Attributing Organizational Goals with Intelligence Initiatives
Intelligence initiatives enable you to attribute threat intelligence and efforts to larger organizational goals. Intelligence initiatives focus efforts related to specific goals by centralizing related threat intelligence feeds (known within intelligence initiatives as Collections), import sessions, investigations, rules, sandbox detonations, Threat Model entities, and observables.
The intelligence initiative framework in ThreatStream includes the following initiative types:
| Initiative Type | Description |
|---|---|
| Adversary Monitoring | Threat actors or groups that pose the greatest threat to public or private enterprises. Threat assessment of adversaries is based on a combination of their sophistication and their volume of activity. |
| Brand Monitoring | Threats to a corporate brand based on observations in open and closed sources. Includes compromises of corporate intellectual property, domains, or credentials; threats to corporate personnel, facilities, or operations; attacks on corporate brands or reputations; and rogue applications. |
| Domain Monitoring | Misuse or compromise of corporate domains. Includes domain names crafted to deceive consumers through variations of legitimate domains or typosquatting, domains that host counterfeit websites that impersonate a legitimate entity, and domains created to support phishing campaigns. |
| Fraudulent Activity | Activities include financial fraud (credit cards, business email compromise, rewards fraud, etc.), bogus applications, identity theft or misuse, and unauthorized access to information systems of facilities. |
| Geopolitical | Threats assessed to be most likely to have significant impact on a global scale, including political, social, criminal, governmental, economic, or environmental events. Examples include conflict/war, cyber attacks, economic sanctions, significant changes in financial markets, and natural disasters. |
| Malware Intelligence | Known or suspected threats from malicious software. |
| Mobile | Threats to mobile communications hardware (Apple, Samsung, etc.), operating systems (iOS, Android, etc.), and applications. |
| Phishing | Attempts to fraudulently acquire access or information by means of impersonation through email or messaging. Includes tactics, techniques, procedures, and impacts of such campaigns. Includes attribution when possible. |
| Physical Infrastructure | Threats or malicious activity against cyber infrastructure, including hardware, software, supply chain components, and both public and private cloud architectures. |
| Social Media | Threats made on social media to corporate brands, personnel, facilities, or reputation. Threats may include malicious comments or explicit threats. |
| Threat and Risk Analysis | Threats to an organization mapped against known defensive tools. Threat assessment is based on the known or suspected intent and capabilities of specific threat actors, groups, or TTPs. Risk assessment is based on potential damage. |
| Vulnerability and Patch Management | Known vulnerabilities prioritized by risk. Based on intelligence assessments of potential threats against the current configuration. |
Org Admins can create one intelligence initiative of a given type at a time. After marking an intelligence initiative as complete, the initiative is archived and available for export in PDF by members of your organization.
Non Admin users can view and export intelligence initiatives.
You can also monitor intelligence initiatives on the Intelligence Initiatives dashboard. See Viewing the Intelligence Initiatives Dashboard for more information.
Intelligence Requirements
ThreatStream also enables you to leverage specific intelligence requirements. Intelligence requirements function as secondary intelligence initiatives. Available intelligence requirements are listed below.
| Initiative Type | Available Intelligence Requirements |
|---|---|
| Adversary Monitoring |
|
| Fraudulent Activity |
|
| Geopolitical |
|
| Malware Intelligence |
|
| Physical Infrastructure |
|
| Vulnerability and Patch Management |
|
To add an intelligence requirement to an intelligence initiative, hover over the intelligence initiative of interest and click the add symbol.
Additionally, you can select the intelligence initiative of interest and then click Add Intelligence Requirement in the Actions menu.
When you add an intelligence requirement to a primary intelligence initiative, the intelligence requirement inherits the Start and End dates from the intelligence initiative and can be completed independently of the primary intelligence initiative.
Note: Read Only users cannot view or export intelligence initiatives.