incident response, and threat-hunting teams (Consumers of TI). Traditionally, information flow has been limited by lack of interconnected systems, culture, and process. But now, with the ThreatConnect TI Ops Platform and Polarity, customers will have threat intelligence alongside all role-relevant context and enrichment available directly on their desktop and integrated with their operational tools and controls. In addition, for CTI teams, Polarity will enhance their analysis and investigations with additional context and enrichment from all available data sources from a single interface.

In short, CTI analysts will be more productive and more effective in their investigations. SOC, IR, and hunt teams will have all the data they need, at the time of decision, overlaid on whatever interface they are doing their work. This will nearly eliminate “last mile” friction in getting the intelligence to the right consumer at the right time.

In addition to being offered as a bundle with ThreatConnect’s TI Ops Platform, Polarity will continue to be sold independently. We’ll be excited to offer Polarity customers an increasing array of AI-based insights, like extracted insights on MITRE ATT&CK techniques mentioned in text, bespoke threat intelligence enrichment, feed performance and value, and trending metrics on IOCs from CAL, our AI-powered analytics brain/engine.

Looking AheadWe will strengthen our integration with Polarity and our Threat Intelligence Operations Platform as we build out our AI capabilities, streamlining workflows and investigations, and automating every step of analyst workflows.

Let’s not leave out ThreatConnect Risk Quantifier, aka RQ, our cyber risk quantification product that is increasing its operationally relevant insights, informing the risk pertinent to assets, helping prioritize vulnerabilities to remediate, and the MITRE ATT&CK techniques to focus on. Users of Polarity and RQ together will soon be able to surface insights on the risk to apps and assets related to their alerts, investigations, and threat capabilities. Together with threat intelligence from our TI OPs Platform, RQ, and Polarity will be able to surface internal asset information, business risk and impact associated with them, and threat insights trying to affect them from one overlay.

Polarity’s capabilities also will position us for our longer-term aspirations to inform decisions for traditional security teams as threats represented by cyber adversaries and criminals increasingly begin to have impacts in physical space.

Want to learn more?Reach out to us at threatconnect.com/request-a-demo or sales@threatconnect.com to learn more about how the combination of ThreatConnect and Polarity is the force-multiplier your CTI and Security Operations teams need right now.

The post Why Polarity & ThreatConnect? appeared first on ThreatConnect.

View Details

In today’s digital world, the volume of cyber threats is growing at an alarming rate. Alerts often overwhelm analysts tasked with monitoring, detecting, analyzing, and responding to these threats.

The newest integration between ThreatConnect’s TI Ops Platform and Elastic helps security operations teams and analysts get the upper hand on the threat actors targeting their organizations.

Key Benefits

Integrating ThreatConnect with Elastic brings multiple benefits to SecOps teams:

  • Stronger Threat Detection – The new integration strengthens threat detection by providing high-fidelity threat intelligence and context directly in Elastic Security. This ensures that analysts can identify and prioritize the most critical threats rather than chasing false positives.
  • Efficient Incident Response – With integrated platforms, incident responders can act quickly and precisely using relevant intel, reducing the time to respond to threats.
  • Enhanced Threat Hunting – Threat hunting becomes more effective as analysts can use relevant intel to define hypotheses and starting points for hunts and use the Threat Graph in TI Ops to visually see and understand how threat actors operate.
  • Customizable for High-Fidelity Intel – One of the standout features is the integration’s unmatched level of customization. SecOps teams can tailor the integration to meet their specific needs, ensuring they receive the most relevant, high-fidelity intel.
  • Comprehensive Intel Context and Relationship Data – Unlike other solutions that provide raw intel feeds, ThreatConnect supplies Elastic with comprehensive intel context and relationship data. This added context helps analysts make better-informed decisions and respond to threats more effectively.

Quick to Set Up and Time-to-Value

Using the new native integration between ThreatConnect and Elastic and pre-built Apps available in ThreatConnect TI Ops, the platforms can be connected in just a few minutes enabling organizations to start benefiting immediately.

Take the next steps

To learn more about the latest integration and other integrations with Elastic, visit the ThreatConnect Marketplace. To learn more about the ThreatConnect TI Ops Platform, take a tour, or reach out and speak to one of our experts at threatconnect.com/request-a-demo. To learn more about Elastic Security, contact sales at www.elastic.co/contact.

The post A New Integration With Elastic appeared first on ThreatConnect.

View Details

CTI analysts often face the challenge of managing an overwhelming volume of diverse threat intelligence data, making it difficult to effectively aggregate, correlate, and act on this information. The brain of ThreatConnect’s TI Ops Platform, CAL, addresses this issue by leveraging AI, natural language processing (NLP), and machine learning (ML) to deliver advanced analytics and global intelligence.

The TI Ops Platform includes several open-source intelligence (OSINT), proprietary CAL analytics-powered intel feeds, and the ThreatConnect user community, tracking 271 billion data points and over 1.1 billion anonymized daily observations from ThreatConnect users worldwide to offer a collective perspective on threats, enhancing organizations’ ability to identify and respond to emerging risks.

In previous blogs, I provided a high-level understanding of CAL and the CAL Automated Threat Library (ATL). In this blog, let’s expand our view of CAL’s novel threat feeds in the Platform, the dozens of open-source intel feeds available for frictionless use, and assess intel feed performance with Report Cards.

OSINT and CAL FeedsThreatConnect TI Ops makes it frictionless to add the dozens of OSINT and proprietary CAL feeds that can be turned on with the click of a button in Feed Explorer. We eliminate the labor of finding, subscribing to, and configuring OSINT threat feeds. Our Platform integrates this process, allowing you to effortlessly add threat intelligence data to the Threat Library.

CAL Feeds Powered by ThreatConnect’s AI-powered analytics, the CAL Feeds provides 15 novel threat intel feeds unique to ThreatConnect.

Not only do the CAL Feeds include CAL ATL, which automatically aggregates articles from information security news sites, industry sites (like CISA), and blogs ,and automatically identifies and extracts IOCs, malware families, threat actors, etc, but the CAL Feeds also provide sector-themed newly-registered domains (NRDs) feeds for energy, finance, and healthcare.

For example, let’s say that as a CTI analyst, you use the CAL ATL feed to keep track of the latest cybersecurity threats through its aggregation and quick parsing of information from a wide variety of trusted security news sources. This helps you quickly identify indicators of compromise (IOCs), malware families, and threat actors to save you valuable time.

Additionally, suppose you work in an industry with sector-specific threats, you may also want to leverage one of our NRD feeds to establish a tripwire in order to detect and respond to targeted threats. This enables analysts to focus on intel specific to your organization and intel requirements.

Feed Explorer and Report CardsAnalysts who want an up-to-date assessment and a comparison between various feeds will want to check out Feed Explorer and Report Cards. These features provide performance-related insights and Report Cards for all the intel feeds enabled in the Platform,.

Analysts can quickly assess feed performance and its value using a Report Card that provides a reliability rating, measures false positives, and performance scores based on multiple factors. Report Cards list Common Classifiers from CAL and analyses for key metrics like Unique Indicators, First Reported, Scoring Disposition, and Classifier Coverage. It’s a great feature to help optimize your intelligence sources (commercial/paid, OSINT, or industry partners), and intel feed budget.

Benefits of CAL Feeds, Feed Explorer, and Report CardsOSINT and CAL Feeds allow for easy access to threat intel out-of-the-box. Feed Explorer and Report Cards offer analysts valuable insights and comparisons between various intel feeds, facilitating informed decision-making and optimization of intelligence sources.

Want to Learn More?We offer various ways to learn more about the ThreatConnect TI Ops Platform. Take an interactive tour, check out our website, or request a demo to learn more about how ThreatConnect can help you operationalize your threat intel program.

The post Elevate Your Threat Intel with CAL™ Feeds and AI-Powered Insights appeared first on ThreatConnect.

View Details

We’re pleased to announce a new integration between ThreatConnect’s TI Ops Platform and Silent Push!

The Challenge of Limited VisibilityAnalysts face a significant challenge – only about 2% of threat actor infrastructure is tracked. This leaves CTI and SecOps teams, which are already struggling to track, understand, and respond to threat actors effectively, with blind spots. Limited visibility means that potential threats can go unnoticed until it’s too late.

Why ThreatConnect and Silent Push?Silent Push generates first-party data across the IPv4 space and produces Indicators of Future Attack (IoFA). These indicators enable analysts to track adversary infrastructure before it becomes weaponized. One of the benefits of this integration is highly enriched threat intelligence. Silent Push’s data provides complete, timely, and accurate context of global internet-facing infrastructure. The integration also enables analysts to leverage intel on the infrastructure used by threat actors targeting their industry and organization. With these insights, CTI analysts can better anticipate threat actor activities. This knowledge can be used to improve threat defense and increase attack resistance by disrupting the tools used by attackers.

How It Works – The Silent Push Playbook AppThe new Playbook App simplifies context enrichment and data searching in Silent Push with almost two dozen out-of-the-box actions through ThreatConnect’s Playbook automation.

The combination of ThreatConnect and Silent Push supports various use cases:

  • Enrich Threat Intelligence – Automated contextualization improves the accuracy and fidelity of threat intelligence, enabling better analysis.
  • Threat Detection and Prevention – Enhance threat detection capabilities by identifying and blocking adversary infrastructure before attacks occur.
  • Threat Hunting – Reduce attacker dwell time by identifying indicators associated with attacker infrastructure and taking action.

Next StepsTo learn more about the integration, check out the ThreatConnect Marketplace. If you’d like to speak to one of our experts about ThreatConnect TI Ops, reach out via threatconnect.com/request-a-demo or email sales@threatconnect.com. To learn more about Silent Push, visit silentpush.com or reach out via info@silentpush.com.

The post Stay Ahead of Threat Actors with ThreatConnect and Silent Push appeared first on ThreatConnect.

View Details

Analysts often deal with the inefficiencies of creating reports from scratch and navigating through scattered threat intel. In response to these challenges, ThreatConnect is excited to announce the latest enhancements for TI Ops Platform release 7.6. This update adds the capability to create more reporting templates and a streamlined way to view threat context, enabling analysts to work more efficiently and effectively.

Explore these updates with our TI Ops 7.6 interactive demo

Introducing New Reporting Templates for Cases and Generic UseEffective reporting plays a crucial role in conveying value to stakeholders. We’re excited to announce the ability to create two new reporting templates: one for Cases and a Generic template.

Save Time with TemplatesCreating reports from scratch every time is time-consuming, inconsistent, and prone to errors. With the capability of creating templates, retaining best practices and training new team members is more manageable.

When templates can be created once, updated at will, and used frequently to generate consistent and professional reports, users realize increased efficiency, consistency, and accuracy in reporting, a critical element for effective threat intel operations.

The Solution: More Options to Create Reporting TemplatesCustomers can now create two new additional reporting templates: one specifically designed for Case reports and a versatile Generic template – giving analysts the ability to craft executive or strategic reports, conveying top-level insights. These templates join the existing Group report template, providing a useful set of options for various reporting needs.

Key Features of TI Ops Platform Reporting:

  • Template Options: Analysts can now create reports tailored to specific Groups, Cases, or general purposes with greater ease and flexibility.
  • Template Library: Save and reuse multiple templates to quickly produce reports, reducing effort and boosting productivity.
  • Flexibility and Customization: Utilize Placeholder and Content Blocks to tailor reports with dynamic content and pre-configured data, ensuring relevance and accuracy.
  • Rich Text Contextualization: Incorporate detailed and rich text information, providing deeper insights and context within reports.
  • Custom Report Distribution: Distribute customized reports efficiently through export or email, ensuring stakeholders receive consistent and valuable insights.

Multi-Source Tags in One Place! Introducing the Tags Across Owners CardThreatConnect aims to streamline threat context for CTI Analysts, bringing more features and intel into a “single pane” to minimize the need for multiple clicks and pages. Release 7.6 focuses specifically on consolidating Indicator Tags.

The new Tags Across Owners card consolidates all Tags and their associated owners in one place, reducing the need to navigate through multiple Details pages.

Key Benefits of the Tags Across Owners’ card:

  • Unified Threat Context: View all Tags associated with an indicator and their owners in one consolidated view.
  • Enhanced Threat Visibility: Gather and understand threat intelligence quickly without navigating multiple pages.
  • Time Efficiency: Decrease time to value by streamlining the gathering and analyzing threat data.

By integrating the Tags Across Owners card into our customizable Details View, users can also tailor their experience to prioritize relevant information, improving efficiency.

Enhanced Search Release 7.6 also introduces new Enhanced Search features, providing a streamlined UI for better context in search results. Users can see which fields their search results match and combine filters for comprehensive pattern searches. This enhanced interface ensures comprehensive search across all your threat intel, offering a more detailed and interconnected perspective on potential threats.

Flexible Filtering

  • Pinpoint accuracy with filters for Cases, Indicators, and Groups.
  • Filter for owners, group types, indicator types, and dates.
  • Quickly access the most relevant information for better decision-making.

Prioritization and Organization

  • Advanced sorting capabilities to prioritize key information.
  • Manage workload efficiently, addressing critical issues first.
  • Quickly produce results when time and accuracy are crucial.

Through the new Reporting Templates, Tags Across Owners card, and Enhanced Search upgrades, analysts can focus on more critical tasks, such as threat detection and response, rather than getting bogged down by report creation and data consolidation.

If you are ready to see how ThreatConnect can help your organization operationalize threat intelligence, please reach out to sales@threatconnect.com or request a custom demo today.

The post ThreatConnect TI Ops Platform 7.6: Enhanced Report Creation and Threat Context appeared first on ThreatConnect.

View Details

Story time. I recently had the opportunity to work with a large organization in the healthcare insurance industry. They wanted to adopt cyber risk quantification (CRQ) and really liked the FAIR model. The customer came to ThreatConnect and stated “we don’t need all the bells and whistles; we just want to be able to use FAIR” within our CRQ solution Risk Quantifier (RQ). They had already put in a lot of work around gathering data and even worked with a consulting group to help. However, they also recognized the challenges of going to a fully FAIR-based CRQ program. In short, the amount of time and effort it takes to implement FAIR (both from a scoping and data collection) was A LOT!

The organization asked to do a trial of the ThreatConnect RQ platform and was very clear that they wanted a FAIR-only approach. That was easy as our platform supports the use of FAIR, but also takes risk quantification beyond FAIR through the use of AI/ML and the MITRE ATT&CK framework.

Fast forward a few weeks. The organization realized that continuing down the FAIR path would ultimately be detrimental to their program because of the overhead with implementing FAIR – training staff (both analysts and SMEs), finding time amongst everyone’s busy days, and gaining consensus with every analyst for the analysis process would be too much work and would take too much time for the organization to absorb. This got them wondering if they could leverage an AI-powered approach to risk quantification for most of their risks and reserve the manual FAIR-based approach for specific scenarios.

This organization realized that using the data-driven approach provided by ThreatConnect RQ would also help them scale their program. This was because they could use their own data from their existing tools (CMBD/asset lists, vulnerability scans, GRC, etc.) and let RQ do all the hard work. Even with that desire, they also began to worry that maybe the data in their tools wasn’t good enough. But they quickly realized that even if it wasn’t perfect data, the decision to improve the data in their tools could be an outcome of a risk assessment. Starting with the industry data provided by ThreatConnect will allow them to focus on their biggest areas of risk. The lightbulb went off, and they decided this was indeed the easier and faster way to measure their cyber risk quantitatively. They could always improve upon their data in the future as their program matures. In leveraging this approach, they could start communicating risk in a way that actually moves the needle and really action upon risk.

Fast forward a few weeks. They were able to quantify over 300 business applications within less than 30 days by simply using the AI-driven approach offered by ThreatConnect RQ. This allows them to spend their resources on managing the risk instead of trying to figure out how to measure it.

Throughout this endeavor (and now as a customer), this organization realized that with the help of ThreatConnect RQ and the experienced Customer Success team, they could truly make risk management actionable within their organization. All without the requirement of spending thousands upon thousands of extra dollars on professional services to help them set up, train them, implement it and measure risk for them.

Want to achieve the same CRQ benefits?

If you want to learn more about how ThreatConnect can help you move beyond FAIR and scale your cyber risk quantification program, reach out to one of our experts today. Want to see more of ThreatConnect RQ? Take a guided tour of RQ right now.

The post Recognizing the Limitations of FAIR appeared first on ThreatConnect.

View Details

In a recent webinar, Addressing the SEC Requirements for Materiality Disclosure, industry experts shed light on the intricate balance between cybersecurity management and the new regulatory requirements enforced by the Securities and Exchange Commission (SEC). They discussed the critical aspects of risk management, emphasizing the importance of quantifying cybersecurity risk and the role of executive management in fostering a robust cybersecurity posture.

Myrna Soto, Founder and CEO of Apogee Executive Advisors LLC, with a background that spans over 16 years as a CIO and now serving on the board of directors, paired with the experience of Jerry Caponera, GM of Cyber Risk Products in risk qualification and board advisement, provided attendees with a comprehensive overview of the evolving SEC requirements and effective cybersecurity strategies.

They emphasized the urgent need for organizations to pivot towards a more quantifiable approach to assessing cybersecurity risks and incident materiality. Adopting quantifiable measures that organizations can utilize internally to determine the materiality of cybersecurity incidents helps support better decision-making and more transparent disclosures.

A crucial point in this discussion is the concept of “materiality.” Businesses must proactively assess what constitutes a significant enough incident to warrant reporting under the SEC regulations. The definition of Materiality is vague, which is good because companies should be able to define it based on their business however, it’s still challenging because there is little guidance. United Healthcare recently suffered a large breach where the expected cost could exceed $1B, but in their most recent filings, they didn’t claim it was material. The ambiguity in the SEC guidelines was intentional but will most likely be updated in the future to be more specific.

These discussions provide valuable insights into the SEC’s cybersecurity regulations and their implications for companies. For example, ThreatConnect Risk Quantifier (RQ) helps manage these issues by illustrating financial exposure to attacks and quickly addressing the materiality question.

As secure investment planning emerges as a critical business factor, materiality thresholds become vital in determining which instances warrant attention. Adopting structured risk quantification constructs will aid businesses in making informed investment decisions. Companies face the continual challenge of measuring and appropriately conveying their assessment or outcomes to the board.

In conclusion, this webinar underlined the evolving landscape of cyber risk management in response to stringent SEC guidelines. While organizations may initially perceive these SEC regulations as burdensome, seeing them as beneficial guidelines will change their perspective. After all, the regulations aim to ensure transparency in managing cyber risks, promote best practices, drive investor confidence, and ultimately lead to a more secure market. Myrna and Jerry’s insights into quantifiable risk measures, internal discussion of materiality thresholds, and the value of scenario planning offer a strategic roadmap for organizations navigating these regulatory complexities. Aligning cybersecurity measures with quantifiable risk management practices not only aids in making informed security investment decisions but also fosters a stronger case in discussions with boards or during unfortunate incidents.

To get started on your cyber risk quantification journey – explore tools and frameworks that enable risk quantification and engage with leadership to ensure a shared understanding of the cybersecurity risk landscape. Organizations should examine their current security measures, consider the quantifiable impact of potential security investments, and align their cybersecurity strategy with broader business objectives.

Check out ThreatConnect Buyer’s Guide for Cyber Risk Quantification Solutions to explore the different types of CRQ solutions. From semi-quantitative measurements to AI-powered solutions, CRQ techniques continue to evolve. Discover how these approaches streamline risk assessment processes and drive effective risk mitigation strategies.

Explore ThreatConnect Risk Quantifier – designed to operationalize cyber risk quantification effortlessly. ThreatConnect RQ addresses common cyber risk management challenges and paves the way for superior decision-making and strategic planning. You can take the interactive tour here or reach out to our experts for a demo!

The post Understanding the SEC’s Recent Cybersecurity Regulations appeared first on ThreatConnect.

View Details

I’m excited to announce the latest version of ThreatConnect Risk Quantifier (RQ) and a new addition to the RQ solution family, RQ Impacts!

Introducing RQ ImpactsRQ Impacts is a simplified version of RQ Enterprise that helps answer common cyber risk questions businesses face quickly and easily. You don’t need to be a cyber risk quantification expert; just a few data inputs are enough to produce robust, quantified financial impact outputs. RQ Impacts help answer questions such as:

  • I’m a publicly traded company in the U.S. How do I define materiality for my company before an incident occurs?
  • What is the optimal cyber insurance coverage for my organization?
  • How do I compare to my peers?

What’s new in ThreatConnect RQ?RQ version 7.7 brings some great new features to make users more efficient and effective.

Peer AnalyticsA common question among cybersecurity leaders is, “How do I compare to my industry peers?” Peer Analytics in RQ helps answer this question. It provides three industry peer examples aligned with your firmographics (industry, revenue, number of employees) by loss and revenue for attack events. CISOs are now empowered to answer this question from executives and the board with confidence and defensibility backed by industry data.

New Side Navigation Bar and Analysis SummaryRQ has a new side navigation bar to make accessing features faster and easier.

Other updates in version 7.7 include:

  • SLE loss type is now available in exported CSVs
  • A new RQ FAIR-Only user role
  • Support for SAML SSO

Take the next stepIf you’d like to learn more about ThreatConnect RQ and RQ Impacts, take our interactive tour or contact one of our cyber risk experts.

The post Announcing Risk Quantifier 7.7 and Introducing RQ Impacts appeared first on ThreatConnect.

View Details

CTI analysts encounter numerous challenges in handling the constant influx of data from various unstructured open-source intel (OSINT) sources, such as reports and blogs, news sites, and other websites. ThreatConnect’s CAL Automated Threat Library (ATL) efficiently distills over 60 definitive OSINT sources into a structured and ready-to-use threat intel feed.

CAL: Real-Time Insights and Global IntelligenceIn our last blog, we explored the source of power – the brain, if you will – of ThreatConnect’s TI Ops Platform—ThreatConnect CAL. CAL is a comprehensive solution from ThreatConnect, utilizing AI and ML-powered analytics to offer real-time insights and context into threats and their behaviors. This includes automated ATT&CK analysis, unique feeds specific to ThreatConnect, and the collective intelligence shared among ThreatConnect users.

With a little grounding in CAL’s overall scope and power, let’s now focus on the Automated Threat Library (ATL) within CAL.

CAL ATL: Simplifying OSINT HandlingThe Automated Threat Library (ATL) plays a crucial role in simplifying the handling of unstructured OSINT. By distilling information from diverse sources into a structured format, CAL ATL automates the heavy lifting required by analysts. This saves valuable time and enhances the efficiency of threat intelligence operations.

Once identified by ATL, IOCs are seamlessly integrated and enriched with relevant information, such as Classifiers, MITRE ATT&CK tactics and techniques, and Domain Generation Algorithms discovered through Machine Learning. ThreatAssess scores and Classifiers further aid teams in focusing on the most critical intelligence.

Easy to Read and DigestAll of CAL ATL is assembled in one feed that is easy to search and consume. CAL ATL automatically tags intelligence with known aliases for mentioned groups, such as threat actors, malware, etc. CAL ATL users can also select CAL Alias Information or combine group nodes by alias to provide a better understanding of which objects are related to a given Group. This saves time for analysts so they don’t have to manually deduplicate all the threat actor group names.

AI Insights: Elevating Report UnderstandingCAL ATL provides an AI-Generated summary card prominently displayed at the top of the Report Group’s overview page. This summary consists of brief, easy-to-read bullet points, providing users with a high-level understanding of the report’s contents. This empowers users to efficiently decide whether a report warrants further attention or analysis, optimizing their workflow and ensuring a more focused and informed approach to threat intelligence.

Strategic Intelligence SourceCAL ATL is a strategic intelligence source. By incorporating an organization’s intel requirements in the TI Ops Platform’s Intelligence Requirements feature, analysts can quickly provide intel to help decision-makers answer critical questions and stay informed about emerging threats. The structured threat intel feed allows for efficient communication and informed strategies.

Benefits of CAL ATLThe practical approach of CAL ATL offers a robust, accurate, and actionable solution to the challenges of handling high volumes and varieties of OSINT. By staying abreast of the latest threats, improving analyst operational efficiency, and facilitating faster, informed decision-making, CAL ATL becomes an essential tool in the cybersecurity arsenal.

For more details, please tour the ThreatConnect TI Ops and reach out to sales@threatconnect.com or request a demo to learn more about how ThreatConnect can help you operationalize your threat intel program.

The post CAL™ ATL: Collecting and Analyzing Open Source Intel Faster and Easier appeared first on ThreatConnect.

View Details

We are excited to announce an update to the integration between the ThreatConnect Threat Intelligence Operations Platform and Recorded Future!

Knowing which adversaries are targeting your organization is vital to ensure you have the right threat defenses in place. Attackers, like ransomware gangs and nation-states, are looking for entry points into an organization and will abuse any exposure they find to achieve their goals, whether that’s via phishing emails or vulnerabilities in your systems and apps.

The Recorded Future Intelligence Engine App makes it quick and simple to integrate Record Future’s Threat Intelligence, SecOps, and Vulnerability Intelligence solutions into the ThreatConnect TIOps Platform, ingesting Domain, Hash, IP, URL, and Vulnerability Risk Lists, as well as Recorded Future Insikt Group Analyst Notes. The integration automatically digs deeper into the intel supplied by Recorded Future, following links in indicator and vulnerability intel and Insikt notes and providing that additional context directly within the ThreatConnect Platform.

The App is customizable allowing specific threat intelligence to be supplied to ThreatConnect, for example, intel with a specific Risk Score. The integration leverages ThreatConnect’s Threat Intelligence Engine, making it easy to monitor and manage the Recorded Future integration via a single interface – Dashboard and Reports let you monitor integration performance, while Jobs, Tasks, and Downloads enable precise management of the integration.

This integration is available now to ThreatConnect and Recorded Future customers via the App Catalog in the TIOps Platform. If you are interested in learning more about this integration, please visit the ThreatConnect Marketplace.

Want to experience the power of ThreatConnect’s TIOps Platform? Check out our interactive demo to see it in action. Please reach out if you have any questions about this integration or the Platform, and one of our experts would be happy to chat with you.

The post Announcing Our Enhanced Integration with Recorded Future appeared first on ThreatConnect.

View Details

Many organizations face the challenge of operating across multiple platforms, making managing cyber risk as part of their cybersecurity strategy daunting. Traditional cyber risk management programs often utilize Governance, Risk, and Compliance (GRC) heatmaps that use shades of red, yellow, and green, with qualitative terms, ratings, and scores as risk measurements. However, these methods make it challenging to manage cyber risk effectively. To address these issues, ThreatConnect and ServiceNow have come together to provide the Risk Quantifier (RQ) App for ServiceNow GRC. This game-changing solution integrates the financial quantification of cyber risk directly within existing risk management workflows.

With the RQ App, you can quickly and easily measure the monetary impact of risks and the effect of mitigating controls on those risks across your organization. Integrating measurable figures in your Integrated Risk Management (IRM) product offers clearer visibility into your risk profile, enabling you to make well-informed decisions about cost-effectively reducing risks.

By incorporating this feature, ServiceNow customers can leverage ThreatConnect RQ’s AI-powered analytics engine to assess the financial impact of cyber risk with IRM and generate automated risk reduction recommendations in financial terms. This will enable you to convert your qualitative ratings and ordinal scales to quantitative metrics, allowing you to effectively communicate and manage the most critical risks facing your organization. With the holistic ServiceNow GRC platform and the RQ App, we can offer a comprehensive solution for risk management.

Often, risks are prioritized subjectively, with input from various business leaders. While these feelings may be valid, prioritization decisions must be made using objective data that can be defended. This approach helps ensure that resources are directed to mitigating the greatest risks to the business.

Many organizations are implementing some form of cyber risk quantification to make better-informed decisions as part of their cybersecurity strategy. This process enables them to communicate cyber risk to the board more effectively and create a resilient cybersecurity program based on objective data expressed in business terms. By quantifying risk, organizations can identify and prioritize security initiatives that drive a more significant financial risk reduction. This shift towards quantifiable cyber risk management is integral to resilient cybersecurity strategies, granting organizations the advantage of informed resource allocation. This approach ensures that they don’t waste time and resources in areas that feel risky but are not truly as harmful as initially suspected.

The partnership between ThreatConnect and ServiceNow ushers in a new era of cyber risk management, where defensible and actionable financial risks can be assessed directly within the enterprise risk management platform. By enabling this data-driven decision-making, leaders can calibrate investments to actual impacts, maximizing the effectiveness of the organization’s defenses. With the new RQ App, ServiceNow and ThreatConnect are evolving and expanding how organizations can access the benefits of risk quantification.

To learn more about the new RQ App for ServiceNow, please visit the ServiceNow Store. You can read our press release here.

To learn more about ThreatConnect RQ, check out our interactive demo or reach out to speak with an expert.

The post ThreatConnect RQ Integration With ServiceNow To Enhance Governance, Risk, and Compliance Is Now Available appeared first on ThreatConnect.

View Details

In the complex game of geopolitics, the digitized world has to contend with cyber threats that don’t conform to conventional rules. Nowhere is this shift more significant than in the sanctity of electoral processes. With many physical and digital elements involved across federal, regional, state, and local elections, ensuring the integrity of the voting process and results is vitally important.

Cybersecurity has become an increasingly important component as nation-states seek to influence and potentially disrupt elections. Getting ahead of adversaries before they can impact an election is vital to the overall security of electoral systems. To achieve these insights, agencies and their cybersecurity teams need high-fidelity cyber threat intelligence (CTI) that is relevant and actionable. CTI is one of the key tools in making election infrastructure and processes resilient to attacks.

There are excellent resources online from CISA and ENISA if you’d like to learn more about election cybersecurity.

Challenges in Election SecurityThe heart of election security is not only in the casting and counting of votes, but in the entire democratic process leading up to election day. This process is now tied to the new forms of digital communication; thus, it is inherently at risk. The rise of digital voting systems, the reliance on electronic communication for campaigns, and the pervasive spread of information online have created new points of vulnerability that malicious actors can exploit.

Vulnerabilities in the Electoral ProcessWhile traditional voting mechanisms are not without risk, digital systems introduce new vulnerabilities. These may include:

  • Data Integrity: Ensuring the accuracy of voter registration databases and election results against tampering.
  • Destructive Malware and Ransomware: The potential for attacks that could disrupt critical election systems and processes.
  • Phishing: Targeting election officials or political organizations to gain unauthorized access and steal sensitive information.

Targeted Cyberattacks and Disinformation CampaignsCyber threats during the electoral period are not just technical—they often intersect with the world of disinformation and propaganda and, most importantly, are not theoretical. They are happening:

  • Social Engineering Attacks: Malicious attempts to sway voters by exploiting social media.
  • Information Warfare: Coordinated campaigns to alter perceptions and influence the course of elections.
  • Deep Fakes: The creation of misleading audio and video content to discredit candidates or parties.

An example of how the threat actors operate was detailed in the US Justice Department’s indictment of Iran-based actors trying to influence the 2020 Presidential Election. They “… obtained confidential U.S. voter information from at least one state election website; sent threatening email messages to intimidate and interfere with voters; created and disseminated a video containing disinformation about purported election infrastructure vulnerabilities; attempted to access, without authorization, several states’ voting-related websites; and successfully gained unauthorized access to a U.S. media company’s computer network…”

Role of Cyber Threat Intelligence for Threat Awareness and PreventionCTI is an instrument of awareness in the battle for election security. It is the gathering and analysis of information about adversaries’ capabilities, their intent, and the opportunities they have for attacks across the electoral process. In the context of election security, CTI serves as both a shield and a spear:

  • Proactive Monitoring: Utilizing human expertise and tools like threat intel platforms (TIPs) to monitor for potential threats before they materialize.
  • Adaptive Response: Employing real-time indicators to tune defenses as situations change.
  • Threat Actor Campaign Analysis: Examining previous tactics deployed in similar elections to predict and anticipate future attacks.

The Need for Operational, Tactical, and Strategic CTIIt’s important to reinforce the need for all types of threat intel in election security.

  • Operational: Indicators can be used to proactively defend election infrastructure and systems, and tools like email are common threat vectors to compromise organizations through phishing attacks.
  • Tactical: Understanding threat actor tactics, techniques, processes, tools and infrastructure, and behaviors can be used to identify defensive gaps and make improvements proactively. For example, MITRE ATT&CK can be used to gain more precise awareness of how adversaries operate and communicate that knowledge across cybersecurity teams.
  • Strategic: Guides forward-looking strategic planning and decision-making with greater precision and effectiveness.

The Importance of Collaboration and Information SharingSharing CTI across government agencies and private cybersecurity firms is vital for ensuring election security. In this domain, no entity is an island, and collective threat intelligence is strong currency against the range of cyber threats and actors. Intel sharing takes the form of:

  • Public-Private Partnerships: Joint initiatives between government and private sectors to exchange threat information and best practices.
  • International Cooperation: Engaging with global partners to create a united front against cross-border cybersecurity threats.
  • Information Silos vs. Sharing Cultures: Breaking down barriers to information flow for a more dynamic and responsive collective defense.

How ThreatConnect Can HelpOperationalizing threat intelligence is crucial in ensuring your organization and those you share intel with through partnerships are tracking the most relevant threats and actor activities. The ThreatConnect TIOps Platform has various features and capabilities that make it easier to produce actionable, high-fidelity threat intel and disseminate it to stakeholders in the right format at the right time.

  • Intelligence Requirements allows CTI teams to document and action requirements from stakeholders, whether high-level intel requirements (IRs), priority intel requirements (PIRs), ad-hoc requests, etc.

  • CAL Automated Threat Library is the time-saving approach to monitoring over 60 definitive sources of open-source intel. The AI-powered analytics in CAL uses GenAI, natural language processing (NLP), and machine learning (ML) to automatically summarize the intel, and understand and ingest IOCs and ATT&CK tactics and techniques from those sources, removing hours of manual work from analysts.

  • ATT&CK Navigator enables the tactics, techniques, and sub-techniques tracked across multiple threat intel data points to be displayed visually, enabling analysts to get deep insights into threat actor behaviors and map that against current defensive control coverage.

  • Native support for STIX and TAXII, and pre-built Apps for integrating with popular technologies make it easy to share intel with trusted partners through a variety of mechanisms, such as through MISP for example.

ConclusionElection security in the digital age demands a robust approach to cybersecurity. Proactive, intel-driven defense is not just an option—it’s a necessity. The application of cyber threat intelligence helps assure the integrity of election processes.

For those in the trenches of election planning and execution, the message is clear—CTI is not just an abstract principle. It’s time to make CTI a mandatory component of electoral infrastructure, not just a nice-to-have.

Take the next step!If you would like to learn more about how ThreatConnect enables threat intel and security operations teams to gain insights on threat actors and proactively improve defenses with high-fidelity threat intelligence, experience an interactive tour of our TI Ops Platform or reach out and chat with one of our experts.

The post The Role of Cyber Threat Intelligence in Election Security appeared first on ThreatConnect.

View Details

ThreatConnect is introducing a set of exciting new upgrades to its Threat Intelligence Operations Platform with release 7.5, aimed at enhancing team efficiency in the face of evolving cyber threats.

Explore more features updates with our TI Ops 7.5 interactive demo

Customized Detail Screen for PrecisionNew for TI Ops Platform version 7.5 is our Customizable Details Screen for Groups and Indicators, allowing analysts to tailor their workflow and ensure critical information is readily accessible, reducing the risk of overlooking vital details. ThreatConnect prioritizes user experience, ensuring it’s intuitive and improves team workflow.

Tailored Details for Efficient ProcessesThe Customizable Details Screen for Groups and Indicators empowers users to personalize their default Details Screen. This enhancement streamlines processes by reducing the need to search for information across multiple tabs and providing quick access to relevant data. This maximizes insights, enhances efficiency, and promotes speedy collaboration.

Efficient Reporting Made SimpleAlso, in Release 7.5, ThreatConnect improves the report creation experience with Custom Templates for Groups. These templates transform data into actionable, reusable reports, ensuring your team stays informed and up-to-date on the latest threats. With the Custom Templates for Groups, analysts will be able to leverage more:

  • Adaptability: Custom Templates for Groups cater to a variety of requirements.
  • Time Savings: Reduces the time spent on each report, allowing analysts to focus on strategic intel analysis.
  • Flexibility: Enables the addition of more sections as needed.

ThreatConnect’s CommitmentThreatConnect regularly reaffirms its commitment to enhancing capabilities and outcomes through our streamlined reporting through Templates and a Customizable Detail Screen.

For more details, take our interactive tour! If you are ready to see how ThreatConnect can help your organization operationalize threat intelligence, please reach out to sales@threatconnect.com or request a demo.

The post TI Ops Platform 7.5: More Flexibility With Customization and Templates appeared first on ThreatConnect.

View Details

Cyber attacks have surged to the forefront of significant enterprise risk factors in the modern business landscape. As businesses continue to embrace digital transformations, the resultant increase of their attack surface leads to increased exposure and successful cyber attacks, creating substantial risk. Why? Cyber risks fundamentally differ from traditional risks businesses face and, thus, are more challenging to manage, measure, and mitigate. The regulatory landscape is quickly changing alongside the threat landscape, putting more pressure on organizations (e.g., publicly traded companies must comply with the US SEC cybersecurity rules.)

This is where the importance of cyber risk management comes in, but there are challenges commonly encountered in analyzing and managing cyber risks – visibility, effort, and data analysis. This is why cyber risk quantification (CRQ) is crucial, and the financial quantification of cyber risks is the key to a robust cyber risk management program. CRQ provides a measurable way to ensure that investments in a cyber risk program are beneficial across a multitude of business functions and use cases. If you’d like to learn more about CRQ, be sure to check out our Guide to Cyber Risk Quantification.

Implementing CRQ needs tools and solutions that bridge the gap between those responsible for cyber risk and the program’s processes. The question is, which solution is appropriate to support your CRQ efforts?

The ThreatConnect Buyer’s Guide for Cyber Risk Quantification Solutions is here to help you answer that question!

In this guide, learn about the common use cases and the solutions used for quantifying cyber risks, along with the benefits and limitations of each type of solution. The guide covers do-it-yourself, FAIR-oriented, and modern AI and data-powered solutions, enabling you to know which option best suits your CRQ journey.

Download the Buyer’s Guide to CRQ Solutions today!

Download Here

To learn more about cyber risk quantification or to get a custom demo of ThreatConnect Risk Quantifier (RQ), reach out to one of our experts or take a tour right now to learn more about the power of RQ.

The post Introducing the ThreatConnect Buyer’s Guide for Cyber Risk Quantification Solutions appeared first on ThreatConnect.

View Details

ThreatConnect is excited to announce a new integration with Spur! The integration with Spur’s Context-API allows a range of ThreatConnect users – intel analysts, detection engineers, SOC analysts, threat hunters, and incident responders – to save effort when enriching IP address Indicators to facilitate their work. Spur enables threat intel and security operations teams to gain advanced detection of anonymization and threats to counter fraud and other malicious activity.

Spur Context-API is a REST API service providing detailed IP context. It offers rapid IP search with actionable data, including client behaviors, geographical concentration, and associated risks. The outputs analysts benefit from include autonomous system details, client behavior and geographic information, known risks and threats associated with the IP, VPN and proxy insights, org details, and much more.

Using Spur’s Context-API is really easy. It can be leveraged via Playbook automations in the ThreatConnect TI Ops Platform. Playbooks allow organizations to easily create custom automations using a drag-and-drop, low-code interface. Access to Spur’s rich IP address context is done using a pre-built Playbook App. This allows IP address context to be quickly incorporated into new and existing automations, saving analysts time and reducing manual effort.

Want to learn more?

Checkout the Spur Playbook App in the ThreatConnect Marketplace. To learn more about how ThreatConnect and Spur can help you reduce malicious attacks and fraud activities, reach out to an expert at ThreatConnect today.

Contact Us

The post Announcing A New Integration Between ThreatConnect and Spur appeared first on ThreatConnect.

View Details

Let’s dive into the source of power – the brain, if you will – of ThreatConnect’s TI Ops Platform—ThreatConnect CAL. This innovative capability uses Generative AI, natural language processing (NLP), and machine learning (ML) to deliver advanced analytics and global intelligence.

Key highlights of CAL features: Advanced Analytics: Access insightful data throughout the platform for operational efficiency. * Rich Data Sources: CAL offers comprehensive intelligence with access to over 300 sources (OSINT, proprietary analytics-powered intel feeds, ThreatConnect user community) and tracking 241 billion data points. * Harness Insights from ThreatConnect User Community:* CAL analyzes over 200 million anonymized, daily observations from ThreatConnect users worldwide to provide a collective perspective on threats.

And there’s more! Let’s further explore CAL’s capabilities and power to enable analysts to gain more efficiency and insights with their threat intel across the ThreatConnect TI OpsPlatform.

Request a Demo

AI Insights – Provides AI-generated summaries within the CAL Automated Threat Library. Users get easy-to-read bullet points and a brief summary, giving users an understanding of a Report’s contents.

MITRE ATT&CK Analysis – CAL’s natural language processing (NLP) analyzes the content in blogs, websites, and other text sources, interprets it, and identifies ATT&CK techniques. This streamlines the laborious process of analysis and tagging intel details, saving time and effort.

CAL Automated Threat Library – CAL Automated Threat Library streamlines open-source threat intelligence curation. It collects intelligence from over 60 open-source intel (OSINT) sources, including blogs and websites, and simplifies the analyst’s task of reading, analyzing, and memorializing intel from those sources. In practical terms, it helps analysts save hours of manual effort per day.

CAL Feeds – Powered by ThreatConnect’s AI-powered analytics, CAL Feeds provides over 60 novel threat intel feeds unique to ThreatConnect and optimized open-source feeds.

ThreatAssess Scoring – Enhance intelligence scoring with ThreatAssess, minimizing false positives and enabling efficient intel prioritization. ThreatAssess delivers a consolidated score for each Indicator, derived from comprehensive data across all intel sources in the Threat Library. This approach streamlines the assessment process, promoting accurate evaluation and strategic prioritization of intelligence and threats when there is a potential attack happening.

CAL Feed Explorer and Report Cards -CAL Feed Explorer and Report Cards provide a performance-related insights practical report card for all the intel feeds enabled in the Platform, enabling straightforward comparisons across feeds with aggregated metrics from other feeds. It’s a valuable feature for feed analysis and optimization. Assess your intelligence feeds with a report card that provides a reliability rating, measures false positives, and performance score based on multiple indicators. Report Cards list Common Classifiers from CAL and analyses for key metrics like Unique Indicators, First Reported, Scoring Disposition, and Classifier Coverage. It’s a concise way to optimize your intelligence sources.

Threat Actor Aliases – Simplify threat intelligence management with Threat Actor Alias Deconfliction. This feature translates threat actor group aliases, facilitating seamless coordination across various sources in the threat intelligence landscape.

Intelligence Anywhere – Efficiently gather information from online resources with ThreatConnect Intelligence Anywhere. With a simple click, instantly scan and identify relevant details from various sources, including static and dynamic web pages, social media platforms, and emails. This feature lets you quickly comprehend existing knowledge about a known Indicator or threat and seamlessly add it to your Threat Library for future analysis and investigation efforts.

Indicator Reputations – Leverages the machine learning in CAL to perform reputation analysis, scoring the criticality of an Indicator on a single numeric scale to prioritize decision-making and minimize false positives.

ThreatConnect CAL offers a comprehensive set of features to enhance threat intelligence operations. From advanced analytics to AI-generated summaries, the platform provides features for analysts to efficiently and effectively navigate, analyze, and prioritize threat intelligence.

Take the Next StepFor more details, please tour the ThreatConnect TI Ops or please reach out to sales@threatconnect.com or request a demo to learn more about how ThreatConnect can help you operationalize your threat intel program.

The post Exploring ThreatConnect CAL™: AI & ML-Powered Threat Intel appeared first on ThreatConnect.

View Details

2023 marked a tremendous year for ThreatConnect, with strong new business growth, increasing customer loyalty and expansion, market-leading product innovation, and widespread industry recognition.

Adding, Retaining, and Expanding Marquee Customer RelationshipsThreatConnect had substantial new customer growth in both its threat intelligence operations and cyber risk quantification (CRQ) businesses. A particular highlight was the growth in the CRQ market, where we more than doubled.

In all, we closed new deals with more than 40 enterprises, including:

  • A top 10 software company
  • A Fortune 500 investment management leader
  • A top 5 global airline
  • 10 global government agencies
  • 7 banking and financial services leaders

In addition, we expanded our relationships with 55 enterprise customers. ThreatConnect now serves more than 200 enterprise customers, including:

  • 3 of the top 5 software companies in the world
  • 2 of the top 5 cybersecurity companies in the world
  • 3 of the top 5 U.S. banks
  • 2 of the top 5 airlines
  • 3 of the top 10 pharmaceutical companies
  • 2 of the top 5 insurance providers
  • More than 10 US federal and defense agencies and 10 US state governments

Extending Market Leadership in Threat Intelligence OperationsThreatConnect continued to extend its position as the innovation leader in threat intelligence operations. Key new product innovations include:

  • Intelligence Requirements – By enabling cyber threat intelligence teams to seamlessly document, manage, and action their intelligence requirements directly within the ThreatConnect platform, customers can more efficiently and effectively align their efforts towards the greatest risks to their business. No other threat intelligence management solution offers this capability.
  • ATT&CK Visualizer – This new capability allows customers to analyze their threat intelligence using the Mitre ATT&CK Framework. Our easy-to-use visual tool enables a comprehensive understanding and documentation of threat actor behaviors Using ATT&CK Visualizer, customers can detect, prevent, and respond to threats faster and more effectively.
  • Enhancements to the CAL Automated Threat Library (ATL) – CAL ATL is a unique AI/ML engine that forms the core of the company’s rapidly expanding AI strategy. Today, CAL ATL distills over 60 definitive OSINT sources, such as blogs and social media, into a structured, ready-to-use threat intel feed. It automates aggregation and analysis using AI/Machine Learning and Natural Language Processing (NLP) to extract and tag MITRE ATT&CK tactics and techniques, saving daily hours of manual analyst effort. As we continue to advance our AI/ML innovation, 2023 saw CAL become an even more valuable foundational element of the ThreatConnect platform:
    • The data science and big data analytics team that drive CAL have led our delivery and research in Generative AI capabilities. We’ve launched initial intelligence summarization capabilities in ATL and have even bigger plans for 2024 to make analysts’ lives significantly easier with this technology.
    • The CAL repository experienced remarkable growth by 44% to more than 241 Billion data points, providing a much larger data set to glean intelligence insights.
    • Integration with the new Intelligence Requirements feature allowed customers to find nearly 3 million relevant intelligence insights across 1,500 topics.
  • Native Reporting – By enabling in-platform report generation, ThreatConnect empowers analysts to provide stakeholders with the necessary information and insights to make strategic, tactical, and operational decisions.

2023 was a game-changing year for ThreatConnect. It was a year of innovation and growth, and you can read more about it in our blog.

Meeting the Emerging Need for Cyber Risk QuantificationAs data-driven cyber risk quantification becomes increasingly important for enterprise buyers, ThreatConnect added key innovations to support the growing customer needs for meeting SEC materiality requirements, cyber insurance, and integration with governance, risk, and compliance solutions.

Specific innovations include:

  • SEC Materiality and Cyber Insurance – Leveraging AI and ML-based models, RQ customers can now answers answer questions about SEC Materiality, whether they have good amounts of cyber insurance coverage, and how they compare to their peers in terms of losses
  • ServiceNow Integration – ServiceNow GRC customers can quantify cyber risk in financial terms directly within their current risk assessment workflow. RQ’s AI and ML-based loss models, built with years of loss and attack data, leverage our data, combined with your business and control environment as defined in ServiceNow, to calculate loss and show which improvements provide the best ROI.
  • Custom Loss Models – Customers can now add custom loss models. RQ, enabling users to add their own losses to our existing AI / ML models.

Achieving Industry RecognitionThreatConnect continued to garner the attention of top-tier industry analysts and media, including:

  • ThreatConnect’s Risk Quantifier solution was named a Leader, with the strongest current capabilities, in Forrester’s inaugural Wave for Cyber Risk Quantification.
  • ThreatConnect’s Threat Intel Ops Platform received widespread recognition in the press for our innovative Intelligence Requirements feature announced at Black Hat USA 2023. CRN named ThreatConnect as one of the ’20 Hottest New Cybersecurity Tools at Black Hat 2023.’
  • Selected as a 2023 SC Media Trust Awards Finalist for Best Threat Intelligence Technology
  • Won the Next-Gen Threat Intelligence award at the 11th Annual Global InfoSec Awards at RSAC 2023
  • Named the winner of the Hot Company – Threat Intelligence award from Cyber Defense Magazine (CDM), the industry’s leading electronic information security magazine.

Dave DeWalt Joins as Executive Chairman of the BoardUnderscoring the tremendous opportunity ahead, Dave DeWalt, former CEO of FireEye, McAfee, and Documentum and Founder and CEO of NightDragon, a dedicated cybersecurity, safety, security, and privacy investment and advisory firm, as Non-Executive Chairman of the Board.

Looking Ahead to 2024Coming off the momentum of 2023, ThreatConnect is once again poised for growth in 2024.

Exciting new product capabilities, including the expanded use of AI to surface the greatest risks to our customers’ businesses, set the table for extending the company’s position as an innovation leader. Alongside product innovations, the company will extend its partnerships to open new routes to market and help our customers achieve more value faster.

Read the full press release here

The post ThreatConnect Celebrates 2023 as a Banner Year for Business Growth, Product Innovation, and Industry Recognition appeared first on ThreatConnect.

View Details

2023 was a banner year for ThreatConnect’s Threat Intelligence Operations Platform. The innovative, market-leading features introduced last year allow CTI teams to:

  • Align to the Evolved Threat Intel Lifecycle
  • Operationalize their threat intelligence in a way that benefits the CTI team and their customers
  • Clearly demonstrate the value of the CTI program

So, let’s take a look at what the ThreatConnect TI Ops Platform team delivered in 2023.

January 2023The next major version of the TI Ops Platform, version 7.0 was launched. It brought threat intelligence platforms (TIPs) into the age of Threat Intelligence Operations with new features like:

  • Built-in Reporting
  • Automated Enrichment (starting with VirusTotal)
  • Our new UI design

We also launched the Automated Threat Library (ATL) as part of our regular updates to CAL, the AI-powered “brain” of the ThreatConnect TI Ops Platform. CAL ATL covers 60+ definitive sources of open source threat intel and uses CAL’s natural language processing (NLP) to automatically extract indicators and tag relevant details, like MITRE ATT&CK tactics and techniques, and threat actor aliases using our “Rosetta Stone” of threat actors.

April 2023Version 7.1 delivered enhancements to a variety of features in the platform, for example:

  • The ability to execute Playbook automations directly within Threat Graph
  • Automated enrichment was expanded with coverage for Shodan

July 2023Version 7.2 was a major milestone in the evolution of the TI Ops Platform with the introduction of ATT&CK Visualizer. Visualizer does what it says – it allows organizations to visually analyze their threat intelligence in the MITRE ATT&CK Framework directly in the Platform instead of having to use ATT&CK Navigator or spreadsheets.

We also released features to improve the operationalization of threat intelligence, like

  • Tag Normalization and Management to enforce standardization of the tags used by teams
  • Built-in Reporting enhancements for report management and easier dissemination
  • Automated Enrichment was expanded with coverage for URLScan.io

October 2023ThreatConnect broke new ground in operationalizing threat intel with the introduction of Intelligence Requirements in version 7.3. This feature was announced at Black Hat USA and received significant press coverage, such as being named by CRN as one of 20 Hottest New Cybersecurity Tools at Black Hat 2023 and one of the top new cybersecurity products by CSO Online.

And beyond launching Intelligence Requirements, we also delivered

  • ATT&CK Visualizer enhancements that expanded its capabilities to provide a heatmap of tactics, techniques, and sub-technique coverage across multiple Groups.
  • Automated Enrichment was expanded to DomainTools

Looking at 20242024 is already off to a bang with the release of version 7.4. I won’t spoil the surprises here, so be sure to check out the blog announcing the release. And don’t forget to take a tour of the ThreatConnect TI Ops or reach out to one of our experts to learn more about how ThreatConnect can help you operationalize your threat intel program.

The post 2023: An Innovative Year for the ThreatConnect TI Ops Platform appeared first on ThreatConnect.

View Details

The cybersecurity landscape is complex and fraught with many threats and vulnerabilities. Understanding and navigating this space requires access to up-to-date information on the activities of threat actors, which you can get through ThreatConnect ATT&CK Visualizer.  What is ATT&CK Visualizer? ThreatConnect ATT&CK Visualizer is our new interactive platform capability that visualizes the MITRE ATT&CK matrix […]

The post Top 5 Use Cases for ATT&CK Visualizer appeared first on ThreatConnect.

View Details

In the first blog of this series, I took a 30,000 foot view of the seven tenets of TI Ops defined in the Dawn of Threat Intelligence Operations paper. In this blog, I’m diving deeper into Tenet #4 – Focus is not solely on indicators of compromise, but expands to cover the motivations, tactics, techniques, […]

The post The 7 Tenets of Threat Intelligence Operations – Tenet #4 – Go Beyond IoCs appeared first on ThreatConnect.

View Details

Another Black Hat USA is in the books, and we’re already looking forward to 2024. The energy across the event was great, and as always, it was fun to catch up with colleagues, customers, and friends in person. I polled my colleagues on their takeaways from this year and what changed from BHUSA 2022.  Quality […]

The post That’s A Wrap From Black Hat USA 2023 appeared first on ThreatConnect.

View Details

We’re improving our integration with Intel 471 by releasing more apps and functionality between the platforms. We now have multiple Runtime Playbook Apps, a Job App, and a Service App for joint customers to leverage. The following use cases are enabled through this integration: Utilize Intel 471 intelligence in an enrichment fashion to correlate and […]

The post ThreatConnect and Intel 471: Comprehensive Intelligence to Protect Your Mission appeared first on ThreatConnect.

View Details

BlackHat 2023 is just around the corner, and before you head out to Vegas, it’s important to ensure your devices are secure and know what to look out for. To help attendees prepare for their security during the conference, here are some best practices to follow: Avoid public Wi-Fi networks, including hotel networks. Wi-Fi compromise […]

The post Preparing for Black Hat 2023: How To Stay Safe at One Of The Largest Cybersecurity Conferences appeared first on ThreatConnect.

View Details

In the first blog of this series, I took a 30,000-foot view of the seven tenets of TI Ops defined in the Dawn of Threat Intelligence Operations paper. In this blog, I’m diving deeper into Tenet #3 – Threat intel is aligned and focused on the most critical risks to the business through a living […]

The post The Tenets of Threat Intel Operations – Tenet #3 appeared first on ThreatConnect.

View Details

In today’s rapidly evolving cybersecurity landscape, organizations realize the significance of quantifying cyber risk to make informed decisions. This blog highlights our recent case study that explores the challenges a leading pharmaceutical company faces in its risk quantification and analysis processes. We will look at how the implementation of ThreatConnect Risk Quantifier (RQ) revolutionized their […]

The post Transforming Cyber Risk Quantification and Analysis: A Customer Case Study with ThreatConnect Risk Quantifier appeared first on ThreatConnect.

View Details

Today, we’re launching version 7.2 of the ThreatConnect TI Ops Platform. It’s an exciting day because, with this release, we’re giving a massive upgrade to our customers with some fantastic new features and capabilities. Our latest features now include ATT&CK Visualizer, ThreatConnect’s native ATT&CK navigator, and Tag Normalization and Management.  ATT&CK Visualizer will enable Threat […]

The post ThreatConnect 7.2: Harnessing ATT&CK Visualizer for Evolved Threat Intel appeared first on ThreatConnect.

View Details

The Forrester Wave™: Cyber Risk Quantification, Q3 2023 report acknowledges ThreatConnect’s pioneering approach to Cyber Risk Quantification (CRQ), ranking ThreatConnect highest in the current offering category of all evaluated CRQ tools. According to the report, “ThreatConnect sets the standard for a threat-driven approach to CRQ.” This recognition is a testament to ThreatConnect’s commitment to delivering […]

The post ThreatConnect Named a Leader in Cyber Risk Quantification Report by Independent Research Firm appeared first on ThreatConnect.

View Details

In today’s interconnected world, software supply chains play a crucial role in the functioning of businesses and organizations across various sectors. However, they also present a significant risk to cybersecurity. The increasing complexity and interdependencies within software supply chains have made them vulnerable to various threats, such as malware, data breaches, and unauthorized access. To […]

The post The Power of CRQ in Managing Software Supply Chain Risks appeared first on ThreatConnect.

View Details

The Shiйy ФbjЭkt? ThreatConnect challenges Guccifer 2.0’s claimed attribution for the Democratic National Committee (DNC) breach Read the full series of ThreatConnect posts following the DNC Breach: “Rebooting Watergate: Tapping into the Democratic National Committee“, “Shiny Object? Guccifer 2.0 and the DNC Breach“, “What’s in a Name Server?“, “Guccifer 2.0: the Man, the Myth, the Legend?“, […]

The post Shiny Object? Guccifer 2.0 and the DNC Breach appeared first on ThreatConnect.

View Details

Guccifer 2.0: the Man, the Myth, the Legend? ThreatConnect reassesses Guccifer 2.0’s claims in light of his recent public statements Read the full series of ThreatConnect posts following the DNC Breach: “Rebooting Watergate: Tapping into the Democratic National Committee“, “Shiny Object? Guccifer 2.0 and the DNC Breach“, “What’s in a Name Server?“, “Guccifer 2.0: the Man, […]

The post Guccifer 2.0: the Man, the Myth, the Legend? appeared first on ThreatConnect.

View Details

Guccifer 2.0: All Roads Lead to Russia Update 07/26/2016  4:00pm EDT Joe Uchill with The Hill, who has previously covered Guccifer 2.0 and the Wikileaks DNC data dump, has provided us with redacted information on his communications with Guccifer 2.0 that has raised our confidence in our current assessments and hypotheses. Check out Joe’s story […]

The post Guccifer 2.0: All Roads Lead to Russia appeared first on ThreatConnect.

View Details

This post can also be found on the Fidelis blog, ThreatGeek.             FANCY BEAR Has an (IT) Itch that They Can’t Scratch ThreatConnect and Fidelis team up to explore the Democratic Congressional Campaign Committee (DCCC) compromise Read the full series of ThreatConnect posts following the DNC Breach: “Rebooting Watergate: Tapping into the Democratic National […]

The post FANCY BEAR Has an (IT) Itch that They Can’t Scratch appeared first on ThreatConnect.

View Details

[av_textblock size=” font_color=” color=” av_uid=’av-351khbb’] ThreatConnect Identifies DCLeaks As Another Russian-backed Influence Outlet Read the full series of ThreatConnect posts following the DNC Breach: “Rebooting Watergate: Tapping into the Democratic National Committee“, “Shiny Object? Guccifer 2.0 and the DNC Breach“, “What’s in a Name Server?“, “Guccifer 2.0: the Man, the Myth, the Legend?“, “Guccifer 2.0: All […]

The post Does a BEAR Leak in the Woods? appeared first on ThreatConnect.

View Details

Can a BEAR Fit Down a Rabbit Hole? ThreatConnect Identifies Infrastructure Nexus Between Attacks Against State Election Boards and Spearphishing Campaign Against Turkish, Ukrainian Governments Read the full series of ThreatConnect posts following the DNC Breach: “Rebooting Watergate: Tapping into the Democratic National Committee“, “Shiny Object? Guccifer 2.0 and the DNC Breach“, “What’s in a Name Server?“, […]

The post Can a BEAR Fit Down a Rabbit Hole? appeared first on ThreatConnect.

View Details

Threat intelligence is crucial in understanding the threat landscape and making informed decisions. Priority Intelligence Requirements (PIRs) are central to effective threat intelligence planning and operations. PIRs enable organizations to prioritize and act upon the most relevant threats, giving focus to the management of threat intelligence. In this blog, we explore the concept of PIRs […]

The post The 7 Critical Elements of a Robust PIR appeared first on ThreatConnect.

View Details

The evolving cyber threat landscape demands an innovative approach to cybersecurity, especially for large enterprises. Retail organizations and banks, in particular, face complex challenges in managing and mitigating cyber threats. The amount of data involved, coupled with the need to access multiple sources of intelligence, can be overwhelming. Our goal is to explore the changing […]

The post The Future of Threat Intelligence for Large Enterprises appeared first on ThreatConnect.

View Details

In today’s interconnected world, organizations rely heavily on a complex network of suppliers and vendors critical to their operations. They supply software used across an enterprise and provide services that may be part of essential business processes. While these partnerships offer numerous benefits, they can also introduce significant cyber risks that can impact the security […]

The post Why Threat Intel is Critical for Supply Chain Security appeared first on ThreatConnect.

View Details

Alternate titles: “Diamonds are a Sith’s best friend” “I used to Bullseye Womp Rats in my t-shirt back home.” “That’s no Shamoon…it’s a space station attack! Those of you who know ThreatConnect well are aware that we’re Star Wars fans. A recent example and awesome webinar if you haven’t seen it – The Need for […]

The post Applying the Diamond Model for Threat Intelligence to the Star Wars’ Battle of Yavin appeared first on ThreatConnect.

View Details

Welcome back, Class! This is ThreatConnect 101 for CTI analysts featuring me…a former analyst and all-around nerd. If you haven’t seen the first post in this series, I highly recommend checking that out before diving into this one. You can find it here. Part 1 lays the foundation that we’ll build upon in this post, […]

The post Day in the Life of a TI Analyst Part 2: Dashing Through Dashboards appeared first on ThreatConnect.

View Details

In the first blog of this series, I took a 30,000-foot view of the seven tenets of TI Ops defined in the Dawn of Threat Intelligence Operations paper. In this edition we are going to dig into Tenet #2 – Requires an Evolved Threat Intelligence Lifecycle, one that emphasizes the planning and requirements and the use of threat intel by the consumers

My colleague Dan Cole, VP of Product Management, who conceived the Evolved Threat Intel Lifecycle, agreed to answer my questions and provide his insights, like an AMA, about why an evolution of the current threat intel lifecycle and why it’s needed now, and how it helps both TI Ops and SecOps teams. First, a brief background on the current Cyber Threat Intel Lifecycle.

The current lifecycle consists of 5, or 6, phases depending on the version:

  1. Planning and Direction (aka Requirements)
  2. Collection
  3. Processing
  4. Analysis (and Production)
  5. Dissemination, and
  6. Feedback (sometimes combined with Dissemination as a single phase, hence the variations).

Current Threat Intel Lifecycle

The lifecycle forms the foundation of most cyber threat intel programs. However, there are challenges with implementing and operationalizing the lifecycle. For example, planning, direction, and requirements are the first phase in a lifecycle that logically flows from one phase to the next, yet organizations struggle with this phase. The 2022 SANS Cyber Threat Intel Survey shows that almost two-thirds of cybersecurity organizations lack defined intel requirements, and looking over the 4 years of data summarized in the report, it’s not improving.

Source: SANS 2022 Cyber Threat Intelligence Survey

We hear the same thing from organizations that struggle in the dissemination and feedback stages. This seems obvious if there are no requirements or ad-hoc requirements with stakeholders. CTI teams can be great at producing the most high-fidelity intelligence, but if there aren’t any customers for the intel, then the value of the CTI program isn’t realized, and unfortunately, its relevance is challenged, particularly in these times of economic uncertainty.

The Evolved Threat Intel Lifecycle expands on the current lifecycle making it more relevant to the needs of cybersecurity teams these days, e.g., it expands the focus on not just the management and production, but the consumption of threat intelligence.

The Evolved Threat Intel Lifecycle

With this background, let’s get to the questions I asked Dan along with his insights.

Why do CTI teams need an evolution of the current threat intel lifecycle? CTI teams need an evolution of the current threat intel lifecycle because the traditional lifecycle does not prioritize feedback and stakeholder involvement sufficiently. The drawbacks of the current lifecycle include:

  • Insufficient focus on feedback and evaluation, hinders continuous improvement and the relevance of the intelligence gathered.
  • Limited stakeholder involvement, can lead to a disconnect between the producers and consumers of intelligence and may result in under-utilization of the intelligence provided.
  • The perception of CTI as a “nice-to-have” rather than an essential component of an organization’s security posture.

So why now?The need for an evolved threat intel lifecycle is more urgent now due to several factors:

  • The rapidly changing threat landscape and the increasing complexity of cyberattacks. Organizations face a myriad of threats from various sources, and staying ahead of these threats requires a more agile and collaborative approach to threat intelligence.
  • The growing importance of collaboration and breaking down silos within security organizations. An evolved threat intel lifecycle fosters better communication between different teams, enabling a more unified and effective response to threats.
  • The growing popularity of the fusion center model, which integrates various security functions and stakeholders to create a comprehensive and coordinated approach to threat management. The evolved threat intel lifecycle is well-aligned with this model, ensuring that threat intelligence is effectively integrated into broader security operations.

By adopting an evolved lifecycle, CTI teams can better address the challenges posed by sophisticated adversaries, help their organizations make more informed decisions to protect their assets and networks and contribute more effectively to the organization’s security posture.

How does the Evolved Threat Intel Lifecycle help CTI teams? What benefits should they expect by adopting this updated lifecycle?The Evolved Threat Intel Lifecycle helps CTI teams by:

  • Enhancing collaboration and communication between intelligence producers and consumers, ensuring that the intelligence gathered is effectively utilized by the relevant stakeholders.
  • Fostering accountability and continuous improvement, with a strong focus on feedback and evaluation, to ensure the quality and relevance of the intelligence produced.
  • Encouraging a more action-oriented approach to threat intelligence, moving beyond mere dissemination to actively informing decisions and driving effective responses to threats.
  • Transforming CTI from a “nice-to-have” to a must-have: an essential part of security. This helps CTI teams demonstrate their value, build trust with their stakeholders, and contribute more effectively to the organization’s security posture.

By adopting this updated lifecycle, CTI teams can expect to see increased efficiency, improved decision-making, and better overall security posture for their organizations.

The Bottom LineEmbracing the Evolved Threat Intel Lifecycle is one of the important steps to achieving a TI Ops capability. It helps CTI teams become an integral part of Security Operations, demonstrating the power, and value, of threat intelligence.

Take the Next StepIf you’d like to learn more about the Evolved Threat Intel Lifecycle, check out Dan’s blog “The Need for an Evolved Threat Intel Lifecycle”. Reach out to one of our experts if you want to learn more about how the ThreatConnect Platform can help you operationalize the Evolved Threat Intel Lifecycle.

The post The 7 Tenets of Threat Intelligence Operations – Tenet #2: Requires an Evolved Threat Intelligence Lifecycle appeared first on ThreatConnect.

View Details

Gartner recently released the latest version of their Market Guide for Security Threat Intelligence Products and Services. We’re honored to be named a Representative Vendor, but equally excited by the insights and advice offered in the Gartner report.

I find the Key Findings and Recommendations to be a great summary of the challenges we hear in the market, and whole heartedly agree with the recommendations. I commend the authors for calling out these specific points that we believe need to be recognized and addressed by organizations, whether they are just starting out on their threat intelligence journey or are in the maturation phases. The failure to produce priority intelligence requirements can have a significant impact on the success of a threat intelligence function and team, keeping them from being the heroes of security operations. Gartner had a number of recommendations and observations:

  • “Although a larger variety of organizations are choosing threat intelligence (TI) services and products to enrich their security programs, many haven’t formalized these programs, resulting in a lack of defined requirements, diminished actionability, and an overall lack of long-term program defensibility.”
  • “The core of any TI program is priority intelligence requirements (PIRs), used to identify where the organization will focus intelligence efforts and what tools are required to achieve it.”
  • “They are overwhelmed with data because they have not defined what they really need to focus on and care about. Security and risk management leaders must demand that PIRs be defined for their organizations before any TI product purchases are made.”
  • “Even today, a key issue is actionability. Security and risk management leaders must understand knowing is not enough, and they must be able to take action. Keeping PIRs in mind will be enormously helpful because you will not lose the end goal and can make sure that you are addressing the PIRs, no matter what you do.”

Another point worth highlighting is the distinction between platforms and services. Threat intelligence products, aka the technology, are not the same as threat intelligence services. I was pleased to see this distinction specifically addressed in Figure 3: Market Overlap Between Threat Intelligence, DRPS, and EASM — Part 1 in the report.

This is critical to understand from a buyer’s perspective because a threat intel platform (TIP) is what allows you to manage and operationalize threat intelligence, and is necessary when there are multiple intel data sources being consumed – commercial or paid intel (aka the services), open source intel (OSINT), intel shared between trusted partners like ISACs, and internally produced intelligence like from a SOC or incident response team. Even Gartner calls out that “There is not a single TI source, whether open-source, commercial off-the-shelf or government-created, in the market today, which has visibility into everything.” We agree! It’s why we believe that a diversity of threat intelligence sources aggregated into a single source of high-fidelity threat intelligence is the only way to identify, prevent, detect, and respond to the adversaries targeting your organization.

Finally, I commend the authors on ending the report by making the linkage between threat intelligence and cyber risk quantification – “Promote cohesion among intelligence services by correlating across your external threat data for better risk quantification and prioritization.” ThreatConnect also has a cyber risk quantification (CRQ) solution – Risk Quantifier – that easily integrates into ThreatConnect’s TIP to bridge the gap between intel and cyber risk.

Want to learn more? Download a complimentary copy of the Gartner Market Guide for Threat Intelligence Products and Services here, and reach out to learn or get a demo of the ThreatConnect TI Ops Platform.

Gartner, Market Guide for Security Threat Intelligence Products and Services, Jonathan Nunez, Ruggero Contu, Mitchell Schneider, 4 May 2023.

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from ThreatConnect.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose

The post Evolution of the Threat Intelligence Products and Services Market – Our Take on The Latest Gartner® Market Guide appeared first on ThreatConnect.

View Details

We asked some of the Senior Leaders at ThreatConnect, whose teams’ spend a lot of time with enterprises, to give their insights on how an organization can prepare for a TI Ops Platform project. We think these insights will give some ‘hacks’ to be successful in selecting, gaining support (e.g., budget and resources), and delivering a Platform for their cyber threat intel teams.

  • Lara Meadows, VP of Solution Engineering
  • Dan Cole, VP of Product
  • Jody Caldwell, VP of Customer Success
  • Toby Bussa, VP of Product Marketing

Lara Meadows – VP of Solution EngineeringPlanning is one of the most important and often overlooked steps in growing a successful TI Ops program. It should be the backbone of every cybersecurity organization because every cybersecurity team member and every security tool is only as relevant as the latest intelligence being provided to them.

For this reason, as part of planning, before even thinking of a Platform, it’s important to understand the following;

  • Do you have established and documented priority intelligence requirements (PIRs)?
  • How often are PIRs reviewed and updated?
  • What type of intelligence is needed (threat actors, IOCs, deep web, dark web, etc.)?
  • Who (and which tools) will be receiving the intelligence?
  • What format does intel need to be in for third-party tools?
  • Will third-party tools automatically provide intel BACK to your TI Ops team for new and unknown threats?
  • What type of reporting is needed for all the various security teams (executive briefings, detailed analyst notes), and who will be the recipients?

Having answers to these questions will build the foundation for an incredible TI Ops program allowing your intelligence to be the lifeblood of your entire security program, and giving you the foundation to construct robust, stakeholder-aligned requirements for a TI Ops Platform.

Dan Cole – VP of ProductTo start, having a defined set of PIRs is critical. A solid TI Ops platform enables teams to address these PIRs more effectively and efficiently, ultimately providing a stronger security posture for the organization. By identifying and prioritizing these requirements, security architects and engineers can better demonstrate the platform’s value and ensure that it meets the specific needs of their organization.

PIRs can also inform technology choices. Teams should have a thorough understanding of the software tools they will be integrating into the TI Ops platform, and how those tools help them address their PIRs. This includes being familiar with their features, capabilities, and limitations. By knowing the tools inside and out, teams can make more informed decisions and better advocate for the value of the platform to their organization. Which intel feeds will they ingest? What analysis tools will they bring to bear? What tools do their stakeholders need the intel disseminated to?

Another essential aspect of preparing for a TI Ops Platform project is securing strong buy-in from stakeholders, such as leadership and the Security Operations Center (SOC). This support can be vital in securing the necessary budget and resources for the project, as well as driving strong adoption. To achieve this, architects and engineers should clearly communicate the benefits of the TI Ops platform and demonstrate how it will help the organization address its unique challenges and goals.

Jody Caldwell – VP of Customer SuccessPlanning any large project always takes time and resources. Having and implementing a plan is crucial to getting the project off the ground and having forward momentum. Being on the customer delivery side of the house, this is something that we work with customers on so they are adequately prepared. This process starts with our initial kickoff call.

Ideally, customers have a thorough set of requirements to address their operational, strategic, and business needs. This enables them to know specifically how they intend to use the platform to meet their desired needs. Planning should always include identifying what feeds, integrations, and processes are going to be a part of the day-to-day operational workflow.

Planning also needs to ensure the right project participants are identified and engaged, e.g., analysts, project managers, and leaders. The most successful teams always have a game plan, and that includes identifying a point person for the project. This doesn’t always have to be a project manner but someone that can help align internal tasks and priorities. This could include working with network and application engineers, developers, and end users. When all of these things are documented, and prioritized it enables a TI Ops team to get the quickest value from the platform.

Toby Bussa – VP of Product Marketing I heard it in the numerous conversations I had as a Gartner Analyst, whether it was about SIEM, SOAR, TIP, etc. Spending time in the preparation phase is absolutely critical to successfully delivering a new solution. So what would be my top recommendation?

Know the most critical pain points you’re solving for, and make sure you have metrics. When I spoke with someone who didn’t know these, and if there were no measures, or they were qualitative, not quantitative, my advice was “start measuring.” Perfection isn’t critical, but having quantifiable data allows you to know what your starting point is, and to have a conversation with stakeholders on where they want to be (i.e., we want to see an improvement of X% in 6 months). If you’re looking to improve the time it takes to disseminate indicators to your downstream security tools, then you need to know how long the process takes. Spend 30 days getting sufficient data points, then use these metrics to set evaluation and implementation success criteria, and keep measuring while you progress the project. By the time you’re doing an evaluation of Platforms, you’ll probably have 60-90 days of quantitative measures. The happiest customers I see are the ones that can say, “We started here at X, we demonstrated that the solution will help us achieve at least Y, and 90 days after being implemented, we actually delivered Z, besting our goal by this percentage.”

The Bottom LineBe Prepared! It’s simple to say, but being prepared before even speaking with vendors is critical. You need to have a robust project plan that documents the following:

  • Requirements aligned with stakeholders,
  • Clear and agreed goals for the Platform,
  • Relevant metrics that measure the current state, and
  • How you are going to demonstrate success for evaluation and post-implementation of the Platform.

With these items in hand, before you start your vendor evaluation and selection process, you’ll be well prepared to defend the purchase of a TI Ops Platform, get your budget, and make the TI Ops team very, very happy.

Take the Next StepTo learn more about preparing for a TI Ops Platform project, reach out to one of our experts to discuss your TI Ops Platform initiatives or to get a demo of the ThreatConnect Platform.

The post How To Prepare For A Threat Intel Ops Platform Project appeared first on ThreatConnect.

View Details

Over a decade ago, Forrester Research introduced the concept of zero trust. Today, zero trust is considered one of the leading frameworks to guide information and security architects in the design of robust and resilient information security architectures. This is a very important aspect of zero trust – it’s a framework that influences security architectures and not a singular technology that you buy.

Zero trust starts out with some very different principles to help you architect your defenses. The legacy concept of a trusted internal network zone, and an untrusted external network zone, are no longer adequate. Zero trust essentially posits that no data traffic or user can be trusted just because of their position within the network. It is now assumed that at any time, any portion of the network can and will be compromised. Users, therefore, must go through re-authentication and validation at every step of the experience.

Zero trust architectures have shown to bring compelling value. They are a best practice way for government and private enterprises to add the layers of necessary security to manage and protect sensitive information while rapidly taking advantage of and supporting digital transformation initiatives and the value that those bring.

There are a few key best practices that guide users in building out their own zero trust architectures.

  • To begin, data is the core element that must be continually protected. Any access to this data will require authentication and revalidation.
  • Understanding the flow of data is critical to designing the micro-networks in which that data moves. Access to these micro-networks is to be similarly protected.
  • Finally, in order to build a robust and scalable zero trust architecture, you must have deep visibility of activity, be able to monitor and log this activity, and then analyze this data to understand if malicious activity is ongoing.

In order to get the speed of execution and scale, the technologies implemented for a zero trust approach must be able to integrate and be orchestrated.

The Role of Threat Intelligence in a Zero Trust ArchitectureZero trust implementations require context. Why? NIST800-207 explains it well. Access to each enterprise resource, like applications and data, is granted on a per-session basis. Access to resources is determined by A dynamic policy. The enterprise monitors the state of the security posture of all assets. Resource authentication and approval are dynamic and strictly enforced prior to allowing access.

Threat intelligence provides critical context to address these tenets of zero trust. In NIST 800-207, Figure 2: Core Zero Trust Logical Components specifically addresses threat intelligence as a logical input into a zero trust control plane. NIST800-207 states, “The [Policy Engine] PE uses enterprise policy as well as input from external sources (e.g., CDM systems, threat intelligence services described below) as input to a trust algorithm … to grant, deny, or revoke access to the resource.”

Without a single source of high-fidelity threat intel, there can be potential challenges in integrating threat intel into your zero trust control plane.

  1. Intel sources – If you have multiple threat intel data sources and feeds, you have to make sure the data is optimized to be ingested by your policy engine. Will all your intel sources integrate with your policy engine? How well will a policy engine handle duplicative intel? Will that create a resource constraint on that engine?
  2. Connectivity overhead – You may have a lot of overhead making sure multiple integrations stay working and up-to-date in the event of any events, e.g. changes to APIs.
  3. Intel reliability – Relying on intel that hasn’t been refined can lead to false positives without ensuring it is of sufficient quality. Without this assurance, end users may have a negative experience if they are unable to access critical resources in a timely manner due to low-fidelity threat intel.

So how do you avoid these potential challenges? Here’s how the ThreatConnect Platform helps you avoid these challenges and provides high-quality and reliable context in a zero trust architecture.

  • Threat Library – Your organization’s single source of threat intelligence. The Threat Library leverages an industry-leading data model to normalize, optimize, and make available any type of intel data and knowledge.
  • CAL Global Intelligence – using AI and ML-powered insights into threats and indicators and the industry’s largest ground-truth threat telemetry from the global ThreatConnect user community. CAL’s Automated Threat Library, CAL Feeds, ThreatAssess intel scoring, and Feed Cards ensure highly relevant, accurate, and reliable intel is supporting your zero trust technologies.
  • Easy Connectivity – Out-of-the-box integrations via Apps, and a flexible API for any custom integrations.
  • Flexible automation, from no-code to custom code, makes your daily management and operationalization of threat intelligence easier and faster.

Just having a single source of threat intelligence is not enough to achieve a successful zero-trust architecture. Having robust, performant, and reliable intelligence feeding the decision-making elements in your zero trust architecture is vital to ensure that the security tools are protecting and defending your organization, not impeding and causing unnecessary disruptions.

Learn MoreWant to learn how ThreatConnect fills a critical need in your zero trust architecture? Reach out today to speak to one of our experts to learn more or to request a demo of the ThreatConnect Platform.

The post Zero Trust Steps Up To Shut Down Threat Actors appeared first on ThreatConnect.

View Details

ThreatConnect’s 7.1 release delivers an even better ThreatConnect user experience. ThreatConnect 7.1 strengthens capabilities introduced in 7.0, including Enrichment and Reporting, providing more flexibility and customization while also refining the Platform for a more streamlined user experience so security teams can be more efficient and effective.

Built-in Enrichment v2When investigating an indicator, knowledge is power. The more analysts know about an indicator, the faster they can assess its relevance and severity to the organization. In ThreatConnect 7.0, we introduced our first iteration of built-in Enrichment with VirusTotal, enabling teams to understand the maliciousness of an indicator and links and dependencies between indicators. In this latest release, we added built-in Enrichment with Shodan and expanded on our VirusTotal capabilities for even more efficient and effective investigations,

Built-in Enrichment with ShodanEnrichment with Shodan adds context to IP addresses. The In-Platform Shodan Detail View includes details on Ports, Protocols, and Associated Certificates, as well as whether a vulnerability is verified or unverified. Details on Ports, Protocols, and Associated Certificates help identify potential risks in the form of misconfigurations, expired certificates, and weak cryptographic algorithms. Vulnerabilities verified by Shodan are easily prioritized by analysts, while unverified vulnerabilities need further investigation from them.

Analysts can scrutinize the contextual information from Shodan in the Detail View on the Platform and compare it to the enrichment data from VirusTotal on the same page to identify patterns. They can also view the data in Threat Graph, our visualization tool, to explore, pivot, and gain insight into connections between Indicators for both Shodan and VirusTotal Enrichment data.

Explore Enrichment with Shodan in our interactive demo

VirusTotal Enrichment ImprovementsIn ThreatConnect 7.1, we include more improvements to Enrichment with VirusTotal. We added VirusTotal enrichment data to Workflow Cases to the Artifacts section so security operations teams have all of the information they need in one place. We also added automatic Enrichment with VirusTotal via our v3 API and the ability to import VirusTotal relationship data to new or existing Groups for a deeper understanding of relationships between Indicators.

Native Reporting v2The ability to quickly and easily disseminate information and enable leadership is key to a successful threat intelligence operations program, but it’s not about getting just any information in front of stakeholders. It’s about getting the right information in front of the right stakeholders at the right time. In our second iteration of Reporting, we provide even more flexibility for building reports so teams can be precise and effective with the information they share.

In ThreatConnect 7.0, users could build Reports from Groups. Now, users can also create Reports directly from Workflow Cases with the flexibility to create more customized reports that include data from multiple Groups and Cases. Multi Group and Case support enables users to create reports around topics like Threat Groups they observed in a week or cases they are working on to streamline their investigations and organize their data more efficiently.

For even more flexibility, users can create a generic report, regardless of whether the data is associated with a Group or Case. Using text blocks, users can easily and quickly add relevant information to a Report without creating a Case or Group first. Generic reporting gives users more control over the information they include in a report and speeds up dissemination.

User Experience Improvements To deliver a more streamlined user experience on the ThreatConnect Platform, we are continuously elevating the right information so analysts can make fast and confident decisions. In ThreatConnect 7.1, users get more context with Pinned Association Attributes on the Overview page and CAL Impact Factors to understand the factors and their impact on a CAL score, a reputation score for the criticality of an Indicator. Additionally, users can automatically associate Indicators and Groups to a Group with ThreatConnect Query Language (TQL).

Automated Associations with TQLAutomated Associations with TQL, ThreatConnect’s proprietary query language, allows users to assign a TQL query to a Group. That query then automatically searches ThreatConnect for Groups or Indicators matching the TQL query and associates those items directly to the assigned Group, making the process of building a threat profile much faster and more streamlined. Each query is scheduled to run nightly but can be run on-demand to provide the most up-to-date information.

Automated Associations bring together all of the information an analyst has about a topic so they can build out their Threat Library and Threat Actor Profiles without having to dig around the Platform. This feature can also be used to track Intrusion Sets, MITRE techniques, and Vulnerabilities without the need to build Dashboards.

Threat Graph Enhancements Threat Graph is ThreatConnect’s visualization tool used by analysts to view, pivot, and explore relationships in their datasets. In ThreatConnect 7.1, users can run Playbooks directly in Threat Graph so they can efficiently investigate and act on Indicators in one place. Users can even run a Playbook on multiple Indicators for maximum efficiency.

Explore Playbooks in Threat Graph with our interactive demo

Additional Features and Fixes* Explore and Pivot on Tags in Threat Graph * Added ‘default source’ attribute to the Detail page * Ability to save a source with an attribute when editing

For more information on these new capabilities and how ThreatConnect can help your organization operationalize threat intelligence, please reach out to sales@threatconnect.com or request a demo.

The post ThreatConnect 7.1: An Even Better User Experience appeared first on ThreatConnect.

View Details

In partnership with one of the most well-respected independent auditors, Schellman & Company, ThreatConnect has achieved SOC 2 Type 2 compliance with our Dedicated Cloud and Risk Quantifier products for the second year in a row. Over the last few years, ThreatConnect has demonstrated our commitment to protecting our customer’s data by aligning our security program to the American Institute of Certified Public Accountants (AICPA) rigorous Trust Services Criteria framework. This successful compliance outcome required months of inter-departmental cooperation and virtual coordination.

As a leading threat intelligence operations and risk quantification SaaS provider, ThreatConnect’s SOC 2 Type 2 report gives our customers a greater understanding of our security controls. The unqualified opinion from the auditors means that ThreatConnect architected and enforced controls effectively for the entire twelve-month audit period.

What Is A SOC 2 Type 2 Report?Successful completion of a SOC 2 Type 2 audit proves that an organization not only has the necessary controls in place but that an independent auditor has confirmed that those controls operated effectively over the audit period. This is more rigorous than a SOC 2 Type 1 report, which only measures control effectiveness for a point in time.

All companies are required to have their security controls tested for a SOC 2 Type 2 audit. The security controls cover access control, unauthorized disclosure, and other controls that would affect an organization’s ability to achieve availability, confidentiality, and integrity objectives. ThreatConnect completed an additional two tests to certify our availability and confidentiality controls. These additional tests are optional but a great way to show our comprehensive security posture.

What Does This Mean For Our Future and Current Customers?With the proliferation of cybersecurity incidents and data breaches, more companies are requiring their third-party partners to have a SOC 2 Type 2 report. By investing time and resources into a SOC 2 audit, ThreatConnect is renewing our commitment to exceeding industry best practices. Our customers and partners, current and future, can be confident that we take our security seriously. ThreatConnect continues to strive to exceed standards by remaining SOC 2 Type 2 qualified and ISO 27001 certified.

About the Authors:
Kevin Chalkley, Senior Information Security Compliance Analyst at ThreatConnect, has worked in information security for marketing agencies, health insurance companies, and healthcare providers before coming to ThreatConnect. Kevin enjoys finding ways to make the information security compliance process easier and more streamlined for all stakeholders.

Kevin Johnson, Manager of Information Security & Compliance at ThreatConnect, has spent the last 10+ years dedicated to solving complex security problems from log analysis to compliance enforcement. Kevin has worked with very small companies to large Fortune 25 companies.

The post ThreatConnect, Inc Achieves SOC 2 Type 2 Compliance appeared first on ThreatConnect.

View Details

In the first blog of this series, I took a 30,000-foot view of the 7 Tenets of TI Ops defined in the Dawn of Threat Intelligence Operations paper. In this edition, I’m going to dig into Tenet #1 – Elevates threat intelligence to a mandatory, critical security operations role – in more detail.

In the various roles I’ve had over the years, I have observed CTI teams primarily being a function within the SOC. This makes sense as threat intel is a crucial element of threat monitoring, detection, and incident response, but it also limits the value that threat intel can provide across cybersecurity operations and cyber risk management. By elevating TI Ops to a peer-level role within security operations, threat intel becomes the core of how to transform SecOps into what we call Intelligence-Powered Security Operations.

Why is this elevation important? A failure of every team in an organization operating from and contributing to a common body of threat intelligence gives adversaries the advantage. An Intelligence-Powered Security Operations approach takes this advantage away by:

  1. Enhancing Prevention and Detection capabilities – Correlate data from your security tools with threat intelligence for more accurate alerting, blocking, and threat response
  2. Improving Response Time –The more knowledge you have about a particular threat, the faster you can respond to it
  3. Inform Security Policy and Controls – Ensure that your organization has the appropriate and optimized defenses in place for adversaries relevant to your organization

The formation of the concept of fusion centers after the 9/11 attacks in the U.S. is an apt reference point, especially as it established the foundations of cyber fusion centers and operations. There is a lot written already about intelligence sharing failures as one of the root causes for why terrorists were able to carry out successful attacks (see the 9/11 Commission Final Report ). The outcomes from the analyses highlighted how intelligence existed, but it was collected and leveraged in siloes, not widely shared with applicable stakeholders, and could not be operationalized. This sounds very much like how cyber threat intelligence exists for many organizations these days.

The recommendations to form fusion centers gave direction to state and federal government agencies to elevate their intelligence collection and sharing capabilities. I love the call to action for leadership from the Fusion Center Guidelines Developing and Sharing Information and Intelligence in a New Era, which is equally applicable to cybersecurity.

“In developing our country’s response to the threat of terrorism, law enforcement, public safety, and private sector leaders have recognized the need to improve the sharing of information and intelligence across agency borders. Every official involved in information and intelligence sharing has a stake in this initiative. Leaders must move forward with a new paradigm on the exchange of information and intelligence, one that includes the integration of law enforcement, public safety, and the private sector.”

However, it was not something that occurred overnight. It took years to see progress, and this is another important point in the journey to elevate threat intelligence – it’s a marathon, not a sprint, and more like a 100 miler in reality since technology, threats, and adversaries will all change and evolve, and therefore you won’t be able to just stop after 26.2 miles). Some of this progress is evident in the improvements within the cybersecurity community of sharing intelligence between organizations, such as ISACs and ISAOs. There are 27 ISACs that are part of the National Council of ISACs across a broad spectrum of industries.

Making some organization reporting changes can be seen as the “easy” path – elevate the CTI team to being a direct report of the CISO, and the problem is solved, right? Not at all. Building and sustaining a high-performant, value-delivering function requires more than changing an org chart. It requires:

  • Getting leadership buy-in on a target operating model for the TI Ops function and securing a commitment to the required funding for multiple years (one year is not enough!)
  • Identifying and engaging the right stakeholders to understand, document, agree, and prioritize their requirements and get sustained support.
  • Hiring, developing, and maintaining TI Ops talent is a challenge. It’s estimated that millions of cybersecurity jobs are unfilled. Experience with cyber threat intelligence is a very specific class of talent that can be hard to find, and if you can find it, affording that talent might not be feasible. It’s possible to develop that talent, but that takes time too.

So by now, you’re probably thinking, “Too hard, too much work, etc. There is no way I’m getting a TI Ops function, and it’s going to be that important to my organization.” Don’t despair! I’ve seen both large, global, and very well-funded enterprises implement a TI Ops capability, but I’ve also seen midsize enterprises embrace the power of having threat intelligence be a core capability for their security and risk management operations. Sure, they didn’t have dozens of CTI or TI Ops analysts, but they didn’t need that. They did great with a couple of analysts. They invested in TI Ops because they recognized the payback to the overall security function was significant and the effort worthwhile.

The Bottom LineTI Ops must be the future of CTI teams and functions in order to remain relevant to an organization’s cyber security and risk management program. By adopting the 7 Tenets of TI Ops, CISOs and SecOps leaders are going to gain an advantage over the adversaries, and any upper hand they get to make their organizations more defensible and resilient to attacks is a win.

Take the Next StepWhile waiting for the next part of this series, read the Dawn of TI Ops paper, and be sure to subscribe to get notified of the latest blogs from ThreatConnect.

The post The 7 Tenets of Threat Intel Operations – Tenet #1: Elevating Threat Intelligence appeared first on ThreatConnect.

View Details

If you have been a FAIR practitioner for years, like me, or maybe you are just starting out, you may have noticed (or will notice) that FAIR is great for understanding your financial risk exposure, however, it has its challenges. I’m not here to highlight everything, but the good does FAR outweigh the bad. No method for quantifying risk is perfect, and all have their own unique challenges. In this blog, I will highlight two of the largest challenges and how to address them.

ControlsFAIR highlights 4 main categories of controls, Avoidance, Deterrence, Resistive, and Responsive controls. However, the challenge is where do you apply them? Sure, training may provide a general mapping (Avoidance = Contact Frequency, Deterrence = Probability of Action, Resistive = Resistive Strength, Responsive = Loss Magnitude), but how a scenario is scoped and how a control is implemented is also extremely important as to where to apply them. This makes determining the Threat Event Frequency (TEF) and Vulnerability (VULN) difficult.

Let’s take DLP, for example. In general, one may think that a DLP control may only affect Secondary Loss Event Frequency (SLEF), but what happens if that control is implemented with Block All? This could actually affect the VULN calculation, as one could assume it would prevent an actor from being successful. Then on top of that, how do you account for all of your controls across your environment, as a lot of them come into play for the scenarios you are measuring? There are a lot of assumptions that still need to be made.

Don’t get me wrong, assumptions are not a bad thing, however, it still doesn’t make the application of controls any easier. The new FAIR-CAM (FAIR Controls Analytics Model) might help with that, but it looks complicated. I have only seen demonstrations of how it would work, but it still leaves me with a lot of questions.

The ideal state would be a solution that would automatically apply my controls for me.

RecommendationsOnce you have identified and measured the scenarios of concern, how do you know what to do about them? Sure, you can perform “What-if” scenarios to determine if you made an improvement to a particular control and how it would reduce your risk, but how do you apply that in a holistic manner across your organization? This is cumbersome because it usually takes interviews with multiple Subject Matter Experts (or maybe only one if you get lucky and identify the right person) to determine the true effect of a control on your environment. After those conversations, you are still left with an assumption based on that SMEs experience. I have used this approach many dozens of times over the years, and it can work, but is it really defensible? Only if there was a way to automatically recommend improvements that remove some of the subjectivity from the equation

A Different Approach I’m pleased to be working at ThreatConnect, a company that has taken a different approach to risk quantification which addresses these challenges and more. ThreatConnect Risk Quantifier has the capability of automatically applying controls holistically across your organization. ThreatConnect RQ’s Semi-Automated FAIR analyzes your attack surface area all the way down at the MITRE ATT&CK level so you can truly see the impact of your controls on your scenarios.

It also automatically recommends what controls should be improved to help mitigate the risk exposure. This allows you to spend time on having better conversations versus spending extra time on adjusting analyses.

Sound like something you’d want to try out and see in action? Check out our Free 14-day trial of the ThreatConnect Risk Quantifier for FAIR!

The post Balancing the Benefits and Challenges of FAIR – A Practitioner’s View appeared first on ThreatConnect.

View Details

Many organizations struggle to demonstrate value for threat intel and their threat intelligence teams. The intel team is trying to do the right thing though. They are collecting threat intelligence, managing it into usable shape, making it available for use, and then struggling to find consumers who need, or want, to use it.

Security operations is a well-used and accepted term. It’s an action-oriented term. Security teams have people, processes, and tools that support activities like vulnerability management, and threat detection and response. Threat intelligence teams are called the cyber threat intel or “the CTI team”. There is zero implication that there is any operational aspect, or action, to the function. We know that’s not the truth. This may appear simplistic, but I believe it’s a foundational issue with threat intel – how’s it perceived by leaders and peers in cybersecurity operations and cyber risk management?

This is the reason why I believe the perceptions of cyber threat intel have to change. But that change requires assessing the what, how, and why of threat intelligence. A new approach is needed. This is the reason why CTI teams need to evolve into Threat Intel Operations, or TI Ops as we call it. And it’s definitely more than just a name change.

In the Dawn of Threat Intelligence Operations paper, seven tenets of TI Ops are defined. This blog is the first in a series where I’m going to dive deep into these and the reason why their adoption will help transform CTI teams into TI Ops. Here I’ll touch on the tenets at a high level, with more blogs focusing on specific tenets coming in the near future.

The Seven Tenets of TI Ops1. Elevates threat intelligence to a mandatory, critical security operations role.

I observe many CTI teams being relegated to a function within the SOC. This makes sense as threat intel is a crucial element of threat monitoring, detection, and incident response, but it also limits the value that threat intel can provide across cybersecurity operations and cyber risk management. By elevating TI Ops to a top-level role within security operations, threat intel can become the core of how to transform SecOps into what we call Intelligence-Powered Security Operations.

A Sample CyberSecurity Operations Org Chart

  1. Requires an Evolved Threat Intelligence Lifecycle, one that emphasizes the planning and requirements and the use of threat intel by the consumers.

I’m a fan of processes in tradecraft, and the CTI lifecycle has done an admirable job of aligning CTI teams around a common process, but it’s showing its age. It really focuses on the production of CTI, not the consumer or customer of intel, and the importance of the feedback to make it a virtuous cycle. This is why we believe an Evolved Threat Intel Lifecycle is required for TI OPs.

The Evolved Threat Intel Lifecycle

  1. Threat intel is aligned and focused on the most critical risks to the business through a living set of requirements.

The Evolved Threat Intel Lifecycle’s emphasis on the threat intel consumers reinforces the importance of defined intel requirements (e.g. PIRs), which according to SANS’ 2022 Cyber Threat Intelligence Survey don’t exist in almost ⅔ of the organizations they surveyed. Like other functions that rely on technology to enable the people and processes, the lack of defined requirements makes it difficult to determine if the function is operating efficiently, meeting customer requirements, and technologies employed are fit-for-purpose. If threat intel requirements don’t exist or are not aligned to the organizational risks, there is a high likelihood the CTI function will ultimately fail. Cybersecurity teams can’t afford these failures.

  1. Focus is not solely on indicators of compromise, but expands to cover the motivations, tactics, techniques, trends, tools, and infrastructure patterns of threat actors.

The days of threat intel focused only on indicators of compromise are numbered, but many CTI teams are still stuck here because it serves a valuable use case – threat detection and prevention – but it’s just one of the many areas a CTI team can inject value into. I’ve heard from many leading-edge companies that are expanding the focus of their CTI teams into monitoring the motives, methods and tradecraft, and infrastructure used by adversaries. The adoption and use of MITRE ATT&CK within threat intel reflects this interest. TI Ops goes beyond just managing intel and focusing on IOCs and expands to include all the other valuable intel that provides context to consumers, enabling not just the operational use of intel, but informing and influencing cybersecurity and risk management strategies.

  1. Automates the work of the TI Ops team.

Automation is critical. It’s becoming ubiquitous and accepted within the technology across our daily lives, and CTI is no different. Automation is one of the critical advantages that helps CTI teams pivot to being operationally focused, and it needs to be applied to as many stages of the Evolved Threat Intel Lifecycle as feasible. Leveraging automation allows the CTI team to address the big data challenges they are facing these days, e.g., the volume, variety, and velocity of intel, and to scale operations by being more efficient and effective.

  1. Integrates and automates threat intel into every aspect of security and cyber risk management.

Security operations teams are still too siloed in many organizations. The SOC does its thing by detecting and responding to threats. The vulnerability management team is trying to reduce exposures to the organization’s attack surface. The identity and access management and governance teams are trying to keep identities and accounts current with the right level of security. The infrastructure security team is trying to keep the adversaries out while enabling employees and partners to get their work done with as little friction as possible. Cyber risk management is trying to identify and quantify the greatest risks to the organization. And finally, Leadership is responsible for the strategic direction of the cybersecurity and cyber risk management functions. What is a common thread across all of them? Threat intelligence. They are all important customers of threat intel, whether it be strategic, operational, or tactical intel.

  1. Creates measures of effectiveness and success for produced and consumed threat intel that are understandable and relevant to the business.

CTI functions struggle to demonstrate their value, and that falls back on the lack of agreed and documented requirements, and being able to measure the team’s performance against those requirements and demonstrate how the intel they produced led to wins. Evolving into a TI Ops function requires putting in place measures, and then using those measures to communicate with stakeholders, both the good and the bad. This allows TI Ops team to implement a virtuous improvement cycle, and more importantly to demonstrate the value, like ROA, of the TI Ops team and insulating it against the perennial question from leadership – “what value is the CTI function providing for the money I’m spending on it, and should I expand or reduce that budget”?

The Bottom LineTI Ops must be the future of CTI teams and functions in order to remain relevant to an organization’s cyber security and risk management program. By adopting the 7 tenets of TI Ops, CISOs and SecOps leaders are going to gain an advantage over the adversaries, and any upper hand they get to make their organizations more defensible and resilient to attacks is a win.

To learn moreWhile waiting for the next part of this series, subscribe to be notified of new blogs from ThreatConnect and read the Dawn of TI Ops paper.

The post The Tenets of Threat Intel Operations appeared first on ThreatConnect.

View Details

Blog authored by Dave DeWalt, Founder and Managing Director, NightDragon. Read it on the Night Dragon’s website here

We live in a true golden age of data and information. Organizations have more threat intelligence, whether it be cyber, physical, etc, at their fingertips than ever before, from vulnerabilities to adversary profiles and more. Inside these stores of intelligence lies the opportunity for stronger, more resilient, and more responsive cyber and physical security. It’s truly a big data opportunity.

However, as with every many opportunities, it also creates new challenges. Of those millions of intel data points and alerts funneled into the organization from a variety of sources, which are the ones that matter to you? How do specific threats impact the risk profile of your business? How do you translate knowledge of a threat or threats and turn that into operational defense and protection? In short, what do you DO with all that threat intelligence, and how do you operationalize it? This is a challenge facing every CISO, security leader, and risk manager I talk to today.

Over the last few years, it has become more and more evident that we need to unite our threat and risk intelligence across all domains, such as Cyber, Physical, Supply Chain, Industrial, BlockChain, and more. Allowing seams in our security and safety operations can cause longer response times, less efficacy, and significantly more cost and risk.

We have seen the impacts of this breach after breach, incident after incident. Ransomware, for example, can cause physical damage as well as digital and cyber damage. Physical threats such as floods, storms, accidents, and even outright war can cause risk and damage to digital systems. The attack on Colonial Pipeline is a perfect example of this, with a digital ransomware attack causing physical impacts to fuel supply chains.

Today, security teams primarily rely on cyber threat intel sources Mandiant, Crowdstrike, Recorded Future, and others, while other teams like OT security and physical security rely on other threat intel sources to make decisions and prioritize risk. NightDragon sees a world where a single platform can serve as a connective tissue to all intelligence gathered from the world’s best researchers and threat intelligence sources, whether it be cybersecurity, physical security, related to critical infrastructure, or supply chains. The time to fuse our Intelligence is NOW. The time to measure each indicator with quantifiable risk is NOW. The time to build integrated playbooks and workflows across all threat domains in NOW.

A Unified Threat Intelligence Operations Platform not only helps aggregate the increasing volume and variety of intel data but also confidently prioritize, manage, and respond to threats using automation and quantitative risk insights.

This is why I am excited to announce that NightDragon has partnered with ThreatConnect, maker of leading threat intelligence operations (TI Ops) and risk quantification solutions. ThreatConnect’s platform centralizes the aggregation and management of all the threat data relevant to CISOs and security operations teams, then turns that threat intelligence into actionable insights, captures and applies analyst knowledge for additional context, and layers a risk quantifier to measure cyber risk in monetary terms. It then allows teams to orchestrate and automate processes to respond faster and more confidently than ever before.

CEO Balaji Yelamanchili and I share this vision for a single platform to serve as a connective tissue between all the various threat intelligence feeds that CISOs leverage today. I have known Balaji for 25+ years since I was CEO of Documentum. While we may have served on what some might call opposite sides of the table in the years since – him on Team Yellow at Symantec and me on Team Red as CEO of McAfee – I am thrilled to now reunite with him to make this vision a reality.

NightDragon will partner with ThreatConnect to help launch the company into its next phase of growth and accelerate this shared vision of a connected view of threat intelligence. We will put the power of our NightScale platform to work with ThreatConnect, providing the team with the people, partnerships, playbooks, and programs needed to grow and scale. As part of this partnership, I will also be joining the Board of Directors of ThreatConnect as Non-Executive Chairman.

Given its platform and market traction, ThreatConnect is well-positioned to be the threat intelligence platform that serves as this connective tissue. The team’s platform accomplishes much of this today, and the organization has already seen incredible momentum, including more than 200 enterprises and thousands of security operations professionals who already rely on ThreatConnect every day to protect their most critical systems. I believe this can and will be done. It needs to be done. Connect the Threat with ThreatConnect.

We look forward to working with the entire ThreatConnect team to bring our shared vision into reality. Together, we will change how CISOs and security leaders are able to tap into the power of threat intelligence from every source and, as a result, better protect their organizations for many years to come.

About the AuthorDave DeWalt is Founder and Managing Director of NightDragon, a late-stage and growth venture capital firm focused on the cybersecurity, safety, security, and privacy market. He is a veteran CEO, advisor, and investor who has led companies, from startups to the Fortune 500, on a transformational journey of success. Focused on technology and cybersecurity, Dave helped create more than $20 billion of shareholder value during his 15-plus years as President and CEO of three major companies. That includes driving the largest cybersecurity IPO to date as of 2013, and leading the largest all-cash deal in technology history as of 2010. Today, he serves as Managing Director of Allegis Cyber as well as investor and board member in the world’s most innovative companies such as Delta Airlines, Five9, Forescout, Phantom Cyber, Claroty, Team8, DataTribe, Illusive Networks, and Optiv.

The post Uniting the Threat and Risk Intelligence Across ALL Domains appeared first on ThreatConnect.

View Details

If you’ve seen our blog, “Luke in the Sky with Diamonds,” or have read Adam Shostack’s excellent book: “Threats: What Every Engineer Should Learn From Star Wars,” you know that Star Wars is really just a series of cybersecurity parables. In this blog, we’re going to examine how the lead-up to the Battle of Hoth in The Empire Strikes Back illustrates some of the shortcomings of the traditional Threat Intelligence Cycle, as well as how the Galactic Empire was able to overcome those shortcomings by leveraging an Evolved Threat Intelligence Cycle.

The Battle of Hoth itself is a textbook example of the value of threat intel, which we can define as “knowledge of an adversary that can be used to inform action.” In this case, the knowledge was the location of the Rebel’s hidden base, and the ultimate action was an overwhelming Imperial victory against the Rebellion.

The Traditional Intelligence CycleLet’s look at how the Intel Cycle was put to use here. As a refresher, the Intel Cycle consists of five phases:

  1. Planning and Direction
  2. Collection
  3. Processing
  4. Analysis and Production
  5. Dissemination and Integration

“Feedback and Evaluation” is thrown in as a meta-phase intended to ensure continuous improvement throughout the cycle.

Planning and DirectionI wish Darth Vader were my CISO!

In the opening of the film, Darth Vader is painted as an effective manager. He sets clear, specific objectives for the team’s intelligence activity: find the Rebel base and Luke Skywalker. This is a well-aligned Priority Intelligence Requirement because it specifically addresses threats that are highly relevant to the security of the Empire. So far, so good!

CollectionAn Imperial Probe Droid.

Following Planning and Direction, the Imperial Navy leaps to action and sends thousands of probe droids into the far reaches of space. This is a very broad but necessary Collection effort.

Processing[John Williams intensifies]

Even though Han and Chewbacca managed to trigger the probe droid’s self-destruct while conducting a bit of intrusion analysis, the droid still managed to radio its findings back to the fleet, where the data was decrypted and Processed for final analysis.

AnalysisA fragment of intelligence from a probe droid in the Hoth system.

Upon examining the probe droid’s data, Imperial agents were able to identify human life readings.

DisseminationJust another SOC meeting.

This is where things start to go off the rails. Captain Piett, a threat intel analyst, attempts to convey his findings to Admiral Ozzel, who’s focused on operations. The Admiral is concerned about false positives: “If we followed up every lead [it would waste resources]!” He has no desire to take action on the disseminated intelligence.

That Is Why You FailSo we have a plan, data is collected, processed, and analyzed, disseminated, and Captain Piett even gets some feedback (“I want proof, not leads!”). We have a fully complete and closed intelligence cycle. If the Empire didn’t find a better way to operationalize their intel, the movie would be over: Captain Piett would go back to searching, the Rebels would have had time for a complete evacuation, and Luke Skywalker would have eluded Vader’s grasp.

Of course, that’s not what happens. Let’s take a look at the shortcomings of the traditional cycle, and how the Empire took a move evolved approach.

Limitations of the Intel CycleThere are a few key limitations with the intel cycle, but fundamentally they boil down to the same point: the cycle is treated as a fully closed loop. Intel is disseminated… but then what? Does it sit, ignored, in a SOC analyst’s inbox? Does it blow up a SIEM with false positives? Does it miss a true positive due to a flawed detection signature? Does a power-tripping admiral reject it due to a culture of silos and backstabbing?

Lack of AccountabilityWhile the intel cycle does have a “feedback” step, it’s not strictly enforced and very often is not properly quantified. Teams can end up in echo chambers, and as with the case of Admiral Ozzel often the feedback is based on a lack of trust or confidence in the very intelligence that’s supposed to be informing action!

The end result is that threat intelligence can often be seen as a nice-to-have rather than an absolute essential element of a security organization. As we’ll see, we know that the Empire does consider it essential, and it ultimately leads to their victory during the Battle of Hoth.

Lack of Stakeholder InvolvementIntelligence doesn’t exist for its own sake, so it’s curious that the stakeholders it’s supposed to benefit aren’t even called out in the cycle! There’s a strong risk that Dissemination is treated as a “toss it over the fence” kind of step. If Darth Vader is the one setting the PIRs for his team, why is he not looped in when relevant intelligence is uncovered?

The Evolved Intelligence CycleA delicious intelligence pizza.

The Evolved Intelligence Cycle solves these issues in a few key ways:

  1. It explicitly calls out the personas involved in threat intelligence: Producers (CTI analysts, researchers, Captain Piett, etc.), and Consumers (SOC/IR, threat hunters, leadership/CISOs, red and blue teams, Admiral Ozzel, Darth Vader, etc.).
  2. It takes into account the action part of threat intel (Dissemination is not action!), such as detection and enabling leadership to make strategic decisions.
  3. Dissemination and Feedback are “bridge” steps between the two personas, which turns threat intelligence into a truly collaborative discipline across the entire security organization.

Consumers must have agency and a voice in the intel cycle, and Producers need to be held accountable for the quality of the intel they produce. “Feedback” here means looking at data like detection efficacy (e.g. false positives vs true positives), actions taken, and whether decisions were informed. If you’d like to learn more about how to measure the overall impact of threat intelligence, definitely check out this talk from our own Marika Chauvin: How to Get Promoted: Developing Metrics to Show How Threat Intel Works.

The Empire: EvolvedLuckily for the Empire (but unluckily for the Rebellion!), Darth Vader understands the importance of accountability and stakeholder involvement.

General Veers must have ice in his veins to stand so close!

Since Vader’s the primary stakeholder of the “Find the Rebel Base” Priority Intelligence Requirement, he inserts himself as an Intelligence Consumer into the conversation.

Consumption in FocusNow this is what I call taking action based on knowledge of an adversary!

| Enable Leadership | | Leaders and Sith lords have the big picture and need the right intel to make effective decisions.* Vader immediately recognizes the intel as the Rebel’s base thanks to his connection with the Force. * He smashes through silos and shuts down Admiral Ozzel’s power play. * He brings together leaders from other departments to take action.

Prevention, Detection, and Response* The real meat of the action. * The fleet is deployed to Hoth for the attack. * General Veers prepares his troops for a ground assault. |

Continuing the LoopThere are plenty of examples throughout the rest of the film of the Evolved Threat Intel Cycle loop continuing to run:

  • Intelligence is acquired that the Rebels have raised their shield generator, which leads to the Consumers changing their Response action from orbital bombardment to ground assault.
  • Priority Intelligence Requirements are changed based on new information to find the Millenium Falcon, and Intel Producers conduct several pivots to accomplish this (asteroid bombardment, attempted hyperspace tracking, etc.).
  • Consumers are supplemented with third-party threat hunt teams (i.e. bounty hunters like Boba Fett and Bossk).
  • The entire security organization collaborates to set up a honeypot to lure Luke Skywalker to Cloud City on Bespin. Or should it be considered ransomware?

The Importance of FeedbackThe best managers cultivate top talent and promote from within.

We’ll close where we started: with Darth Vader as an effective manager. Giving actionable feedback and making adjustments to inform the next run through the evolved intel cycle is critical to improving the overall quality, relevance, and effectiveness of threat intelligence. Vader does a great job of breaking down silos (by using the Force to choke one bad apple), and by promoting Captain Piett to Admiral, he’s effectively giving a vote of confidence to the power of threat intel and creating a fusion center model. He continues to give feedback to his team throughout the film, thanks to him being an empowered intel Consumer.

ConclusionThe Battle of Hoth in The Empire Strikes Back is a clear example of the value of threat intelligence. The film highlights the limitations of the traditional Threat Intelligence Cycle, which is often treated as a closed loop and lacks accountability and stakeholder involvement. However, the Galactic Empire was able to overcome these limitations by adopting an Evolved Threat Intelligence Cycle. This approach explicitly calls out the personas involved in threat intelligence, ensures continuous improvement, and fosters collaboration and trust between producers and consumers of intelligence. The end result is that threat intelligence becomes an essential element of the security organization, leading to successful operations and outcomes.

One thing that the Empire did not have was a software platform purpose-built to operationalize the Evolved Threat Intel Cycle: a TI Ops platform. A TI Ops platform takes the Evolved Cycle and streamlines each phase with automation and analytics. A TI Ops platform helps boost consumer confidence in the cycle and gives Producers tools that help them demonstrate how they’re making a difference to the broader security organization. Perhaps if Admiral Ozzel had had a TI Ops platform, he wouldn’t have faced Vader’s wrath!

May the Force be with you.

If you’d like to learn more about our Threat Intelligence Operations and the Evolved Threat Intel Lifecycle, please read “The Dawn of TI Ops.”

The post The Need for an Evolved Threat Intel Lifecycle appeared first on ThreatConnect.

View Details

Threat intelligence activities, especially enrichment, analysis, and action, have traditionally required a lot of manual work. Threat Intel Operations analysts are not expected to be coders, spending their time in Python to automate their activities, and it’s not usually a “one and done” activity. Changing APIs and process improvements that require scripts to be updated regularly takes time away from TI Ops analysts doing what they want to be doing – operational, tactical, and strategic threat intel activities.

Drop ‘n Drag is BetterDrop ‘n drag tools are easier to use and much faster than manual coding when building out automation. Drop ‘n drag coding is more visual, easily understandable, and user-friendly. This saves valuable time and improves the availability of Playbooks, both new and updated.

Empower Your TI Ops AnalystsTI Ops and other security operations analysts can leverage ThreatConnect’s low-code automation capability to address threats that can potentially impact your enterprise proactively and rapidly. Full automation is the key to rapid threat intelligence processing and dissemination to power threat response and mitigation.

Cybersecurity Ecosystem Integration is EverythingPlaybooks can automate the dissemination of threat intelligence to any of ThreatConnect’s hundreds of integration partners. Low Code Playbook Automation can also handle data from any cybersecurity control or tool, such as firewalls, etc., including those not yet integrated with the ThreatConnect Platform.

Let the ThreatConnect Platform Work for YouThe ThreatConnect Platform uniquely leverages risk insights and automation to help focus limited organizational resources on the organization’s top priorities. The ThreatConnect Platform will help move your TI Ops team from reactive to proactive engagement. Your team will more effectively use threat intelligence and knowledge to drive better decisions and more effective action. This allows security teams to more rapidly leverage actionable threat intelligence to close the loop between threat actor activity and defensive cyber measures. This new knowledge enables your team to detect, prevent, and mitigate malicious ongoing threats.

As an example, consider that a new and dangerous cyber threat has been identified targeting banks and financial institutions within the United States. Your threat intelligence sources and review of industry websites indicate that your organization may be facing this threat shortly. Using your IOC data, you have crafted a response plan along with the threat detection and response team to automate a response to this threat to minimize the risk of a successful attack. It will take about three days to program and test the new Playbook. But that may be too long. Another bank in your state was just successfully hit by the threat. The solution? Using ThreatConnect’s low-code automation to quickly and easily construct a playbook. Using the drop ‘n drag playbook builder capability, you can construct the process for the Playbook in minutes.30 minutes., test it, and deploy it the same afternoon.

Learn MoreThreatConnect’s Low Code Playbook Automation can give you the flexibility, consistency, and rapid speed implementation that your team needs.

To learn more about how ThreatConnect can help your organization maximize insight, increase efficiency, and improve overall collaboration, please look at the ThreatConnect Platform. Reach out to us via https://threatconnect.com/contact/, and we’ll be pleased to share a customized demonstration of the ThreatConnect Platform.

The post It’s 2023, Automating Your Threat Intelligence Operations Doesn’t Have to be Hard appeared first on ThreatConnect.

View Details

A dedicated threat intelligence team and function has been treated as a luxury for far too long, and if there is one, demonstrating its value is a persistent struggle.

However, security leaders know that the modernization and digitization of the enterprise, an expanding attack surface, and evolving adversaries are stressing their teams and capacity. In order for organizations to be more resilient to threats, they need to be more proactive in their response to the most relevant adversaries while working to minimize exposures that can be used in attacks.

Getting ahead of adversaries by operationalizing threat intelligence is the way to do this.

We believe that a new approach to threat intelligence across people, processes, and technology is required.

  • One that elevates the threat intel function, which we call Threat Intelligence Operations (aka TI Ops), to a core team in security operations.
  • It requires an Evolved Threat Intel Lifecycle that considers not just the production but the consumption of threat intel – which meets agreed needs and requirements, is delivered at the right time and place, is actionable, and has demonstrable value to the consumer.
  • A modern Threat Intelligence Operations Platform that solves the challenges faced by teams relying on spreadsheets and legacy threat intel platforms.

ThreatConnect enables organizations to maximize the impact of TI Ops by utilizing a combination of human analysis, AI and machine learning, and automation. In our latest release, ThreatConnect 7.0 delivers new capabilities that radically increase the effectiveness and efficiency of threat intel operations analysts and security operations teams throughout the Evolved Threat Intel Lifecycle.

The ThreatConnect 7.0 features and capabilities include:

  • Native Reporting
  • Built-in Enrichment
  • Improved User Experience

Native ReportingDissemination and Enabling Leadership are key stages in the Evolved Threat Intel Lifecycle, providing stakeholders the necessary information and insights to make strategic, tactical, and operational decisions. This is most easily achieved with reports but getting the right information in front of the right people at the right time is difficult when analysts are stuck exporting data using copy and paste across multiple spreadsheets and documents.

Analysts need an easy way to build custom reports within the ThreatConnect Platform to demonstrate the value of TI Ops to the organization. ThreatConnect 7.0 introduces the first version of in-Platform, native Reporting. ThreatConnect’s Reporting feature was built for ease of use based on real-life reports analysts use every day to ensure you can continue to provide the same type of content and formatting you’re used to, now in the same tool that produces the data and insights.

Building, customizing, and sharing reports within the Platform is nearly effortless with drag-and-drop functionality. Users have the flexibility to choose which sections to include and to format each section within the report as they see fit. Each report has customizable headers and footers so users can include their organization’s brand and have the ability to contextualize each report down to the individual data point. Add out-of-the-box charts and tables or build your own using our proprietary ThreatConnect Query Language (TQL) for valuable context in each report, as well as images, charts, and data from Threat Graph, our interactive visualization tool.

Reporting in the Platform not only saves analysts time but also enables them to easily share the most relevant threats and intel to better communicate the value of TI Ops and enable leadership from the CISO down to have the necessary information and insights to make strategic, tactical, and operational decisions.

In future releases, we’re introducing more features like Case Reports, API Support, Reporting Templates, Automated Scheduling, Playbook Integration, and more!

Built-in EnrichmentSecurity teams are buried in indicators, but not all indicators are relevant. The more an analyst knows about an indicator, the better they can assess its severity and relevance to their organization. Adding context to individual indicators is cumbersome, relying on manual processes or building and maintaining complex Playbooks for simple enrichment.

To help analysts perform more efficient and effective investigations, ThreatConnect added built-in, out-of-the-box Enrichment of threat intel, adding more context without impacting analyst time and effort. In this first iteration of Enrichment, users can easily configure VirusTotal in ThreatConnect to understand the maliciousness of an indicator and links and dependencies between indicators, with more partner integrations coming in the future.

Once VirusTotal is configured, Enrichment is as simple as one click. With a single click, users get basic information about an Indicator beyond just its score, including Tag, Domain, Country, First and Last seen, etc. A second click within the Platform provides more details about an indicator’s links and dependencies for additional context. VirusTotal scores are queryable via ThreatConnect Query Langue (TQL), adding relevant enrichment data to your threat library for future analysis during an investigation.

Additionally, users can leverage Threat Graph to conduct investigations and visualize and contextualize enrichment data to understand an indicator’s relationships and associations with other indicators, like if an IP has been part of a threat campaign.

With Enrichment, you’ll save time and resources processing and analyzing hundreds of thousands of indicators trying to determine which pose a threat and which are benign while expanding your threat library with relevant enrichment data. In later releases, we’re adding more enrichment sources like URLscan, Shodan, and more!

Improved User ExperienceSecurity teams need to move fast and make important decisions to confidently take action on impending threats. In the ThreatConnect 6.7 release, we introduced Cross-Owner Associations (XOA), enabling users to link information across sources in their ThreatConnect instance for a fuller view of their organization’s threat landscape. In ThreatConnect 7.0, we revamped the Details screen, creating a more intuitive user experience.

The updated Details page is easier to use, elevating relevant information about Indicators and Groups in one place so analysts can quickly understand the threats to your organization and make fast decisions without having to dig around the Platform. Noteworthy updates to the Details page include:

  • Insight from multiple sources – Leverage insights from a variety of sources, including local and global insights from CAL, our ML-powered analytics engine.
  • Pinned Attributes – Elevate the most important information to the top of the Details page so you can spend less time scrolling and make decisions even faster.
  • Enrichment – Out-of-the-box enrichment of indicators adds contexts to understand the links and dependencies between indicators for more effective investigations without having to build out complex Playbooks.

This revamped Details page is the foundation of multiple enhancements planned for future releases, including Automated Associations via TQL, ATT&CK Navigator, and other features to form a single pane of glass in the ThreatConnect Platform.

Download ThreatConnect’s Dawn of TI Ops White Paper and the Evolved Threat Intel Lifecycle infographic to learn more about getting ahead of adversaries by operationalizing threat intelligence. You also don’t want to miss our webinar The Need for an Evolved Threat Intel Lifecycle, on February 17th, 2023! Register here.

For more information on these new capabilities and how ThreatConnect can help your organization operationalize threat intelligence, please reach out to sales@threatconnect.com or request a demo.

The post ThreatConnect 7.0: The Industry’s First Threat Intelligence Operations (TI Ops) Platform appeared first on ThreatConnect.

View Details

Cybersecurity technology, processes, and tradecraft are constantly evolving as the attack surface, and vectors expand. It’s no secret that threats are growing faster than defenders can combat them. Organizations often create specialized teams with a specific mandate, such as incident response and threat hunting, which become siloed. This impacts their ability to share valuable threat intelligence they’ve collected with the rest of the security team. Also, as more security technologies are added to this mix – with the average organization having 76 security tools1 – making effective use of high-fidelity threat intelligence is critical.

Organizations that want to infuse threat intelligence into cyber defense operations, offensive security, and incident response activities to gain efficiencies, enhance effectiveness and increase collaboration should consider implementing a cyber fusion operations model. At ThreatConnect, we call this Intelligence-Powered Security Operations.

The cyber fusion operations model is not a new concept. After the release of the 9/11 Commission report the model was introduced in the government intelligence sector by the Department of Homeland Security to enable better communication and collaboration between intelligence agencies and law enforcement. Today, security organizations successfully implement this model and see real results, including improved mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) to threats, lower rates of false positives for alerts, and higher effectiveness through prioritization of the most critical threats.

Threat Intelligence Operations (TI Ops) is the central nucleus or core of a successful cyber fusion operations model, integrating threat intelligence into security activities and tools. Organizations that want optimal performance from cyber fusion operations must invest in a platform that centralizes threat intelligence, automates key activities, and enables information sharing across the security organization and with external parties.

Cyber fusion operations can be centralized in one location, or it can be a virtual team deployed across the globe, as long as collaboration is enabled across professionals that handle security activities such as defense (threat detection & response, vulnerability management, threat hunting, etc.), offense (penetration testing, red teaming, etc.), incident response, and cyber risk management. By placing TI Ops at the core of these activities and using a modern threat intel operations platform to aggregate, enrich, analyze, and act on threat intelligence, security teams can use high-fidelity, intelligence-powered insights to drive the right decisions, activities, and actions.

The key to successful collaboration and effectiveness across cyber fusion operations is making threat intelligence readily available in a centralized location for all security functions. The ThreatConnect Platform is a modern threat intelligence operations platform that provides the capabilities for a cyber fusion operations function:

  • Unified library for threat intelligence, integrating with the organization’s security tools to gather information from all relevant sources and collaborate in a single platform
  • CAL – AI and ML-powered analytics and global intelligence that provides insights across thousands of ThreatConnect Platform users, novel threat feeds, and insights leveraging natural language processing.
  • Threat Graph to quickly explore, pivot, and gain insight into the connections between seemingly disparate intelligence and data points to get a comprehensive picture of a threat.
  • Low code automation capabilities to optimize and automate threat intelligence operations processes, work, and tradecraft
  • Browser Extension allows analysts to leverage the ThreatConnect Threat Library in any web-based environment, easily access the knowledge in the ThreatConnect Platform, and add new threat intelligence data directly to the Threat Library without having to do any copy and pasting.

Cyber fusion operations aligns people, processes, and technology within the security organization to optimize security resources and activities. Through increased collaboration and improved efficiency, teams can realize breakthrough effectiveness, which will lighten the load for everyone and better protect the organization.

Read our newest How ThreatConnect Enables Cyber Fusion Operations Whitepaper to learn more!

The post Powering Cyber Fusion Operations with ThreatConnect appeared first on ThreatConnect.

View Details

Part one of this blog series begins with a simple step-by-step walkthrough of how to craft and save a ThreatConnect Query Language (TQL) query without writing out, or even fully understanding, all of the TQL options. Before we jump into the steps, let’s talk a little about TQL. What is it? Why would I want to use it? How does TQL help?

One of the key tools in an analyst or researcher’s toolbelt is the ability to do a highly targeted search. I’ve personally seen many new analysts succeed or fail based in part on whether they could draft a Google query that brought them the results they needed. In ThreatConnect, TQL is somewhat like a hyper-focused Google query. By combining different terms and data types into a TQL query, you can filter the data in ThreatConnect down to very granular levels so you can weed out the noise and focus on the pieces of information that are relevant to your investigation. TQL is available today in Playbooks as well as on the Platform’s Browse screen. In this blog, we’re going to be focusing on using TQL in the Browse screen. (For additional background and information about TQL, please see this knowledge base article.)

Step 1 – Go to the Browse ScreenWhy the Browse Screen? Well, the Browse screen provides filtering functionality that isn’t available in the traditional Search feature in ThreatConnect. It also has a couple of handy buttons that you can use to get ThreatConnect to do some of the work for you.

Step 2 – Click to view FiltersFilters give you the option to start targeting particular pieces of information. For example, you can leverage the filters to query for files that have certain tags or were created at particular times. You can even query while investigating a certain set of activities based on attributes like import hash (imphash).

Enter any filters you want. This may be a combination of tags and attributes or a series of tags with specific threat ratings and confidence levels. In the example above, you’ll see on the left, only the File indicator type is selected. Additionally, the user filters by the tag “kasperagent” and the imphash attribute with a value of “bb6ef7b30a980028d0e03d1a516f3208”. These filters search for file indicators with the identified tag and the imphash attribute value and help analysts zero in on the information that they need rather than having to wade through the massive amounts of data available to them.

Note: Make sure you hit “Apply” in the bottom right corner before moving on to the next step.

This next part is kind of like magic.

Step 3: Click “Advanced”
The Advanced button on the Browse screen automatically converts the filters into a TQL query that can be used in other areas of the Platform.

From there, you can click the kabob menu on the right to save the query for use in Dashboard cards. (Soon available for use in Reporting and other areas of ThreatConnect.)

By leveraging the Advanced button, you are able to have ThreatConnect build a TQL query for you. You can then add additional parameters as needed to filter your search further. This lets you drill down into the data available in ThreatConnect and bring items of interest to the surface faster. Then, with the Save functionality mentioned above, you can capture that query for later use so that you can use it again and again without having to go through the process of writing a new query each time you want to look at a given set of information. All in all, by leveraging these steps to capture a TQL query, users can identify relevant information faster so they spend more time doing analysis and less time searching through data points.

Next Up:In our next post in this series, we’ll be diving into building a dashboard leveraging some of the TQL queries you can build in the Browse screen and highlighting how Dashboards can help bring relevant information to the surface so you spend more time doing analysis and less time poking about looking for something to research.

Who am I:Hi, I’m Marika. I’m currently the Senior Strategic Product Manager for Threat Intelligence at ThreatConnect, but before moving into that position (and completely changing careers), I spent 10 years in threat intelligence analyst and threat researcher roles. I am a complete nerd at heart and love nothing more than digging into seemingly disparate incidents and finding similarities leading to new understandings of the threats facing an organization. That said, I am not a technical analyst. I do not write code, and I only made it halfway through my Python book. This series is for people like me. People who are more strategic threat intelligence analysts who look at behaviors and trends in activity and make technical concepts easier to understand for non-technical people.

The post ThreatConnect Query Language (TQL) for People Who Don’t Code appeared first on ThreatConnect.

View Details

The new year is almost upon us, and 2022 has been a game of ransomware hardball. However, lessons learned this year can help organizations take proactive steps to protect themselves from ransomware in 2023.

If you followed Cybersecurity and Infrastructure Security Agency (CISA) alerts on ransomware for the year, you would have noted malicious activity attributed to many ransomware variants. CISA noted that threat actors’ ransomware tactics and techniques were continuing to evolve and become more technologically sophisticated with every passing month. That makes high-fidelity threat intelligence and a proactive security stance critically important to success in 2023.

Change it Up in 2023 – Get Ahead of Known VulnerabilitiesMany threat groups successfully leverage aging vulnerabilities, which, if they had been patched by their victims, may have prevented an attack. Organizations can have hundreds, thousands (or more) of un-remediated vulnerabilities that could open the door for an attacker. In a recent survey, respondents indicated that 57% of all observed vulnerabilities are more than two years old, with as many as 17% being more than five years old.

For example, in December 2022, CISA issued an advisory on Cuba ransomware. One of the most common techniques used by Cuba actors exploited known vulnerabilities. In one featured example, Cuba actors exploited a vulnerability in the Windows Common Log File System (CLFS) that allowed them to steal system tokens and escalate privileges.

Cuba ransomware was first observed in 2019. In late 2021 and 2022, Cuba ransomware delivered an increasing number of high-profile attacks. By the end of 2022, Cuba ransomware threat actors had compromised over 100 organizations worldwide. Its demands for ransom have exceeded $145 million, with collections exceeding $60 million. While a top attack vector for Cuba is the exploitation of known vulnerabilities, the actors’ techniques also include phishing campaigns, compromised credentials, and remote desktop protocol exploits.

When it comes to Cuba and similar threats, access to high-fidelity threat intelligence to help identify the highest risk, most actively exploitable vulnerabilities can help prioritization efforts when organizations are faced with a backlog of vulnerabilities to address. Tools for phishing analysis and remediation that save security operations teams time and help find indicators of compromise across a sea of suspicious messages can also make a big difference in the fight against ransomware.

Collaboration and Information-Sharing Can Make A DifferenceOne initiative in the European Union has helped more than 1.5 million ransomware victims. These victims decrypted their files without accepting the ransom demands saving these individuals an estimated $1.5 billion. The program, No More Ransom, was conceived and supported by the National High Tech Crime Unit of the Netherlands’ police, Europol’s European Cybercrime Centre, Kaspersky, and McAfee and offers over 135 freely available decryption tools that can help with 165 variants of ransomware. No More Ransom now includes 185 partners from the public sector, private industry, law enforcement, and academia.

The key to the success of an effort like No More Ransomware is information-sharing and collaboration. Combating malware, ransomware, and malicious cyber attacks has always relied on information sharing, exposure of actors’ TTPs and the dissemination of reliable threat intelligence so that security professionals can quickly develop mitigations, remediations, and update their defenses to block future attacks.

Get Ready for Ransomware in 2023 with the ThreatConnect PlatformThe ThreatConnect Platform centralizes threat intelligence, improves decision-making, automates key activities, and enables information sharing and collaboration across the internal security organization and with external partners to help combat threats like ransomware in real-time. TI Ops teams, security operations, and everyone within the security organization will benefit when threat intelligence is aggregated, enriched, analyzed, and acted upon from a single source.

It’s well-known that ransomware can be delivered via un-remediated vulnerabilities, but many security teams are overwhelmed by the sheer number they are facing. Organizations can leverage threat intelligence in the ThreatConnect Platform to quickly prioritize and help drive vulnerability remediation.ThreatConnect collects real-time intelligence from the CISA Known Exploited Vulnerabilities Catalog and Google Project Zero, as well as other feeds and sources, enriching it with insights from sources such as the National Vulnerability Database (NVD) and the global ThreatConnect community. When combined with the data from your vulnerability scanners, it delivers a full picture of the exposures in your environment. Vulnerability Management teams are provided with vulnerabilities prioritized by those that are being actively exploited in order to take the right actions. Low-code automation of processes can make the required actions fast, reliable, and repeatable.

Another common delivery mechanism for ransomware attacks is via phishing emails, compounding the problem for security teams already overburdened with managing an ever-growing volume of suspicious messages that require review. ThreatConnect simplifies the processing, categorization, and response to suspicious emails, reducing the time to remediate active threats from days to minutes. The Platform can look for indicators across file attachments, embedded links, and more and provide in-platform risk scoring. Indicators can be enriched with data from third-party sources and CAL to identify and prioritize known malicious indicators. Once identified, indicators can be automatically sent to security tools, like secure email gateways and firewalls, to block threats in real-time.

Learn MoreTo learn more about how ThreatConnect can help you prepare for the potential of a ransomware attack, check out the ThreatConnect Platform.

Better yet, reach out to us, and we’ll be pleased to share a customized demonstration of the ThreatConnect Platform.

The post Preparing Organizations To Stop Ransomware in 2023 appeared first on ThreatConnect.

View Details

In cybersecurity, contextual data is important. Contextual data with speed becomes everything. But many cybersecurity teams are too far away from the critical information they need to make fast and accurate decisions. Time is not on your side. It is just an unfortunate fact that threat and security researchers spend too much time digging through multiple threat feed sources and disparate logs searching for key information and not enough time making the data actionable.

ThreatConnect’s new browser extension brings the critical information your security team needs within fast and easy reach. You can review web-based resources and have potential indicators of compromise and related data elements highlighted to show that additional information is available. In one click, you can find expanded data gathered from the ThreatConnect CAL Automated Threat Library and all the threat intel sources available.

A practical example of the browser extension is in being used to disambiguate threat actor groups. So in your document, you might see the term APT41. The ThreatConnect browser extension has highlighted and hyperlinked this term to show that there is data available. You can click the hyperlink to instantly see, “APT41 is a threat group that researchers have assessed as a Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observed targeting healthcare, telecom, technology, and video game industries in 14 countries. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.”

Further, you can click an additional highlighted link and learn that “The state-sponsored group APT41 is also known as ARIUM, Winnti, LEAD, WICKED SPIDER, WICKED PANDA, Blackfly, Suckfly, Winnti Umbrella, and Double Dragon.” This contextual data helps maximize insight so that the best-informed decisions can be made quickly and efficiently.

By operationalizing rapid and easy access to threat intelligence, you help maximize collaboration, break down silos, and increase the value of your threat intelligence program. ThreatConnect’s browser extension provides an easy and automated way to share rich, contextualized threat intelligence on web pages or web-based SaaS tools.

It’s Not a Job—It’s an AdventureYour SOC team doesn’t have a job—almost every day is a hand-to-hand combat adventure. Every day, your team needs the tools and information to gain advantage on the threat actors that would do your organization harm. Speed and rapid access to information enables your team to make the best decisions and execute them faster.

ThreatConnect’s browser extension can enable your team to leverage automated data retrieval for maximized efficiency. The speed of access to relevant and important data can improve collaboration throughout the team and improve decision-making.

Behind the browser extension is the full power and capability of the ThreatConnect platform. You can leverage our automation and orchestration to power your cyber threat intelligence operations to scale and execute with light speed. ThreatConnect’s built-in automation and orchestration can reduce workloads and help your team make better security and business decisions. Your SOC will benefit from faster, smarter, and repeatable processes with accessible and readily available intelligence, and customizable workflows in the ThreatConnect platform.

Learn MoreThreatConnect’s browser extension can give you the speed you need. To learn more about how ThreatConnect can help your organization maximize insight, increase efficiency, and improve overall collaboration, please take a look at the ThreatConnect Platform. Reach out to us via https://threatconnect.com/contact/, and we’ll be pleased to share a customized demonstration of the ThreatConnect Platform.

The post ThreatConnect’s Browser Extension Puts Critical Information Within Fast and Easy Reach appeared first on ThreatConnect.

View Details

In the fast-paced, ever-changing cybersecurity landscape today, organizations recognize the need to transform their security operations to achieve greater effectiveness and deliver better protection while demonstrating a measurable return on investment. When threat intelligence operations (TI Ops) infuses cyber threat intelligence into everything a security team does, it results in better decision-making, greater efficiency, and stronger collaboration. This is the concept of Intelligence-Powered Security Operations (IPSO). IPSO makes it possible for organizations to apply their efforts where they’ll have the biggest impact against the most dangerous threats and most prevalent attack tactics.

Placing TI at the core of your security operations informs every aspect of your security program. Consider IPSO the next evolution in a transformation from traditional SecOps to a highly collaborative and flexible organization that spreads TI across functions to protect against, detect and respond to threats. By combining people, processes, and technology, IPSO can deliver on the promise of a stronger and more agile security organization.

The challenges facing security teams today are no secret:

  • Teams struggle to collect, prioritize, and act-on high-fidelity threat intelligence with a consistent and centralized approach.
  • Having enough skilled staff on hand to address the volume and speed at which vulnerabilities emerge has become one of the biggest challenges in the security industry.
  • Alerts are overwhelming security teams to the point where some alerts may get missed completely.

Threat intelligence management is a starting point to address these problems. Building a centralized threat library can act as the system of record for relevant, documented threats and provide your organization with a holistic view of the threat landscape in one place, supporting faster decision-making and more efficient operations. From this, your defenders will have the information they need to better identify, detect and respond to attacks.

Using a Threat Intelligence Platform (TIP) as your threat library will bring additional capabilities to the table as it can offer access to real-time feeds, machine learning, and valuable analytics to help refine and improve your TI data. The ThreatConnect platform analyzes and makes intelligence actionable, which helps the TI Ops team be more agile and effective.

Infusing threat intelligence into an alert triage program empowers analysts to quickly cross-check alert data with current sources of threat intelligence to get the most current information and act quickly on the most meaningful threats. When using a single source of high-fidelity threat intelligence from a unified threat library to fuel the security technology stack, including firewalls, Endpoint Detection & Response (EDR), Security Access Service Edge/Security Service Edge (SASE/SSE), Security Information and Event Management (SIEM), etc., you get better detections, a reduction in false positives, the ability to link related alerts across tools into a single incident and better alert prioritization which makes organizations more effective and efficient.

Considering the unparalleled growth of vulnerabilities in recent years, it’s easy to see how threat and vulnerability intelligence could be leveraged to create a clear prioritization. Intelligence-powered security operations can evaluate which vulnerabilities are currently being employed by attackers and what’s up next by tracking cybercriminal chatter. Take this a step further and consider how cyber risk quantification could rank vulnerabilities by their potential financial impact to the organization and show clear return on investment for your vulnerability management program. With ThreatConnect RQ, you can focus on remediating the most important unpatched CVEs in the applications and systems that represent the highest financial risk to your organization.

Want to learn more about how threat intelligence and risk quantification can improve your approach to remediation? View this Vulnerability Enrichment webinar.

These are clear examples of how intelligence-powered security operations address some of today’s top cybersecurity challenges, but this is just a taste. Read our white paper: Smarter Security and Maximum Impact from Intelligence-Powered Security Operations for a full exploration of the case for IPSO, how it elevates security operations and puts TI Ops at the core of successful security programs.

The post Intelligence-Powered Security Operations: Evolve Beyond Traditional SecOps appeared first on ThreatConnect.

View Details

The stakes facing USA’s critical public infrastructure organizations in today’s threat environment are higher than ever before. Targeted with an onslaught of relentless attacks and malicious activity, threat actors can and must be stopped every single time. Through a combination of prevention and blocking, if even one successful attempt to sabotage a water system, community healthcare provider, transportation system, food distributor, emergency services provider, or electrical grid happens, it can threaten the health and well-being of a community. And with an increasing number of high-profile ransomware attacks, like the 2021 Colonial Pipeline shutdown that affected travel on the U.S. East Coast for days or the malicious actors that added lye to the water supply in Oldsmar, FL, but were quickly thwarted, this issue is also making the wrong kind of headlines.

New Industry Cyber Performance MeasuresIn October 2022, the U.S. Department of Homeland Security released Cybersecurity Performance Goals (CPGs), a set of baseline measures that critical infrastructure agencies of all sizes can leverage to ‘protect against cyber threats.’ They are intended to be implemented with the NIST Cybersecurity Framework to help organizations across the private sector and government take action on the most impactful cybersecurity practices.

CPG measures simplify what could be vast and unwieldy expectations for organizations that don’t know where to start – and provide a focus for organizations with security programs that need to evaluate their current maturity. Designed by the Cybersecurity and Infrastructure Security Agency (CISA), the CPG measures hone in on areas that will decrease risks to networks, data, and systems to protect U.S. infrastructure and supply chains. Each CPG includes risks, tactics, techniques, & procedures (TTPs), outcomes, scope, security practices, and recommended actions. The CPGs include:

  • Account Security
  • Data Security
  • Device Security
  • Vulnerability Management
  • Response and Recovery
  • Supply Chain / Third Party
  • Governance and Training

Intelligence-Powered Security Operations Can Help Meet CPGsThe CPGs outlined by CISA and DHS offer critical infrastructure sectors a set of standards for organizations of all sizes, as well as a way to prioritize investments in security. To meet these objectives, many teams will need to make meaningful structural changes and transition from a reactive to a proactive security posture. Public sector organizations who want to make this transition should consider adopting an Intelligence-Powered Security Operations model.

When organizations make the decision to place Threat Intelligence Operations (TI Ops) at the core of all security activities and infuse threat intelligence throughout their organization, they can prioritize resources and focus their efforts on addressing the biggest risks and threats. Intelligence-Powered Security Operations combine people, processes, and technology to deliver an agile security organization with centralized functions prepared to protect against, detect and respond to malicious activity based on high-fidelity threat intelligence. A key outcome of adopting this model is the ability to accelerate the time to detect and respond to threats by prioritizing threats targeting your organization.

How ThreatConnect Enables Intelligence-Powered Operations to Protect Critical InfrastructureWhen TI Ops infuses threat intelligence into everything security operations does, it results in better decision-making, greater efficiency, and stronger collaboration. The ThreatConnect Platform centralizes threat intelligence, automates key activities, and enables information sharing across the security organization. The security team will act on high-fidelity threat intelligence to prioritize their efforts thanks to real-time intelligence feeds enriched with CAL analytics and insights from the ThreatConnect global user community. Automation saves teams time with standard and repeatable best practices that speed up the time to respond and remediate threats.

Infusing threat intelligence into an alert triage program empowers analysts to quickly cross-check alert data with current threat intelligence sources to get the latest updates on active threats and make informed decisions. The Platform offers integrations with firewalls, endpoint/network security, security analytics, SIEM, etc., to get better detections, a reduction in false positives, the ability to link related alerts across tools into a single incident and better alert prioritization, which makes organizations more effective and efficient.

An entire set of CPG measures is dedicated to Vulnerability Management. The ThreatConnect Platform enables vulnerability prioritization to ensure the riskiest vulnerabilities are addressed first by ingesting relevant vulnerability data, scoring vulnerabilities, and prioritizing actively exploitable vulnerabilities.

ThreatConnect Helps Transform Security OrganizationsAs critical public infrastructure organizations review the recently released CPGs, and CISA continues to expand guidance for individual sectors, Intelligence-Powered Security Operations offers security operations teams a guide to modernizing by placing TI Ops at the core of security activities and infusing threat intelligence into everything they do. The ThreatConnect Platform empowers TI Ops teams as it aggregates, analyzes, and makes intelligence actionable.

Reach out to us at https://threatconnect.com/contact/, and we’ll be pleased to share a customized demonstration of the ThreatConnect Platform to show how we can help your organization achieve the expectations associated with the CPGs.

The post Intelligence-Powered Security Operations Can Propel U.S. Critical Public Infrastructure to Meet New Cybersecurity Performance Goals appeared first on ThreatConnect.

View Details

One of the main tips & guidance from the Cybersecurity and Infrastructure Security Agency (CISA) is to “Keep Calm and Patch On.” CISA emphasizes addressing vulnerabilities twice in this section. Two out of the four tips focus on the importance of finding and addressing vulnerabilities.

For many organizations, that’s easier said than done. Vulnerability management has become a pain point for overburdened security teams who have thousands of vulnerabilities and find it difficult to decide where to start. The process to find, analyze and prioritize the most actively exploitable vulnerabilities is still time-consuming and decentralized for many security teams.

At the same time, the ransomware threats are real. In summer 2022, a Cyber Security Alert (CSA) published jointly by the FBI and CISA as part of their ongoing #StopRansomware campaign outlined the known tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), as well as recommended mitigation strategies for the Zeppelin ransomware targeting organizations with a ransomware double-header. The Zeppelin actors would both encrypt systems and steal data to sell or publish.

Zeppelin is part of the VegaLocker ransomware family used to support ransomware-as-a-service (RaaS) cyber operations. The VegaLocker ransomware family includes other ransomware strains such as Jamper, Storm, or Buran. The Zeppelin threat actors have been targeting primarily large companies in the United States and Europe. From 2019 through 2022, this has included industries such as defense, education, manufacturing, healthcare, and technology. The Zeppelin threat actors usually request Bitcoin payments in amounts ranging from a few thousand dollars to over $1 million.

The Zeppelin actors are following a multi-vector attack model. They gain access to victim networks via remote desktop protocol (RDP) exploitation. RDP servers are often vulnerable with default passwords. The actors also exploit SonicWall firewall vulnerabilities and use phishing campaigns to trick users into clicking on attachments that appear as document links. Once inside the network, actors map systems, data, and backups before deploying their attacks. With many Zeppelin attacks, traditional ransomware encrypted systems are combined with a secondary threat to sell or publically release sensitive data if the ransom is not paid. These types of ransomware attacks are much more potent when dealing with multiple impacts – encrypted systems and data and the threat of publicly releasing sensitive information.

If you have not already, check out the recommended Zeppelin mitigations in the CISA alert and take steps to protect your organization from lingering IOCs. To stop attacks like Zeppelin in the future, the advice is clear.

  1. Prioritize remediating known exploited vulnerabilities.
  2. Train users to recognize and report phishing attempts.
  3. Enable and enforce multi-factor authentication.

How Does the ThreatConnect Platform Help With Vulnerability Prioritization and Remediation?Organizations can leverage threat intelligence in the ThreatConnect Platform to quickly prioritize and remediate vulnerabilities, which is the number one action item on CISA’s list of proactive mitigation measures for stopping future ransomware attacks like Zeppelin.

To do this, ThreatConnect collects real-time intelligence from the CISA Known Exploited Vulnerabilities Catalog and Google Project Zero, as well as other feeds and sources, enriching it with insights from sources such as the National Vulnerability Database (NVD) and the global ThreatConnect community, to deliver a full picture of vulnerabilities in the environment. Threat Intelligence Operations (TI Ops) teams have a clear dashboard showing vulnerabilities prioritized by those that are being actively exploited in order to take fast action.

TI Op teams and their colleagues in other security roles like vulnerability management get a full picture of each vulnerability in a single record with severity, affected products, attack vectors, related vulnerabilities, reports, signatures, indicators, TTPs, and more. The Threat Graph feature easily creates visual representations of relevant vulnerability information and impact on the organization, making it easier to understand the potential associations and relationships in the environment.

Through low-code automation, organizations can reduce the burden on overworked security teams by automating manual, often repeated tasks which also speeds up vulnerability remediation. And to promote information-sharing and maximize collaboration, TI Ops teams can generate tailored, on-demand, real-time reports with all the necessary information stakeholders need about critical vulnerabilities and their impacts.

Learn How ThreatConnect Can Speed Up Your Time to RemediateLearn more and see a demonstration of how ThreatConnect enables vulnerability prioritization in this webinar.

Or reach out to us at sales@threatconnect.com to see how we can help you use ThreatConnect to track, prioritize and get the detail you need on the most actively exploitable vulnerabilities to stop ransomware attacks.

The post It’s Time to #StopRansomware With Vulnerability Prioritization and Remediation appeared first on ThreatConnect.

View Details

In recent years, healthcare providers are increasingly being targeted with coordinated, sophisticated Phishing and Business Email Compromise (BEC) campaigns. As these attacks continue to grow, security teams need tools to help save time and address the threats more effectively.

In one recent example, the Health and Human Services Health Sector Cybersecurity Coordination Center (HHS HC3) issued an alert warning about a malicious phishing campaign aggressively targeting healthcare institutions. The alert described emails that delivered an Evernote-themed lure to entice targeted recipients into downloading a trojan. Evernote is a popular app in the healthcare community for data sharing (files, notes, schedules, etc.) across phones and other devices. Users were drawn to a login prompt that was designed to harvest user credentials with pages that looked like Adobe, Microsoft, etc.

This campaign was partially effective because of the highly personalized email strategy. HHS HC3 pointed out that some emails included a subject line “(Victim Organization) (Date) Business Review” and gave the user the impression they were opening a secure email from their organization. The login, as mentioned above, was also designed to look legitimate. This convinced the user it was safe to download files once logged in. Then, users were prompted to download a malicious trojan. The trojan acted like a legitimate application or file in order to trick users into running it. Once installed, the trojan could disrupt operations within systems and networks or exfiltrate confidential data.

A main goal of this attack was to obtain access to email accounts. Not only can email accounts contain access to sensitive data, they can provide an even more convincing persona that is used to execute BEC campaigns impersonating other users to further collect credentials and potentially gain access to other systems. This stolen credential access can also be used to launch a ransomware attack. HHS HC3 warned that the stolen credentials may have been used to compromise a number of healthcare organizations and enterprises in other industries.

Healthcare has seen increasing email attacks from threat actors for a number of reasons. The size of the industry has been expanding in the US and globally, with significant revenue increases making it an appealing target for ransoms. There is high turn-over of staff, especially in entry-level positions, which makes it difficult to ensure all staff have cybersecurity training. New technologies are constantly introduced within the industry, and healthcare has experienced a rapid transition to use of connected devices, which puts stress on security teams to keep up.

ThreatConnect Can Help Protect Your Organization from Phishing and BEC Attacks

Security teams need to move fast to capitalize on information in alert communications like those issued regularly from agencies like HHS HC3. For many organizations, managing an endless number of suspicious emails to identify a legitimate threat is extremely time-consuming. The ThreatConnect Platform centralizes threat intelligence, automates key activities and enables information sharing across the internal security organization and with external partners. With ThreatConnect, teams get a single Platform to simplify the processing, categorization, and response to suspicious emails, reducing the time to remediate active threats from days to minutes.

The ThreatConnect Platform also offers workflows and low-code automation to automate the analysis and response process of reported emails. The Platform can look for indicators across file attachments, embedded links, and more and provides in-platform scoring. Indicators can be enriched with data from third-party sources and CAL to identify and prioritize known malicious indicators. Indicators can be automatically sent to your security tools, like secure email gateway and firewalls, to respond and block threats in real-time.

Learn How ThreatConnect Can Help Protect Email From Phishing and BEC Attacks

Request a demo meeting with us or reach out to us at sales@threatconnect.com to see how we can help automate phishing analysis and response for your organization.

The post Healthcare Email Threats are Growing – Combat Them with Phishing Analysis & Response appeared first on ThreatConnect.

View Details

In cybersecurity, contextual data is important. Contextual data with speed becomes everything. But many cybersecurity teams are too far away from the critical information they need to make fast and accurate decisions. Time is not on your side. It is just an unfortunate fact that threat and security researchers spend too much time digging through […]

The post ThreatConnect’s Browser Extension Puts Critical Information Within Fast and Easy Reach appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

The critical challenge for Security Operation Centers (SOC) is minimizing the window of opportunity for attackers by quickly detecting and responding to threats. The time taken to detect and mitigate the threats are tracked by two metrics:  Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR). The efficiency of the SOC is typically […]

The post Improve SOC Efficiency with Intelligence-Powered Security Operations appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

At ThreatConnect, we enable teams to achieve maximum impact on their security program by improving insights, efficiency, and collaboration. We are continuously building and iterating on our Platform based on feedback from our customers to simplify processes, speed up security tasks, and deliver a seamless user experience.  The ThreatConnect 6.7 release delivers a more streamlined […]

The post Maximize Impact with ThreatConnect 6.7 appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

The Latest on ProxyNotShell and How To Respond If You’re Impacted Word is spreading fast about two of the newest zero-day (0-day) vulnerabilities targeting Microsoft Exchange servers, now referred to as “ProxyNotShell” – and how their initial mitigations fell short of expectations. Given the evidence that these vulnerabilities are already being exploited to mount attacks […]

The post ProxyNotShell Zero-day Vulnerabilities Exposed appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

If you don’t have a cyber threat intelligence (CTI) platform, then you need one. The challenge is getting your entire security team, from the CSO or CISO to the security and threat-analyst teams in the trenches, trained and able to use the platform to support daily incident response, network defense, and threat analysis. That’s the […]

The post Cloud-Delivered Cyber Threat Intelligence Platforms Bring Quick Time to Value appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

We all know the saying that, “a picture is worth a thousand words.” It is a fact that people derive meaning faster from imagery and graphics. At our core, humans are visual. Imagery can convey thoughts much faster and more efficiently than just words. Consider an example where you need to describe the shape of […]

The post Threat Graph - Seeing is Believing appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Malware continues to grow in sophistication as record numbers of cyberattacks occur worldwide. Malware is often the tip of the spear for threat actors — first, they use it to compromise a computer or mobile device and then gain access to it. In recognition of the expanding threat that malware presents, the US Cybersecurity and […]

The post Top Malware Strains Used by Threat Actors in 2021 - CISA Alert appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

The pandemic brought major changes to the way organizations work. The rapid adoption of work from anywhere (WFA), completely changed the enterprise cybersecurity landscape.  A recent survey, led by Ipsos Research and management consulting firm, McKinsey, shows that 92 million US workers have the opportunity to work remotely. During the survey, 25,000 Americans were queried, […]

The post The Top Security Risks of Remote Working appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Black Hat USA, also known as Hacker Summer Camp, was held on August 10-11 at the Mandalay Bay Resort in Las Vegas, marking its 25th anniversary of the conference, and it was great to see everyone in person!  Our team had a great time at the conference and wanted to share some highlights they noticed […]

The post Black Hat USA 2022 Cybersecurity Conference Highlights appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

The Federal Bureau of Investigation has recently released an updated FLASH Number CU-000163-MW as part of the overall Government efforts to identify and document ransomware threat actors and the multitude of ransomware variants they deploy. RagnarLocker first surfaced in April 2020 and continues to impact a wide variety of critical infrastructure sectors. These sectors include […]

The post FBI FLASH on RagnarLocker Ransomware Expands Known Indicators of Compromise appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Did you know there were over 1 million phishing attacks just in Q1 of this year? 1,025,968, to be exact! Phishing attacks are getting more sophisticated and involve more clever ways to entice end users to click on those links. Security operations teams are overwhelmed with the number of suspected phishing emails and the lack […]

The post 5 Steps to Combat Phishing With Intelligence-Powered Security Operations appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury, and the Financial Crimes Enforcement Network (FinCEN) have recently released a Cyber Security Advisory AA22-1812A to provide updated information on MedusaLocker ransomware.  This advisory is part of the Government’s efforts to document ransomware threat actors and the […]

The post Top 3 Ways To Defend Your Organization - CISA Issues Critical Alert on MedusaLocker Ransomware appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Threat intelligence teams have a problem, a big data problem due to the velocity, variety, and volume, of the different sets of data they collect. Data comes through non-stop in different forms, from different sources, and from different environments. To make matters worse, not all data is good data because it’s not always accurate or […]

The post Put Threat Intelligence at the Core of your Security Operations appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Leveraging Automation and the Cloud to Improve Cyber Response Threats are moving faster than ever in today’s cyber threat environment. A timely and impactful response to an ongoing cyberattack is critical. Yet, still, today, many companies cannot detect any potentially malicious activity, especially in the early phases of an attack. Most companies are just outnumbered […]

The post Community Powered Insight Gives Defenders the Advantage appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

As more companies look to quantify cyber risk in financial terms, a common question we hear all the time is, “which model (or approach) should I use?.” I saw an interesting quote from a Gartner® research note titled “Drive Business Action with Cyber Risk Quantification “ that spoke about where the CRQ space is going: […]

The post When It Comes To CRQ, What Is An “Open” Model and Is It The Right Question To Ask? appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Security teams need to move at the speed of the business. Teams don’t want to be slowed down by burdensome tasks like manually digging through threat intel or manually triaging alerts. They want to make fast, easy decisions to identify and protect against the most relevant threats. We’ve got you covered! In the 6.6 release […]

The post Move Faster with ThreatConnect 6.6 appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

In recent years, there’s been an increase in attacks targeted specifically toward enterprise software vendors. Nation-states and cyber-criminal gangs are persistently attacking these organizations with increasing sophistication. Attacks like the one against SolarWinds exemplify the challenges software vendors face and it’s getting worse. Microsoft noted that Russian hackers are systematically attempting to infiltrate technology supply […]

The post How Software Vendors Can Leverage Cyber Threat Intelligence for Threat Hunting appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Analysts are overwhelmed by a number of things: the thousands of alerts they receive in a day, the intricacies of hidden details in email messages, embedded links, and attachments, or the inability to control users clicking on malicious materials. Managing the volume of emails and understanding trends in attacks is unwieldy as security teams grapple […]

The post Prioritize Attack Analysis and Response With Actionable Intelligence appeared first on ThreatConnect | Smarter Security for Maximum Impact.

View Details

Business leaders are not always technically-focused, so it is important for security teams to examine how they are communicating risk to leadership and ensure those methods are being effectively received. Overly technical or qualitative methods run the risk of the message getting lost or distorted so well-run security programs are evolving their approach to measuring […]

The post Lessons in Communicating Cyber Risk to the Board and Business Leaders appeared first on ThreatConnect | Smarter Security for Maximum Impact.