@chroniclesec and @virustotal have released a behemoth guide to advanced tools and use cases on https://t.co/20sjgkn4ug (warning, its a 155 page PDF with my notes)
@HostileSpectrum@BrianPKime@jckichen In #threatintel we have to accept that we work with limited visibility during our collection efforts. If I can affect this effort in a positive way and reduce uncertainty I will for sure try to do that first
@markus_neis@BrianPKime@jckichen Credential recovery is generally either result of limited conception of intel as an activity by cyber threat intel vendors racing towards the commodity threshold, or the opportunistic byproduct of other more purposeful collection. Either way it should not be reason for engagement
@BrianPKime@jckichen This in turn affects the Preparation of the Cyber Environment and my collection efforts as I have a better defined focus what I need to collect and where it affects my network. In the end its nice to understand the battlefield but ultimately we want to win War :)
@BrianPKime@jckichen From that perspective I want to take away the adversaries opportunity to leverage those leaked credentials and enforce 2FA for suppliers as trying to fight on the capability side (collection of leaked credentials) is limited in efficacy and implementation.
Another year has passed and lots of good CTI/DFIR stuff have been presented! I took some time to watch again some of my favourite talks within 2018 and list my favourite 20 ones. I hope you enjoy it!
https://t.co/FoSDhP2550 #dfir#cti#ThreatIntel#CyberSecurity#infosec#apt
@cem_oezdemir Genau, die sollten sich mal an der deutschen Politik ein Beispiel nehmen. Den Karren gegen die Wand fahren, bis nichts mehr geht und trotzdem fröhlich weitermachen.