Anti-Virus Log Analysis Cheat Sheet (v1.5)

Florian Roth published the new version of Anti-Virus Log Analysis Cheat Sheet (version 1.5). I highly recommend to implement monitoring of the events included in this cheat sheet. To my mind, this is the easiest and quickest win and AV logs are one of the first things I hunt whenever I go to a new environment.

The new version has information on :

Continue reading “Anti-Virus Log Analysis Cheat Sheet (v1.5)”

Advertisements

Latest advances in MITRE’s ATT&CK framework

Lots of good stuff going on for MITRE ATT&CK framework. It’s great to see the whole project evolving and stimulating cybersecurity community to better analyse intrusions and actors, enhance controls and active defense activities. See some of the latest updates:

Continue reading “Latest advances in MITRE’s ATT&CK framework”

A Study on Threat Intelligence Platforms (TIPs)

ENISA has released the first comprehensive study on cyber Threat Intelligence Platforms (TIPs) focused on the needs of TIP users, developers, vendors and the security research community.

The study channels its efforts into identifying some of the key opportunities and limitations of existing platforms and solutions, since information exchange formats and tools remain central items on the agenda of the cybersecurity community in general, and particularly of incident responders.

Continue reading “A Study on Threat Intelligence Platforms (TIPs)”

ENISA Report on Tools and Methodologies for CSIRTs and Law Enforcement Collaboration

European Union Agency for Network and Information Security (ENISA) has recently released the report on Tools and Methodologies to Support Cooperation between CSIRTs and Law Enforcement.

The report aims to support the cooperation between CSIRTs – in particular national/governmental CSIRTs – and LEAs in their fight against cybercrime, by providing information on the framework and on the technical aspects of the cooperation, identifying current shortcomings, and formulating and proposing recommendations on technical aspects to enhance the cooperation.

Continue reading “ENISA Report on Tools and Methodologies for CSIRTs and Law Enforcement Collaboration”

ENISA Threat Landscape 2016

The ENISA Threat Landscape 2016 is out! This is the annual report published by ENISA that provides useful insights on the cyber threats observed during the past year. Apart from the top cyber threats, the report provides information on threat actors and major attack vectors observed. Finally, the conclusion section provides a collection of issues that will challenge the cyber-security community in the coming months/year in various degrees of intensity.

Some highlights of the report are the following ones:

  • Cyber Threat Intelligence and ETL – “Cyber Threat Intelligence: State-of-play” and the “CTI Big Picture
  • Threat Agents – “Trends” and “Top threat agents and motives
  • Conclusions – “Main cyber-issues ahead” and “Conclusions

Read below the executive summary of the report:

Continue reading “ENISA Threat Landscape 2016”