More modern organizations are now developing and maintaining threat intelligence functions to improve their defensive posture. However, for many organizations, implementation of detection
methods is still limited to low levels of the “pyramid of pain.” The end result is that the threat intelligence function is not producing as much value as it could. This presentation will provide practical examples of applying higher-level “pyramid of pain” detection taken from open-source reporting to hunting activities. Applying similar techniques also provides additional benefits to the organization, as it enables the organization to operationalize and collect feedback on more aspects of its threat intelligence functions. Lastly, we’ll present one possible classification and prioritization framework using the Lockheed Martin Cyber Kill Chain.
Keith Gilbert (@Digital4rensics), Security Technologist, Sqrrl/Malformity Labs