Threat Intelligence should not be about receiving another report telling you what is happening somewhere on the internet. It should tell you what is relevant to your organisation and what you can do about it. At XMON we approach Threat Intelligence from the same philosophy we use in our Red and Purple services: understand how attackers think, understand how they operate and use that knowledge to improve your defense.
That means our starting point is not a generic threat feed. Our starting point is you!
Your organisation, your people, your technology and the information an attacker can find and use against you.
Sometimes you just need to know where you stand.
XMON can perform a one-off Threat Intelligence assessment where we investigate your organisation from an adversary perspective and translate our findings into practical scenarios for Red/Purple Teaming, detection and risk management.
But Threat Intelligence becomes more powerful when it is continuous.
As a service, we can run the CARs cycle continuously and embed Deception Engineering into your environment.
Threat Intelligence only matters when it helps you make better decisions and take action.
That is why XMON uses our CARs model: Collate, Analyse and Respond.
CARs turns Threat Intelligence from information about the threat landscape into intelligence about your threat landscape.
We collate information that is relevant to you .
This can be our own or external Threat Intelligence, information about threat actors and their Threat, Tactics Procedures (TTPs), but also information from your own environment.
Collate goes a step further. It means bringing information from different sources together and organizing it so that it can be compared, connected and understood.
We want to understand what an attacker can see, what they might be interested in and how they could approach your organisation.
By introducing controlled deceptive elements into your environment we create taillord information.
Information alone is not intelligence.
We analyse what we have found from an attacker's perspective. Who could target you? Why? Which techniques are realistic? And where could those techniques be successful?
Where possible we connect this to frameworks such as MITRE ATT&CK, allowing the intelligence to be used directly by Red, Blue and Purple teams.
Instead of testing everything, we can help start testing what actually makes sense for your threat landscape.
And then we do something with it.
Intelligence can result in improved detection, changes to controls, a Red Team scenario, Purple Team exercises or input for risk management.
But sometimes we want to take it one step further:
Machine Executable Layer:
Intelligence becomes automated protection
Operational Layer:
Intelligence becomes decisions
Deception tuning:
Intelligence improves future intelligence
Security ecosystem:
Intelligence strengthens the defense community
Knowing that attackers exist isn't particularly useful. Understanding how they might attack you is.
If we understand what an attacker is looking for, we can also give them something to find. With Deception Engineering we introduce controlled deceptive elements into your environment. These can be identities, systems, credentials, information or other assets designed to look interesting from an attacker's perspective. The objective is not simply to deploy another honeypot. We design deception around your environment and the adversaries relevant to you. When someone starts interacting with something they should never have touched in the first place, that becomes a very interesting signal. And because the deception is connected to our Threat Intelligence, we can continuously learn from what we observe.
The objective is not simply to deploy another honeypot.
We design deception around your environment and the adversaries relevant to you.
When someone starts interacting with something they should never have touched in the first place, that becomes a very interesting signal.
Because the deception is connected to our Threat Intelligence, we can continuously learn from what we observe.
Inspired by our approach? Or simply curious about how we handle Threat Intelligence, Deception Engineering and CARs?
We’re always up for a virtual coffee. Give us a call on +31 6 2000 6200 and let’s talk threats.