Threat Intelligence Fundamentals: Detecting Hacker Tactics and How Autofocus Works

Опубликовано: 16 Июль 2026
на канале: Denis Batrankov
1,405
41

00:00:00 What are popular presentation topics in the information security world?
00:05:24 What is Kill Chain?
00:08:04 Anunak attack - 1 billion rubles stolen
00:10:26 People + processes + technologies
00:10:52 Red Team tests the effectiveness of protection
00:10:46 Blue Team defends
00:12:21 Purple Team coordinates red and blue teams
00:13:04 345 Read Team tips https://www.vincentyiu.com/red-team-tips
00:14:54 What is Threat Intelligence?
00:19:10 What TI Feeds look like and the indicators they contain (IoC)
00:21:25 Free IPSUM feeds https://github.com/stamparm/ipsum
00:22:50 How to extract IoC from a PDF https://github.com/PaloAltoNetworks/i...
00:23:20 STIX, TAXII, CyBOX, MAEC, OpenIOC Exchange Formats
00:24:31 IoC Problems
00:26:34 Attribution
00:28:50 Adversary - Attackers
00:29:20 Tactics, Techniques, Procedures (TTP)
00:30:49 Adversary Playbooks
00:32:57 MITRE ATT&CK
00:37:07 Summary: Adversary-Campaigns-TTP-IoC
00:39:48 Where can I get all this information? Autofocus and Minemeld
00:43:20 Assessing how protection works based on TTP knowledge
00:44:44 How SOC uses TI
00:45:16 Autofocus TIP
01:05:54 What's the difference between TIPs
01:07:35 Integrating IoCs from a sandbox into TI and NGFW
01:18:50 The Minemeld utility
01:19:20 External Dynamic Lists (EDL) in Palo Alto Networks
01:27:59 What IoC indicators do sandboxes generate?
01:28:56 Cortex XDR
01:33:24 BIOC Rules
01:35:40 Answers to questions

An example of an adversary playbook created by Palo Alto Networks researchers for Cobalt
https://pan-unit42.github.io/playbook...

An interesting video worth watching – comparing MITRE and FSTEC techniques and tactics    • Mapping - соответствие техник и тактик ФСТ...