Attributing Organizational Goals with Intelligence Initiatives

Intelligence initiatives enable you to attribute threat intelligence and efforts to larger organizational goals. Intelligence initiatives focus efforts related to specific goals by centralizing related threat intelligence feeds (known within intelligence initiatives as Collections), import sessions, investigations, rules, sandbox detonations, Threat Model entities, and observables.

The intelligence initiative framework in ThreatStream includes the following initiative types:

Initiative Type Description
Adversary Monitoring Threat actors or groups that pose the greatest threat to public or private enterprises. Threat assessment of adversaries is based on a combination of their sophistication and their volume of activity.
Brand Monitoring Threats to a corporate brand based on observations in open and closed sources. Includes compromises of corporate intellectual property, domains, or credentials; threats to corporate personnel, facilities, or operations; attacks on corporate brands or reputations; and rogue applications.
Domain Monitoring Misuse or compromise of corporate domains. Includes domain names crafted to deceive consumers through variations of legitimate domains or typosquatting, domains that host counterfeit websites that impersonate a legitimate entity, and domains created to support phishing campaigns.
Fraudulent Activity Activities include financial fraud (credit cards, business email compromise, rewards fraud, etc.), bogus applications, identity theft or misuse, and unauthorized access to information systems of facilities.
Geopolitical Threats assessed to be most likely to have significant impact on a global scale, including political, social, criminal, governmental, economic, or environmental events. Examples include conflict/war, cyber attacks, economic sanctions, significant changes in financial markets, and natural disasters.
Malware Intelligence Known or suspected threats from malicious software.
Mobile Threats to mobile communications hardware (Apple, Samsung, etc.), operating systems (iOS, Android, etc.), and applications.
Phishing Attempts to fraudulently acquire access or information by means of impersonation through email or messaging. Includes tactics, techniques, procedures, and impacts of such campaigns. Includes attribution when possible.
Physical Infrastructure Threats or malicious activity against cyber infrastructure, including hardware, software, supply chain components, and both public and private cloud architectures.
Social Media Threats made on social media to corporate brands, personnel, facilities, or reputation. Threats may include malicious comments or explicit threats.
Threat and Risk Analysis Threats to an organization mapped against known defensive tools. Threat assessment is based on the known or suspected intent and capabilities of specific threat actors, groups, or TTPs. Risk assessment is based on potential damage.
Vulnerability and Patch Management Known vulnerabilities prioritized by risk. Based on intelligence assessments of potential threats against the current configuration.

Org Admins can create one intelligence initiative of a given type at a time. After marking an intelligence initiative as complete, the initiative is archived and available for export in PDF by members of your organization.

Non Admin users can view and export intelligence initiatives.

You can also monitor intelligence initiatives on the Intelligence Initiatives dashboard. See Viewing the Intelligence Initiatives Dashboard for more information.

Intelligence Requirements

ThreatStream also enables you to leverage specific intelligence requirements. Intelligence requirements function as secondary intelligence initiatives. Available intelligence requirements are listed below.

Initiative Type Available Intelligence Requirements
Adversary Monitoring
  • Pre-attack tactics

  • Post-attack tactics

  • Physical attack techniques against systems

  • Insider threat tactics

  • Information compromise or disclosure tactics

Fraudulent Activity
  • Fraud supply chain monetization

  • Compromised data or access

  • Account takeover

  • Social engineering

Geopolitical
  • All sectors and industries

  • All geographic regions

Malware Intelligence
  • Malware variants

  • Malware-as-a-service

  • Malware development, support, and delivery

Physical Infrastructure
  • Infrastructure-as-a-service

  • Legitimate infrastructure repurposed for malicious activity

  • Dedicated criminal infrastructure

Vulnerability and Patch Management
  • Vulnerabilities

  • Exploit development

To add an intelligence requirement to an intelligence initiative, hover over the intelligence initiative of interest and click the add symbol.

Additionally, you can select the intelligence initiative of interest and then click Add Intelligence Requirement in the Actions menu.

When you add an intelligence requirement to a primary intelligence initiative, the intelligence requirement inherits the Start and End dates from the intelligence initiative and can be completed independently of the primary intelligence initiative.

Note: Read Only users cannot view or export intelligence initiatives.