Cyber Threat Intelligence Service
See the threats forming against your organisation outside your perimeter: dark web monitoring, leaked credentials, lookalike domains, phishing infrastructure and external attack surface intelligence.
What Is Cyber Threat Intelligence?
Cyber threat intelligence is the process of detecting, analysing and interpreting the current and potential cyber threats targeting an organisation, and turning them into actionable security information.
Where classic security products largely try to detect threats that have already reached the organisation's network or systems, a threat intelligence approach aims to see the threat at the earliest possible stage.
Cyber threat intelligence is therefore not limited to analysing logs from inside the organisation.
Open sources on the internet, threat actor activity, malicious infrastructure, lookalike domains, dark web platforms, leaked user credentials, data breaches, malicious IP addresses, domains and other threat indicators can all be assessed to reveal risks that are meaningful for the organisation.
The SecureSys cyber threat intelligence service aims to detect and prioritise, at an early stage, the external threats directed at an organisation's digital assets, brand, employees, customers and critical systems.
The fundamental question behind cyber threat intelligence is this:
"Which threats targeting our organisation are forming in the outside world, and which of them represent a genuine risk to us?"
Why Is Cyber Threat Intelligence Necessary?
Modern cyber attacks often do not begin with the attacker connecting directly to the target systems.
Attackers gather information about the target organisation first.
Employee names, email addresses, the technologies in use, internet-facing systems, the domain structure, third-party services and previously leaked credentials can all be used in preparing an attack.
An employee's corporate email address and password may, for example, have been exposed in a past third-party data breach.
If the user uses the same or a similar password on corporate systems, that information becomes a direct opportunity for access.
Similarly, a new domain resembling the organisation's brand can be registered and used to send phishing emails to its customers.
A significant proportion of these events take place outside the organisation's own security systems.
Monitoring internal security controls such as firewalls, EDR or SIEM alone may therefore not be sufficient.
Cyber threat intelligence services help the organisation monitor its external digital threat landscape as well.
SecureSys Cyber Threat Intelligence Service
SecureSys provides professional cyber threat intelligence services for monitoring and analysing organisations' external threat environments and identifying priority risks.
Depending on the organisation's risk profile, the work can consist of components such as:
dark web monitoring, credential leak monitoring, brand monitoring, domain monitoring, attack surface intelligence, IOC monitoring, data leakage tracking, phishing tracking and threat actor analysis
The aim is not to collect as much data as possible from the internet.
The real aim is to identify the information that carries genuine security value for the organisation and turn it into something technical teams or managers can act on.
Context is therefore critical in threat intelligence.
An IP address flagged as malicious may mean nothing to the organisation on its own.
But if that same IP is seen attacking the organisation's VPN service, the information turns directly into operational security value.
What Is Cyber Threat Intelligence (CTI)?
Cyber Threat Intelligence – CTI is the analysis of raw data about cyber threats and its conversion into contextualised security information on which decisions can be based.
Threat intelligence is not simply a matter of sharing lists of IP addresses, domains or hashes.
Genuine intelligence has to be able to answer the following questions:
Who is the threat coming from?
Which systems is it targeting?
Which techniques does it use?
Why does it matter to the organisation?
Which systems need to be checked?
Which security measures should be taken?
There is therefore an important difference between raw threat data and actionable threat intelligence.
Types of Cyber Threat Intelligence
Cyber threat intelligence can be addressed at different levels.
Strategic Cyber Threat Intelligence
Strategic intelligence largely contains assessments aimed at senior management and security leadership.
Threat actors targeting the sector, rising attack trends, geopolitical risks and the general threat landscape the organisation faces can all be assessed at this level.
The aim is to provide the information that will shape the organisation's cyber risk strategy, rather than technical detail.
Tactical Cyber Threat Intelligence
Tactical intelligence focuses on the tactics, techniques and procedures – TTPs that attackers use.
If it is known that a particular threat actor gains initial access through phishing and then uses credential dumping and lateral movement techniques, for example, the organisation can develop its defence around that attack chain.
MITRE ATT&CK is one of the important references used to model this kind of attacker behaviour.
Operational Cyber Threat Intelligence
Operational intelligence contains information about specific or imminent threat campaigns affecting the organisation.
Information that a particular sector is being targeted by a new ransomware campaign, for example, can be treated as operational threat intelligence.
This information can help the organisation's SOC and security teams strengthen defensive controls in advance.
Technical Cyber Threat Intelligence
Technical intelligence can cover threat indicators that can be used directly in security systems.
These can include:
malicious IP addresses, domains, URLs, file hashes, email addresses and other indicator of compromise (IOC) values
These indicators can be used for checking or blocking in SIEM, EDR, firewall, email security or other security products.
What Is Dark Web Monitoring?
Dark web monitoring is the threat intelligence activity of monitoring whether sensitive information relating to the organisation is being shared on dark web platforms, illegal marketplaces, forums and similar sources.
Attackers can put the information they obtain up for sale on various platforms or share it for free.
This can include:
usernames and passwords, email addresses, customer information, database dumps, access credentials, company documents and remote access accounts
Dark web monitoring allows the organisation to detect leaked information relating to it at an earlier stage.
Finding the data is not sufficient on its own, however.
How current the information is, its source, its accuracy and the real risk it creates for the organisation all have to be assessed.
What Is Credential Leak Monitoring?
Credential leak monitoring is the tracking of whether usernames, email addresses and passwords belonging to the organisation's employees or system accounts have been leaked on the internet.
Credential leak incidents may not originate with the organisation itself.
An employee may have been caught up in a data breach at a third-party service they used with a personal account.
If the user also uses the same password on a corporate system, however, an attacker can try those credentials in a credential stuffing attack.
Detecting leaked credentials early is therefore important.
Once detected, actions such as the following can be taken:
changing the password, verifying MFA, reviewing the accounts concerned and checking for suspicious sign-in records
Infostealer Log Monitoring
In recent years, one of the significant sources of credential leakage has been infostealer malware.
This malware can capture the following from user computers:
browser passwords, cookies, session tokens, crypto wallets and other credentials
The information collected can be shared on attacker forums or data marketplaces.
Monitoring credential risk from infostealers, not only classic data breach lists, has therefore become important.
Where user accounts belonging to the organisation's domain appear in leaks of this kind, the accounts concerned may need to be assessed quickly.
Brand Monitoring
Cyber attackers do not target only an organisation's technical systems.
The organisation's brand can also be used for the purposes of an attack.
Brand monitoring aims to monitor the misuse of the organisation's name, trademarks, product names and digital identity.
Attackers may, for example, build a fake site closely resembling the organisation's official website.
That site can then be used to try to capture customers':
usernames, passwords, payment card details or personal information
Even though the system under attack is not the organisation's own infrastructure, the incident can still be associated with the organisation in the user's eyes.
Brand monitoring is therefore also part of protecting corporate reputation.
Lookalike Domain Detection
One of the most common methods in phishing attacks is registering domain names that resemble the corporate domain.
An attacker may, for example, change a letter within the domain, add a letter, use a similar-looking character or register a different extension.
This method is frequently seen in typosquatting and domain impersonation attacks.
Threat intelligence work can track new domain registrations resembling the organisation's main domain.
When a suspicious domain is detected, the following can be assessed:
whether the domain is active, which IP it is hosted on, its SSL certificate, its web content and whether it is intended for phishing
Phishing Site Monitoring
Attackers can create fake websites by copying the organisation's login screens, customer portals or e-commerce pages.
The purpose of these sites is usually to capture user credentials.
Threat intelligence work aims to detect phishing pages imitating the brand or the domain as early as possible.
Once a suspicious site is confirmed, the organisation's incident response and legal processes can be initiated.
Where necessary, takedown processes can be started by contacting hosting providers or the relevant services.
What Is Attack Surface Intelligence?
An organisation's assets on the internet change continuously.
New servers can be deployed, test environments can be exposed to the internet, new domains can be created, or forgotten systems can keep running.
Attack surface intelligence focuses on identifying and tracking the organisation's externally visible digital attack surface.
This can include:
IP addresses, domains, subdomains, internet services, web applications, certificates and cloud resources
This approach makes it possible to identify systems that are not in the security team's inventory but are visible to attackers.
Assets of this kind are generally part of shadow IT or unknown external asset risk.
Cyber Threat Intelligence With External Attack Surface Management
External Attack Surface Management – EASM aims to discover the organisation's internet-visible assets continuously and assess them for security risk.
Used together, threat intelligence and EASM provide stronger external threat visibility.
An EASM system may detect a forgotten server exposed to the internet, for example.
Threat intelligence may then show that the software version running on that server has a vulnerability under active exploitation.
Combining the two pieces of information can produce a high-priority security risk for the organisation.
What Is an IOC?
An IOC – indicator of compromise is a technical indicator that a system or network may be associated with malicious activity.
Examples of IOCs include:
IP addresses, domains, URLs, file hashes, email addresses and certain file or process indicators
IOCs can be queried in security systems to search for traces of specific threats in the organisation's infrastructure.
When a list of malicious domains associated with a new ransomware campaign is obtained, for example, the organisation's DNS or proxy logs can be checked for access to those domains.
What Is IOC Enrichment?
Raw IOC data is often not sufficient on its own.
IOC enrichment is the enrichment of a threat indicator with additional information.
For an IP address, for example, the following can be examined:
which country it belongs to, which ASN it sits on, which attacks it has been associated with in the past and which domains it is connected to
This information can help SOC analysts assess an alert more quickly.
Threat Intelligence and SIEM Integration
One of the most important applications of threat intelligence is integration with SIEM systems.
IOCs obtained from threat intelligence sources can be compared against logs within the SIEM.
Seeing a connection to a known malicious IP address in the organisation's firewall logs, for example, can generate an alert.
Similarly, known malicious domains appearing in proxy or DNS logs can be passed to the SOC team.
This approach takes threat intelligence beyond passive reporting and makes it part of an active security operation.
Threat Intelligence and EDR/XDR
EDR and XDR platforms monitor endpoint behaviour in order to detect malicious activity.
Threat intelligence data can help make sense of the events seen in these systems more quickly.
Establishing that a file hash seen on an endpoint is associated with a known malware campaign, for example, can raise the priority level of the event.
Building strong integration between CTI, the SOC and endpoint security is therefore important.
Cyber Threat Intelligence and the SOC
Threat intelligence data provides valuable context for SOC teams.
To decide whether an alert represents a genuine threat, an analyst may need not only the log record but also the threat context behind the event.
Failed VPN logins on their own, for example, may look like ordinary user error.
If the login attempts are found to be coming from known botnet infrastructure, however, the event is assessed very differently.
Integration of:
SOC + SIEM + threat intelligence
can therefore strengthen an organisation's detection capability.
MITRE ATT&CK and Threat Intelligence
The attack techniques used by threat actors can be mapped to MITRE ATT&CK.
If the initial access, credential access and lateral movement techniques a particular attacker group favours are known, for example, the organisation can assess its defence against those techniques.
This approach delivers value particularly in detection engineering and purple team work.
Threat intelligence should be able to answer not only "who is attacking?" but also "how are they attacking?"
Data Leakage Monitoring
An organisation's data can leak onto the internet for a range of reasons.
Misconfigured systems, third-party data breaches, malware or attacks can all be the source.
Threat intelligence work can search for data leakage signals using the organisation's name, domain, email suffix and other defined keywords.
Once the authenticity of the content found is verified, the organisation's incident response process can be initiated.
Third-Party and Supplier Risk
An organisation's security does not depend on its own infrastructure alone.
Suppliers, business partners and external service providers can also be part of the attack surface.
Rather than targeting a well-protected organisation directly, attackers may try to reach it by compromising a supplier with a weaker security posture.
This approach is seen in supply chain attack scenarios.
Cyber threat intelligence services can also help assess specific threat signals relating to the organisation's critical business partners.
Executive and VIP Monitoring
High-profile executives can be important targets for attackers.
The names of CEOs, CFOs, board members and employees with critical authority can be used in:
fake social media accounts, phishing campaigns and business email compromise attacks
Brand and identity monitoring can be carried out for the critical individuals identified within scope.
Monitoring of this kind is particularly important in organisations facing a high risk of targeted attack.
Business Email Compromise – BEC Risk
Business email compromise is an attack in which attackers impersonate an organisation's executives or suppliers in order to have a financial transaction carried out.
An attacker may, for example, send an urgent payment instruction to the accounts team from an email address impersonating the CFO.
These attacks do not always use malware or a technical vulnerability.
Misusing the brand, employee information and the corporate communication structure can be enough.
Threat intelligence and domain monitoring work can help detect early the fake domains that could be used in BEC attacks.
Ransomware Intelligence
Ransomware groups no longer limit their attacks to encrypting files.
Many groups steal data from the organisation before encrypting it and threaten to publish it if payment is not made.
Threat intelligence work can track the activity of specific ransomware groups against particular sectors and the data leak announcements they publish.
The appearance of the organisation or its critical business partners in these sources should be treated as a significant security alert.
How Does the Cyber Threat Intelligence Process Work?
1. Defining Intelligence Requirements
Which information matters to the organisation is established first.
Domains, brands, critical employees, product names and other digital assets can be brought into scope.
2. Data Collection
Relevant data is collected from open sources and from the threat sources within scope.
3. Filtering
Data that is irrelevant to the organisation is separated out.
4. Analysis
The accuracy and currency of the information obtained, and the risk it creates for the organisation, are assessed.
5. Prioritisation
Critical threats are separated from the other signals.
6. Notification
Events requiring urgent action are passed to the relevant security teams.
7. Reporting
Periodic threat intelligence reports can be prepared.
8. Follow-Up
Open risks and the associated threat indicators continue to be monitored.
What Does a Cyber Threat Intelligence Report Contain?
A threat intelligence report should be more than a list of links found on the internet.
The report can present:
the threat detected, its source, its verification status, the digital asset affected, the risk level, the possible attack scenario and the recommended actions
When a leaked corporate account is detected, for example, the report should not contain only the username.
It should also state:
the source from which the information was obtained, how current it is, whether password data is included and which actions need to be taken
The Importance of Real-Time Alerting
For some threat intelligence events, waiting for a monthly report is not appropriate.
An active phishing site or a newly leaked administrator account, for example, may require rapid response.
Event-based notification mechanisms can therefore be used when critical threats are detected.
Security teams can then act before the risk grows.
The Benefits of Cyber Threat Intelligence
Threat intelligence does not simply provide organisations with additional data.
Applied correctly, it can help with:
detecting threats early, enabling SOC teams to decide faster, finding leaked accounts, reducing phishing attacks, monitoring digital brand risks and understanding the external attack surface better
Threat intelligence allows security teams to act more proactively against approaching threats, rather than only reacting to events that have already happened.
Which Organisations Is Cyber Threat Intelligence Important For?
Threat intelligence can be an important security layer for organisations that deliver services over the internet, hold significant brand value or process sensitive data.
The following in particular can benefit from continuous monitoring of the external threat environment:
financial institutions, public bodies, defence industry companies, energy organisations, e-commerce companies, telecommunications firms, holding companies and technology companies
A similar approach is worth considering in any organisation facing brand impersonation or customer phishing risk.
Is Cyber Threat Intelligence a One-Off Exercise?
The cyber threat environment changes continuously.
New domains are registered, new data breaches emerge and new attack infrastructure is built every day.
Threat intelligence therefore usually delivers more value through continuous monitoring than through a one-off assessment.
The organisation's digital assets and the defined threat sources can be checked periodically so that new risks are identified.
Proactive Security Through Threat Intelligence
In the classic security approach, an event occurs, an alert is generated and the security team responds.
Threat intelligence aims to make this model more proactive.
A suspicious domain resembling the organisation's domain can be detected before the phishing campaign begins, for example.
A leaked user account's password can be changed before the attacker uses it.
Information about a newly emerged, active threat to the technology the organisation uses can be passed to the defensive teams.
The most important value of threat intelligence is therefore its early warning capability.
Why the SecureSys Cyber Threat Intelligence Service?
The success of a threat intelligence service should not be measured by access to a large number of data sources alone.
What really matters is being able to separate the threats relevant to the organisation from the mass of data and turn them into something actionable.
The SecureSys cyber threat intelligence service monitors organisations' external digital attack surfaces and threat signals in order to identify the events that create genuine security risk.
Depending on scope, the work can cover:
dark web monitoring, credential leak monitoring, brand monitoring, domain monitoring, attack surface intelligence, IOC monitoring and threat intelligence
The aim is not only to report the critical events detected but to offer recommended actions on how the organisation's security operations can address them.
SecureSys is a Türkiye-based cyber security company providing cyber threat intelligence, dark web monitoring, credential leak monitoring, brand and domain monitoring, attack surface intelligence and IOC monitoring services.
What Is Threat Actor Profiling?
One of the important components of threat intelligence work is profiling the threat actors that may pose a risk to the organisation or its sector.
Threat actor profiling can assess attacker groups':
target sectors, attack techniques, preferred initial access methods, malware, infrastructure and operating models
This approach means the organisation does not simply learn that "a threat exists" but also gains a better understanding of who the threat may come from and how it may operate.
If a particular threat actor targets the financial sector and gains initial access predominantly through phishing, for example, the organisation can use that information to prioritise email security, user awareness and MFA controls.
Threat actor profiling can therefore help plan cyber security investment on a more risk-focused basis.
Tracking Ransomware Groups
Ransomware attacks today are not limited to encrypting files.
Many attacker groups exfiltrate sensitive data after reaching the organisation's network and then threaten to publish it.
This model is usually described as the double extortion approach.
Threat intelligence work can track, for particular ransomware groups:
which sectors they target, which countries they are active in, which initial access methods they use and which vulnerabilities they exploit
Seeing a particular ransomware group concentrating on the sector in which the organisation operates can be an important early warning signal.
With this information, SOC, EDR and security teams can review their controls against the relevant attack techniques.
Exploit and Critical Vulnerability Intelligence
A large number of new security vulnerabilities are published every day.
Not all vulnerabilities are exploited to the same extent by real attackers, however.
Tracking the CVE list alone is therefore not sufficient.
One of the important tasks of threat intelligence is to analyse:
which vulnerabilities are being actively exploited, which exploit code has been published and which attacker groups are using those vulnerabilities
A critical vulnerability may have been published in a VPN product the organisation uses, for example.
If that same vulnerability is seen coming into use in active attacks, its priority rises considerably.
This approach allows patch management processes to be prioritised on real threat information rather than on the CVSS score alone.
Risk Prioritisation With Vulnerability Intelligence
Organisations may face thousands of systems and a large number of vulnerabilities.
Closing every vulnerability at the same speed may not be operationally possible.
A vulnerability intelligence approach becomes critical in that case.
When a vulnerability is assessed, criteria beyond the CVSS score can be considered:
accessibility from the internet, the existence of an exploit, information about active exploitation, use by threat actors and whether the organisation uses the technology concerned
The vulnerabilities genuinely likely to turn into an attack can then be addressed faster.
Threat intelligence and vulnerability management working together helps security teams use their resources more accurately.
Early Detection of Phishing Campaigns
Phishing is one of the most common attack methods targeting an organisation's employees or customers.
Attackers often create realistic-looking fake campaigns using:
the organisation's logo, web design, email templates and domain similarities
Threat intelligence work can detect possible phishing infrastructure at an early stage by monitoring brand and domain similarities.
A newly registered suspicious domain, an SSL certificate, or a site using the organisation's imagery can all be an important signal before the attack begins.
This approach is critically important particularly for banks, e-commerce companies and brands with large customer bases.
Monitoring Fake Social Media Accounts
Brand impersonation is not limited to websites.
Attackers can create fake social media accounts impersonating the organisation or its executives.
These accounts can be used for:
deceiving customers, investment fraud, fake campaigns, sharing malicious links or damaging corporate reputation
Threat intelligence and brand protection work can track suspicious accounts opened in the organisation's name.
Detecting accounts of this kind early can reduce harm to customers and misuse of the brand.
Domain and IP Reputation Monitoring
The reputation of the domains and IP addresses an organisation owns matters for the trustworthiness of its digital services.
An IP address becoming associated with spam, phishing or malicious activity can affect email delivery or other services.
Similarly, a domain appearing on malicious lists can create both brand and security risk.
Threat intelligence work can monitor the organisation's:
domain reputation, IP reputation and blacklist status
Problems such as malicious use, account compromise or infrastructure abuse can then be detected earlier.
Typosquatting and Homoglyph Attacks
One of the methods attackers use frequently is creating fake domain names that closely resemble the corporate domain.
Typosquatting attacks exploit users' typing errors.
Homoglyph attacks use characters that look visually similar to one another.
Characters from different alphabets that appear similar to Latin letters can be used, for example.
Domains created by these methods can be used in phishing, malware distribution or BEC attacks.
Monitoring domains of this kind makes an important contribution to the organisation's digital brand security.
Certificate Transparency Monitoring
Newly created phishing infrastructure usually uses an SSL/TLS certificate.
Certificate transparency records can help track the certificates created for particular domains and subdomains.
Monitoring these records means attackers creating certificates for domains resembling the organisation's brand can be treated as an early signal.
It also makes it possible to detect subdomains or certificate records created without the organisation's knowledge.
This approach delivers stronger results when used together with external attack surface management.
Monitoring GitHub and Open Source Code Leakage
Sensitive information belonging to organisations does not surface only on the dark web.
Git repositories made public by mistake can also cause serious data leakage.
Developers can leave the following inside source code:
API keys, passwords, access tokens, private keys, connection details or internal URLs
Publishing this information in open repositories can help attackers gain access to the organisation's infrastructure.
Threat intelligence work can search open source code platforms for leakage signals using the corporate domain, brand, project names and defined keywords.
Cloud Credential Leakage
The leakage of AWS access keys, Azure credentials, service account credentials or other cloud credentials can cause serious security risk.
An attacker can use this information to reach cloud resources, read data or create new resources.
Tracking cloud credential leakage can therefore also be assessed within threat intelligence work.
This risk can be higher in organisations that develop software and make heavy use of cloud services.
VIP and Executive Digital Risk Protection
Senior executives can frequently be targeted by attackers.
Executive names and contact details can be used to create:
fake email accounts, social media profiles, BEC attacks, phishing campaigns and fraud scenarios
VIP monitoring services can track the risks associated with the digital assets of designated executives or critical employees.
The aim is not to monitor an individual's private life, but to detect the misuse of corporate identity and authority by attackers.
Data Breach Intelligence
When an organisation's data is leaked, the source of the incident is not always known at first.
Data breach intelligence aims to determine whether information belonging to the organisation is present, by analysing records obtained from various data leakage sources.
Thousands of email accounts belonging to the organisation's domain may be identified in a data set, for example.
On its own, however, this does not show that the organisation was attacked directly.
The date the data was created, the source it came from and the information it contains all have to be analysed.
An important part of threat intelligence is therefore verification and contextualisation.
Cyber Threat Intelligence and Incident Response
Threat intelligence delivers significant value not only before an incident but during one.
When a security incident occurs, the incident response team can investigate the IP addresses, domains, malware hashes or techniques the attacker used.
Comparing this information against existing threat intelligence sources allows an assessment of which campaign the attack may be associated with.
Incident response teams can then determine more quickly:
the scope of the attack, the attacker's likely next steps and the systems that need to be checked
Threat Hunting and Cyber Threat Intelligence
Threat hunting is the proactive search for attacker activity that may be hidden in the organisation's environment, rather than simply responding to existing alerts.
Threat intelligence data is one of the important inputs to threat hunting work.
When the new domains or attack techniques used by a particular threat group are identified, for example, those indicators can be searched retrospectively in the organisation's logs.
This method can reveal attacker activity that security products did not detect automatically.
Intelligence-Driven Defence
Shaping cyber defence around the organisation's real threat environment, rather than basing it on generic security controls alone, is what constitutes an intelligence-driven defence approach.
If it is known that attackers targeting the organisation's sector make heavy use of particular techniques, for example, the following can be prioritised accordingly:
SOC correlation rules, EDR detection rules, phishing controls and purple team scenarios
This approach ensures that security investment focuses on the attacks that pose a genuine threat to the organisation rather than on theoretical ones.
Threat Intelligence and Purple Team
The attacker techniques obtained through threat intelligence can be turned into purple team exercises.
A threat intelligence team may have established that a particular threat group targets the organisation's sector and uses the following attack chain:
Phishing → PowerShell → Credential Dumping → Lateral Movement → Data Exfiltration
The red team can simulate these techniques in a controlled environment.
The blue team then checks whether the existing security products and SOC processes detect the attack.
Threat intelligence is in this way integrated directly into the process of developing the defence.
From IOCs to TTPs
Traditional threat intelligence has focused largely on IOC values such as IPs, domains and hashes.
Attackers can change these indicators easily, however.
Obtaining a new IP address or registering a new domain is straightforward for an attacker.
An attacker's working methods and techniques, by contrast, change more slowly.
A modern threat intelligence approach therefore focuses not only on tracking IOCs but also on analysing TTPs – tactics, techniques and procedures.
This approach can help build more durable, behaviour-based defensive mechanisms.
The Cyber Threat Intelligence Maturity Model
Organisations can run their threat intelligence processes at different levels of maturity.
At entry level, only IOC feeds may be used.
At more advanced levels, the following processes can be established:
organisation-specific threat profiles, threat actor analysis, vulnerability intelligence, SIEM integration, threat hunting and purple team
The aim of a mature threat intelligence programme is not to collect more data, but to enable better security decisions.
The organisation's threat intelligence approach should therefore be shaped around its own risk profile and SOC maturity.
Managing Noise in a Threat Intelligence Service
Threat intelligence systems can generate very large volumes of data.
Separating the events that matter to the organisation from thousands of domains, millions of IP addresses and a large number of data leak records can be difficult.
False positive and noise reduction is therefore an important component of a threat intelligence service.
As the organisation's:
domains, brands, technologies, executives, sector information and critical assets
are defined, intelligence results can be filtered more accurately.
The value of a good threat intelligence service should be measured not by "how many million IOCs it holds" but by how many genuinely actionable threats it can present to the organisation.
Cyber Threat Intelligence and Risk Scoring
It is not possible to address every threat detected at the same priority.
Threats therefore have to be classified on a risk basis.
A domain resembling the brand but not yet active may represent medium risk, for example, whereas an active phishing site on that same domain imitating the organisation's login screen can represent critical risk.
Similarly, an old credential leak and a newly leaked password for an administrator account in active use should not be assessed at the same level.
A risk-scoring approach helps security teams give priority to the most critical events.
Digital Risk Protection Through Threat Intelligence
Threat intelligence today covers considerably more than tracking technical attack indicators.
An organisation's digital identity in the outside world is also an asset that has to be protected.
A Digital Risk Protection – DRP approach aims to monitor digital risks such as:
brand impersonation, phishing, fake domains, fake social media accounts, leaked credentials and the sharing of sensitive data
The SecureSys cyber threat intelligence service can therefore be configured to provide visibility not only over the organisation's technical infrastructure but also over its digital brand and identity risks.
What Should Be Done When a Threat Is Detected?
The real value of a threat intelligence service emerges when the right action is taken after detection.
When a leaked user account is detected, for example, the following may be needed:
changing the password, terminating active sessions, checking MFA, reviewing the user's past sign-in records and checking similar accounts
When an active phishing site is found:
the domain, hosting, certificate and content information can be analysed and the necessary takedown or blocking processes initiated
When a malicious IOC is detected, retrospective checks can be carried out in the organisation's SIEM, firewall, EDR or DNS logs.
Threat intelligence should therefore produce not merely a "notification" but a recommended action.
The SecureSys Cyber Threat Intelligence Approach
The fundamental aim of the SecureSys threat intelligence approach is not to collect as much data about the organisation as possible from the internet.
The aim is to identify the threats that genuinely matter to the organisation and make that information usable by its security operations.
The service can address the following together:
external attack surface visibility, brand protection, dark web monitoring, credential leakage, threat actor tracking, IOC analysis and actionable threat intelligence
Where required, the information obtained can be used to develop the organisation's SOC, SIEM, EDR/XDR, incident response and threat hunting processes.
Frequently Asked Questions
What is cyber threat intelligence?
Cyber threat intelligence is the process of collecting the digital threats targeting an organisation from various sources, analysing them, and turning them into information security teams can act on.
What is threat intelligence?
Threat intelligence is the analysis of technical and contextual information about cyber threats so that decisions can be based on it.
What is dark web monitoring?
Dark web monitoring is the tracking of whether accounts, data or access credentials relating to the organisation appear on the dark web and similar threat sources.
Can leaked corporate accounts be detected?
Depending on scope and available sources, credential leak and infostealer-related leakage signals associated with the organisation's domain can be investigated.
Can fake domains be detected?
Yes. Similar domains capable of imitating the brand or corporate domain can be monitored and the potential phishing and impersonation risks assessed.
Can threat intelligence be integrated with SIEM?
Suitable threat indicators can be used for correlation or checking in SIEM, firewall, EDR/XDR and other security systems.
What is an IOC?
An IOC is a technical threat indicator such as an IP address, domain, URL or hash associated with known or suspected malicious activity.
Should threat intelligence be continuous?
Because the threat environment changes continuously, continuous or periodic monitoring is more meaningful, particularly in critical organisations.
The SecureSys cyber threat intelligence service is a professional cyber security service for detecting organisations' digital risks arising from the dark web, the open internet, leaked credentials, lookalike domains, phishing infrastructure, the external attack surface and threat actor activity — and turning them into actionable threat intelligence.
See the Threat Before It Reaches You
By the time an attack reaches your systems, the preparation for it has usually been visible on the outside for some time: a lookalike domain has been registered, a set of credentials has appeared in a leak, or a fake login page has been put together.
Get in touch with SecureSys to define the cyber threat intelligence, dark web monitoring and digital risk protection scope that fits your organisation.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.