Bolstering Your Security Controls Against COVID-19

Due to an increase in targeted COVID-19 related attacks on organizations and network infrastructures, Anomali is ensuring that the threat intelligence community members have the ability to rapidly receive intelligence from Anomali ThreatStream and distribute it among peers in this community.

ThreatStream has the following resources, features, and tools available for you to understand and analyze the latest threat intelligence and automate its ingestion in your downstream security controls and integrations.

It is strongly recommended that you leverage all of these resources and the latest threat intelligence on ThreatStream to ensure the best possible defense for your infrastructure. Additionally, review your current filters to ensure COVID-19 specific threat intelligence is properly forwarded and ingested into your downstream integrations and other security controls.

Threat Bulletin and Campaign

The Anomali Threat Research team has issued the following Threat Bulletin and Threat Campaign about cyber threats related to COVID-19:

These threat models are associated with observables, sandbox analysis reports, and other related threat models thus allowing you to obtain the latest threat intelligence from one central location and ingest it into your downstream integrations through Integrator, match against your event logs on Anomali Match, and ingest into your Splunk instances to automatically scan events in Splunk against the observables associated with the bulletin.

The Threat Bulletin and the Threat Campaign are automatically available to you in human-readable and machine-readable forms if you have purchased the Anomali Labs Premium Feed from the ThreatStream APP Store.

Trusted Circles

Anomali recommends joining the following Public Trusted Circles on ThreatStream. For information on joining a trusted circle, see Joining a Trusted Circle.

Trusted Circle Trusted Circle ID
OSINT News & Other Reports 10983
OSINT Threat Reports 10977
OSINT Vulnerability Reports 10982
Twitter - APT 11053
Twitter - Compromised Accounts 10980
Twitter - Compromised Sites 10981
Twitter - Malware 10979
Twitter - Social Engineering & Phishing 10978

Note: The Trusted Circle ID links will only work once your organization has joined them.

Once your organization joins these trusted circles, the following example queries can be used to view the latest COVID-19 specific threat intelligence available from these trusted circles:

Observables in the above trusted circles in the last 30 days (adjust the date in the following query accordingly):

https://ui.threatstream.com/search?status=active&created_ts__gte=2020-02-21T18:02:14.177Z&trustedcircles=10983,10977,10980,10981,10979,10978&value__re=.*coronavirus.*

Threat Models in the above trusted circles in the last 30 days (adjust the date in the following query accordingly):

https://ui.threatstream.com/threatmodels?trusted_circle_ids=10980,10981,10979,10978,10983,10977,10982&modified_ts__gte=2020-02-21T00:00:00.000Z

My Events Map (customized to COVID-19 matches)

Anomali recommends enabling the My Events Map to visualize threats tagged with COVID-19 specific threat information from around the world.

To create a My Events Map for COVID-19:

  1. Create a Saved Search:
    1. Navigate to Analyze > Observables.
    2. Click Advanced.
    3. Enter this in the search text box:

      (type="ip" or type="ipv6" or type="domain") and (status="active") and (value contains "COVID-19" or tags contains "COVID-19")
    4. Click Filter: Save as.
    5. Enter a name for the new filter. For example, COVID-19 or CoronaVirus.
    6. Click Save.
  2. Click Dashboard > My Events.
  3. Click Recent Intelligence at the lower right corner of the map to locate the saved search you created earlier.
  4. Select the saved search (for example, CoronaVirus).

    The My Events Map will start populating with threat intelligence related to COVID-19.

My Alerts - Rules

Configuring rules enables your organization to take automated actions when specific keywords appear in newly created Threat Bulletins, Sandbox Reports, Signatures, Vulnerabilities, or recently imported observables.

Actions you can take are: tag the threat intelligence with additional terms, associate the intelligence to a specific threat model, or add the intelligence to an investigation.

To create a rule specific to COVID-19, follow instructions in Creating Rules and use the following recommendations for parameter values. It can take up to five minutes for a newly created rule to start matching keywords.

Field Description
Name COVID-19, or another name of your choice.
Match Within

Keep all of these checked:

  • Observables
  • Sandbox Reports
  • Signatures
  • Threat Bulletins
  • Vulnerabilities
Keywords

Suggested keywords:

covid*19

corona*virus

Add additional keywords to suit your needs. Keywords must adhere to the guidelines detailed in Keyword Syntax Requirements.

Indicator Types

Accept the default value: Match All

Exclude

Leave unchecked

Add Action

Select the following automated actions to take when keywords match within the selected intelligence types.

  • Tag with Terms: Add tags to intelligence in which the keywords appear. For example, coronavirus, covid-19.

    To add private tags that are only visible to your organization, assign them the My Organization visibility setting. Tags assigned the Anomali Community visibility setting are visible to any user with access to the entity.

  • Add to Investigation: (Optional) Create a dedicated investigation the first time the rule is triggered. All intelligence in which keywords appear are added to the investigation.
Exclude from notifications

Leave unchecked

The My Alerts widget on ThreatStream Overview Dashboard displays the recently triggered rules and corresponding automated actions taken by ThreatStream. Additionally, you can view the type of intelligence the rule matched, any enrichments, add to an investigation, export in multiple formats, clone and share within the community on the Viewing Rule Details page.

Chat - COVID-19

Anomali has created a designated Chat channel for anonymous collaboration and discussion on threat intelligence related to the COVID-19 pandemic. Additionally, the Anomali Threat Research team uses the Chat channel to share breaking news and threat intelligence updates. However, the channel is not a forum for asking questions of the Threat Research team directly.

In order to access the COVID-19 Chat channel, you must join the invite only Anomali News Chat Trusted Circle. Contact your Customer Support representative to gain access.

After joining the Trusted Circle, you can launch the COVID-19 chat channel by opening the "anomalinewschat" chat room.

For more information on using ThreatStream Chat, see Collaborating with ThreatStream Chat.