Maltego KungFu Exploiting Open Source Threat Intelligence OSINT To Gain Strategic Advantage Over You

Опубликовано: 27 Сентябрь 2024
на канале: SANS Digital Forensics and Incident Response
9,743
111

Matt Kodama, VP, Recorded Future

There exists on the open web, an entire universe of valuable open source intelligence (OSINT) containing Analysis on
malicious code and infrastructure as well as key indicators of compromise (IOCs) and techniques tactics and procedures
(TTPs) associated with specific threat actors or groups of actors, be they organized gangs of underground cyber criminals,
terrorist organizations or foreign nation-state sponsored espionage campaigns. In the world of Cyber Threat intelligence,
misattribution, confusion, false information and collusion, inadequate collection tools and techniques are often the adversary’s greatest strength in their persistent attempt to successfully conduct malicious attacks and campaigns targeting private companies, government organizations and the general public at large.

Discovering and validating new and relevant IOCs and TTPs to strengthen your cyber threat intelligence operation can be a
daunting and time consuming task, especially in a world where such gems are often closed source, isolated to specific data
sets and costly to consume and maintain.

In this talk, Matt will demonstrate and provide a step-by-step walkthrough of how threat analysts can use Maltego and other
tools in an optimal way to reduce the time it takes to extract, correlate and make insightful, valuable cyber OSINT data living
on the open web. Additionally the talk will focus on how data collected can be used to enhance detection and monitoring
content on the internal network so Security Operations can gain leverage on the adversary who seeks to do you harm.