The Art of Pivoting - Techniques for Intelligence Analysts to Discover New Relationships in a Complex World
This book explores how intelligence and cyber-security analysts can uncover hidden links between threat actor infrastructure and ongoing investigations by pivoting on both classic and unconventional indicators — many of which are often overlooked.
The material is grounded in empirical, field-tested strategies used in cyber-security, digital forensics, cyber threat intelligence, and intelligence analysis more broadly.
Our goal is to provide analysts with a practical toolkit of analytical methods, supported by real-world examples, to enhance investigative workflows without locking them into a single mindset, strict model, or overly rigid technical strategy.
Instead, the book encourages creative exploration, data-driven reasoning, and the use of diverse data points — from traditional IOCs to subtle metadata traces — as part of a flexible and repeatable analytical process.
#threathunting
https://t.co/IiXTV6p2yY
🔒✨ ¡Prepárate para la #CybersecurityWeek!
Del 4 al 8 de noviembre, descubre cómo proteger tu información digital a través de 10 expertos en ciberseguridad.
📍Sala Mirador – Edificio CEDES en Campus Monterrey
¡Transforma tu seguridad digital! 🚀💻
This is awesome. Our teams have fake tenants as honeypots that look like real ones—they contain realistic-looking data with realistic-looking users. But they’ve taken honeypots to a whole new level.
They’re not just waiting for someone to fall into the trap. They actively search for phishing sites and fill in real login credentials of users from these tenants. Then they track how attackers misuse these credentials—what activities they perform, how they proceed, where they come from, etc. And they use this information to populate our TI databases and improve detections. Super cool!
https://t.co/2PZmUZP8Tk
New tool published which is proving to be useful. Cred1py allows execution of the CRED-1 SCCM attack published by @Raiona_ZA over SOCKS5 UDP by wrapping the awesome https://t.co/vlpvKEVziV from @0xcsandker. Enjoy :) https://t.co/NO7HYTA1PP
At Defcon tomorrow, researchers will reveal a flaw in hundreds of millions of AMD chips they call "Sinkclose," which would let hackers root into some of the most privileged portions of a computer to install virtually undetectable, unfixable malware. https://t.co/lVpdao2jxJ
Folks, the NIST National Cybersecurity Center of Excellence (NCCoE), Microsoft, and 24 other organizations have collaborated to provide you guidance on Zero Trust implementation, including labs from Microsoft for the Microsoft Security products and services.
This is a treasure trove for all things Zero Trust, so bookmark this for future reference.
https://t.co/O7ZCDPe2af
Microsoft says the April 2024 Windows security updates break VPN connections on Windows 11, Windows 10, and Windows Server systems
https://t.co/GeDUktrtn7
Tremendo reporte que debe de ser un "MUST" para los defensores. Aporta desde la experiencia, detalle de cómo la identidad sigue siendo ampliamente explotada durante los ataques de ransomware y cuales son las mejores recomendaciones para la defensa. https://t.co/SsiyFIdtBp