Threat-Intelligence-Tradecraft
Threat-Intelligence-Tradecraft copied to clipboard
Threat Intelligence Tradecraft
This is a work in progress
Intent:
- Create an opensource/free curriculum for learning threat intelligence tradecraft to include:
- 1: Cyber Threat Intelligence and Requirements
- 2: Intrusion Analysis
- 3: Collection Sources
- 4: Analysis and Dissemination of Intelligence
- 5: Higher-Order Analysis and Attribution
- Note: I plan on heavily modeling after/emulating content from commercially available courses
Short Term Goals:
- Utilize entirely free (as in beer) or OSS tools
- Deliver via step by step guides, articles,presentations
- ETA: ~June 2018 (no real idea when this will be done)
Long Term Goals:
- Develop Vagrantfile/VM for module exercises
- Develop MOOC format using openedX with tests
Super Long Term Goals:
-
Host Website with MOOC
-
Create booklet/document format to be used as a digital or printable portable guide
-
Develop Videos (maybe)
-
Contact: If you would like to help me in this project please shoot an email to: [email protected]
Resources:
- http://www.cyintanalysis.com/resources/
- https://github.com/corumir/Practical-Tradecraft
- https://github.com/hslatman/awesome-threat-intelligence
Curriculum:
1: Cyber Threat Intelligence and Requirements
- E01-Using Structured Analytical Techniques
- E02-Consuming Along the Sliding Scale
- E03-Enriching and Understanding Limitations
- E04-Strategic Threat Modeling
2: Intrusion Analysis
- E05-Using Structured Analytical Techniques
- E06-Consuming Along the Sliding Scale
- E07-Enriching and Understanding Limitations
- E08-Strategic Threat Modeling
3: Collection Sources
- E09-Open-Source Intelligence and Domain Pivoting in DomainTools
- E10-Maltego Pivoting and Open-Source Intelligence
- E11-Sifting Through Massive Amounts of Open-Source Intelligence in RecordedFuture
- E12-TLS Certificate Pivoting
- E13-Storing Threat Data and Information in a Malware Information Sharing Platform (MISP)
4: Analysis and Dissemination of Intelligence
- E14-Analysis of Competing Hypotheses
- E15-Visual Analysis in Maltego
- E16-The Rule of 2
- E17-YARA Rule Development
- E18-STIX Framework IOC Extraction and Development
- E19-Building a Campaign Heat Map