Module -2 (Chapter 3)
CYBER THREAT INFORMATION COLLECTION
Level One Threat Indicators - File hashes and reputation data - Technical sources: honeypots and
scanners - Industry sources: malware and reputation feeds. Level Two Threat: Data Feeds - Cyber
threat statistics - reports and surveys - Malware analysis. Level Three: Strategic Cyber Threat
Intelligence - Monitoring the underground - Motivation and intentions - Tactics, techniques, and
procedures
Module -2
CYBER THREAT INFORMATION COLLECTION - Chapter 3 (3 levels)
● Information is not intelligence, but it is the raw material out
of which intelligence is produced through analysis.
● Enterprises today have access to literally terabytes of cyber
threat information in the form of huge databases of logs,
malware signatures, and other indicators of compromise. Yet
most IT groups fail to take advantage of the full range of
information sources available to them.
● This chapter provides an overview of cyber threat information
types grouped into three categories, as shown in Figure
Level 1: Threat Indicators
Level 2: Threat Data Feeds
.
Level 3: Strategic Cyber Threat
Intelligence
.
.
Level 1: Threat Indicators
A threat indicator, or Indicator Of Compromise (IOC),
is an entity that indicates the possibility of an attack
or compromise of some kind. The most common
types are file hashes (signatures),and reputation
data on domains and IP addresses that have been
associated with attacks.
File hashes and reputation data
● A file hash is like a digital fingerprint of a file.
● Malware (e.g., viruses, Trojans, keyloggers) is run through an
algorithm like MD5 or SHA-1, which creates a unique string
(example: 15901ddbccc5e9e0579fc5b42f754fe8).
● If a file on a system matches a known malicious hash, it can be
flagged or blocked.
Reputation Data (Domains/IPs/URLs):
.
● Reputation scores are assigned to websites, IPs, and URLs based on
their behavior.
● High-risk examples include:
○ Malware and spyware sites
○ Phishing and fraud pages
○ Spam
○ Command and control (C&C) servers that manage
○ botnets
○ IP addresses that cannot be traced (the “darknet”)
Technical sources: honeypots & scanners
To create malware signatures, cybersecurity researchers first need to find files infected
by malware circulating in the wild. They do this by creating networks of honeypots,
which are computers that simulate the activities of web servers, email servers, other
systems, and computer users surfing the web.
These sensors collect files and emails that would normally be encountered by
corporate systems and users. Researchers take files that have not been seen before
and examine them using:
● Static analysis – examining the code to uncover program instructions and text
strings associated with malware.
● Dynamic or behavioral analysis – allowing the code to execute and observing
malicious actions.
If either analysis shows the file contains malware, the researchers create a signature.
Determining Domain & IP Address Reputations
Researchers extract URLs from web pages and emails collected by honeypots. They investigate
whether the source domains and websites are under the control of threat actors or have been
compromised by malware.
They also analyze emails found by honeypots for indicators of spam, phishing attacks, or fraud.
Clues include:
● Irregularities in the email header
● Certain keywords and phrases
● Links to known spam and phishing sites
Researchers may also use scanner programs that surf the web and test accessible servers for
signs of compromise and malicious activities.
The results from these analyses are used to assign reputation or risk scores to domains, IP
addresses, and URLs.
Industry Sources: Malware and Reputation Feeds
Most enterprises do not have the resources to run their own threat research
teams. Instead, they get malware signatures and domain reputation data
from different sources, such as:
● Cybersecurity vendors (including antivirus and reputation services)
● Cyber threat intelligence firms
● Independent cybersecurity labs and researchers
● Open source cybersecurity projects, malware and spam
clearinghouses, and real-time blacklist (RBL) providers
● Government and industry groups that share threat data
Some vendors and cyber threat intelligence firms combine data from
multiple sources, making it easier for organizations to access a wide range
of information from a single feed.
Level 2: Threat Data Feeds
-Cyber threat statistics,reports, and surveys
-Malware analysis
What are Threat Data Feeds?
Provide correlated and analyzed threat indicators.
Help security teams identify patterns of attacks.
Include malware analyses to understand how malware behaves, useful
for incident response (IR).
Cyber Threat Statistics, Reports, and Surveys
Statistics
● Offered by industry organizations and cybersecurity vendors.
● Cover data on malware, spam, botnets, etc.
Useful Sources:
● Malware: AV-TEST Institute
● Spam: AV-TEST
● Phishing: APWG (Anti-Phishing Working Group)
Reports and Surveys
● Published by vendors and consulting firms.
● Include:
○ Stats and attack trends
○ Expert analysis
○ Survey results from IT decision-makers
Examples:
● Verizon DBIR – Data breach reports
● Ponemon Institute – Cost of breaches
● Microsoft SIR
● Cisco Security Report
● Symantec Threat Report
Malware Analysis
Purpose:
● Understand malware behavior and attacker intentions.
Technique: Sandboxing(It is a security technique used to safely test and analyze suspicious files (like
malware) in a controlled, isolated environment — without risking the real system.)
● File runs in a virtual environment (safe zone).
● Observes actions like:
○ Modifying the registry
○ Disabling antivirus
○ Searching for files with "admin" or "password"
○ Contacting command & control servers
○ Connecting to data theft servers
Level 3: Strategic Cyber Threat Intelligence
-Monitoring the underground
-Motivation and intentions
-Tactics, techniques, and procedures
Strategic Cyber Threat Intelligence gives insight into:
● Who is targeting your organization
● What threats they pose in the near future
It helps in long-term planning and security posture.
Monitoring the underground
Cybercriminals, cyber espionage agents, and hacktivists have built an entire underground ecosystem where
they collaborate and operate. In this underground world, participants:
● Exchange ideas about targets, strategies, tools, and methods used in cybercrime, cyber espionage, and
hacktivism.
● Share knowledge on creating and using malware, exploits, spear phishing campaigns, DDoS attacks,
and other harmful tools and techniques.
● Plan and coordinate attacks that are driven by ideological or political motives.
● Buy and sell various tools such as exploit kits, weaponized exploits, and tools for evading detection.
● Offer services to other cybercriminals, which can include:
● Specific tasks like designing fake websites or cracking passwords
● Larger operations like hiring hackers, renting botnets, or DDoS-as-a-service
● Trade in stolen digital assets such as:
○ Credit card numbers,Social Security numbers
○ Personal information,Login credentials
● These activities happen through online forums, email, instant messaging, social media, and even fully
functioning online stores.
Contd………
Some of these platforms are open to the public, but the most significant ones are private,
accessible only by invitation, and very difficult for outsiders to access.
If someone were to explore these forums, they would need strong language skills, as
many operate in languages such as Russian, Ukrainian, Mandarin, German, and
Vietnamese. Advanced cybercriminal groups also use strong operational security
practices, making it hard for outsiders to infiltrate. Gaining access might require building
a fake identity and investing significant effort.
Motivation and intentions(Why & What Hackers Plan to Do)
Researchers studying cyber threats can gather valuable information from the online
underground world. One important type of information is about the motivation and intentions of
threat actors.
● Motivation refers to why an attacker wants to carry out a cyberattack.
● Intention refers to what the attacker plans to do and what targets they are interested in.
Cybercriminals
● Their main motivation is profit.
● Their intentions can differ:
○ Some want to steal financial or personal data.
○ Others may focus on attacking specific industries.
contd….
Competitors and Cyber Espionage Agents
● They have diverse motivations, such as:
○ Stealing product designs, intellectual property, and business plans.
○ Learning about bids, proposals, or strategic plans.
○ Collecting political or military intelligence.
Hacktivists
● Their motivations are the most varied, including:
○ Gaining attention or impressing peers.
○ Supporting a cause (e.g., environmentalism).
○ Discrediting individuals or organizations with opposing views.
○ Harassing political or ideological opponents.
○ In extreme cases, trying to shut down part of the economy or infrastructure during political
conflict.
● Their intentions can include:
○ Stealing embarrassing or damaging information.
○ Defacing or disabling websites.
○ Hijacking social media accounts.
○ Disrupting essential services.
Tactics, Techniques, and Procedures(TTP)
Understanding TTPs of adversaries is highly valuable in cybersecurity.
It helps organizations:
● Know what signs to look for to detect cyberattacks early.
● Understand where to strengthen:
○ Security technologies
○ Team capabilities
○ Internal processes
Contd….
Researchers observe adversary behavior online to infer their methods.
Valuable sources of evidence include:
● Discussions on forums and social media about future attack plans and strategies.
● Information exchanges on new exploits and hacking tools under development.
● Purchases of malicious tools and cybercrime services.
● Malware behavior patterns and characteristics of tools being sold.
● Sales of stolen data, such as:
○ Credit card details
○ Personal identity information
○ Other digital assets
Now our attention to how they convert that information into useful intelligence.