
Sign up to save your podcasts
Or


In episode 70 of The Cyber5, we are joined by Open Source Context Director of Operations, Donald McCarthy.
We discuss external telemetry available to the private sector, focusing on passive domain name systems or passive DNS, and Border Gateway Protocol or BGP. These data sets are critical for threat intelligence teams, as they often provide crucial information on attacker infrastructure for the SOC. Still, they also help solve problems and provide context on a much broader scale.
Three Key Takeaways:
1) What is Passive DNS and how is it collected?
To simplify, passive DNS is a way of storing DNS resolution data so that security teams can reference past DNS record values to uncover potential security incidents or discover malicious infrastructures. Passive DNS is the historical phone book of the internet. Practitioners can collect it by:
2) What is Border Gateway Protocol (BGP)?
3) Use Cases for PDNS and BGP in the SOC:
4) Use Cases for PDNS and BGP outside of the SOC:
5) Enrichment is King and Does Not Need to Be Resource Intensive
If security teams are not engaging with the business to solve problems that risk revenue generation, data sets like PDNS or BGP do not matter. For example, if an organization does not control DNS at their borders, they will lose a lot of visibility to reduce risk and potentially give away proprietary information.
In episode 69 of The Cyber5, we are joined by Lima Charlie’s CEO, Maxime Lamothe-Brassard.
We discuss the future of what's known in the security industry as XDR, which is essentially an enrichment of endpoint detection response products.
Three Key Takeaways:
1) What is XDR? Depends who you ask.
XDR is not another tool, but merely an extension of Endpoint Detection and Response (EDR) products. Gartner expects 50% of mid-market buyers to adopt XDR strategies by 2027. For context, in around 2010, cybersecurity vendors started driving stronger antivirus solutions for endpoint computers and servers, called Endpoint Detection and Response (EDR). The antivirus was only catching malware with a known signature and not able to detect more malicious lateral movements that are common in today's attacks.
Every EDR platform has its own unique set of capabilities. However, some common capabilities include the monitoring of endpoints in both online and offline mode, responding to threats in real-time, increasing visibility and transparency of user data, detecting stored events with malicious malware injections, and creating blacklists and white lists in integration with other technologies.
Now that EDR solutions are firmly within the market, they need to be integrated with other tools, including threat intelligence, to be effective at scale for the enterprise. These massive integrations needed at scale, especially with the cloud, are what is starting to be defined as XDR.
2) What are the key integrations to EDR products to form an XDR strategy?
a. Identity Access Management: Gives visibility to who is accessing what applications and websites in the enterprise.
b. Threat Intelligence: Information and artifacts from attacker infrastructure, previous compromises, and behavior that can be identified outside of firewalls.
c. Cloud and SaaS Logging: Any application in the cloud produces a log for access and use.
3) XDR does not have to be expensive or manpower-intensive for SMB.
a. Cloud, SaaS, and Identity Access Management produce logs that can be integrated into easy solutions that do not need to be complex products, particularly for SMB.
b. Enablement should be the critical aspect of XDR rather than more expensive tooling.
c. Easy, automatable solutions to apply security controls are the critical way forward for medium and large enterprises.
In episode 68 of The Cyber5, we are joined by Executive Director and Head of Global Threat Intelligence for Morgan Stanley, Valentina Soria.
We discuss leading a large-scale threat intelligence program in the financial institution space and how to make intelligence absorbable by multiple consumers. We also talk about how intelligence teams can build processes and technology at scale to increase investment costs to criminals. Finally, we touch on large enterprises being a value-add to small and medium-sized businesses.
Two Key Takeaways:
1) Intelligence is Valued Differently By Different Stakeholders
2) Begin with the SOC, then Spread Across All Business Sectors
Topic: Value of Securing Containers in the Technology Supply Chain
In episode 67 of The Cyber5, we are joined by senior security practitioner Julie Tsai.
We discuss security and intelligence in modern-day technology platforms, concentrating on how to secure the impact that container and cloud environments have on the technology supply chain. Compliance and intelligence play a critical role in the application and development of supply chain risk. Specifically, when developers perform code commits and updates, we discuss the criticality of intelligence and compliance to ensure code is truthful, accurate, and complete.
Three Key Takeaways:
1) Containers and Virtualization Images Offer Repeatability But Also Potential for Compromise at Scale
Containers give software developers the potential to establish an assembly line of repeatable, secure patterns because they are operating system agnostic. However, the upstream effort to harden the container and set the right images or configurations needs to be correct from the beginning. Simultaneously, mistakes can lead to a compromised container or host OS level that might impact the container.
Container configurations have a shared kernel with modular application containers and services on top. Therefore, security practitioners must be mindful of anything that can break out of that container. Furthermore, if there is a host OS-level hardening, they must ensure kernel-level memory doesn't compromise and impact all the dependent layers.
2) Supply Chain Risk with Containers
Supply chain risk in technology is challenging because developers generally borrow code from other developers, and they don’t check libraries and dependencies for security issues. In addition, contractual agreements aren’t capturing all the supply chain pipeline nuances. It’s hard enough to know what’s happening inside an enterprise network, let alone understand the provenance and the chain of custody.
Security issues can get injected into the end product when not following a strict process concerning container changes. “Defense in Depth” is a classic security principle that matters in securing containers such as application and configuration management. In addition, other aspects like source control, commit trail, and fingerprinting different kinds of artifacts are all checksums to ensure the correct update of code.
3) Threat Intelligence Fundamentals with Container Security
A threat intelligence program needs to start by aligning with the business with the most prevalent threats. A banking site will have different threats than e-commerce, gaming, or crypt-currency exchange. Therefore, a threat intelligence program needs to be modular enough to scale to many types of threats as the business grows.
More tactically related to containers, developers can’t be tearing down containers as little work would get done if a malicious actor scans a container environment. However, if a threat intelligence team notices a regularity or repeatability with the scan attempts followed by authentication attempts to the environment, those types of intelligence alerts are fruitful.
Intelligence programs show clear value on highly attacked industries (manufacturing, health care, retail, finance). The challenge is if you put blinders on and think there isn’t a way to be attacked other than regular threat intelligence blogs.
In episode 66 of The Cyber5, we are joined by H&R Block Chief Information Security Officer (CISO) Josh Brown.
In this episode we discuss the importance in building an informed security team that can collect intelligence and proper risk strategy. We have a frank conversation about what the business of security means and how to develop a team that understands multiple business lines so a security team is anchoring their security strategy to how the company is driving revenue. We talk through how to do this at scale within the intelligence discipline that touches many lines of risk, not just cybersecurity.
Three Key Takeaways:
1) Security Informs the Business to Make Risk-Based Decisions
Security professionals must have a deep understanding of how the business functions to understand how to develop a proper risk-based approach. Security is a risk management function that puts up guardrails so the business avoids bad decisions and loses money. Intelligence is critical for gaining a 360-degree review: fraud and user segment of the network. Threat intelligence must be relevant to the specific business, not the industry overall. If there is a threat to a bank, that likely has nothing to do with a tax filing service.
2) Actionable Intelligence That Reduces Business Risk
The industry has not secured an intelligence solution. Intelligence is an enrichment function, not the first line of the truth of what to prioritize. Fraud and other specific business-specific data that result in business loss are equally important to be funneled into traditional cybersecurity tools. Further, threat feeds and information must be bi-directional so even competitors and businesses in the same location can understand when incidents are taking place. The threats that most companies face are not those that are regularly marketed such as Advanced Persistent Threats. The cybersecurity industry does a poor job at providing the likelihood of a certain advanced attack. Business email compromises, account takeovers, and fraud are still the most prevalent style attacks, even to those businesses that can afford sophisticated security technology.
3) Actionable Intelligence That Gives Visibility into Supply Chain Risk
“The perimeter” is no longer relevant like it used to be. With work from home, the perimeter is just as much identity access management (IAM) as it is about IP space. On third-party supply chain risk, currently, enterprises implement score card tooling as an audit function so when a software vulnerability is released, an enterprise can quickly query what suppliers use that library or dependency. Further, the supply chain is equally about business interruption (DDoS) as much as it is about suppliers that hold critical data. Major enterprises also care about the vendor’s vendors if compromised depending on the criticality of the data (fourth-party supply chain risk). Since the United States does not even have a standard breach notification law, it’s going to be very challenging to share intelligence bi-directionally let alone get developers to uniformly submit secure technology code.
1) Even in Marketing, Context and Insights Provide Intelligence, Not Data
Raw data is not intelligence; rather, intelligence is a refined product where context is provided around information and data. Similar to the national security and enterprise security world, where adversaries are trying to commit crimes and espionage, businesses want to attract people to their brand. Open-source and social media information are powerful data points when analyzed, providing critical intelligence on what consumers and businesses want to buy. Every human being is now a signal no different from radio intercepts during Pearl Harbor.
2) The Role of OSINT in Driving Revenue for the Brand; Quantitative and Qualitative Metrics
In the security world, attribution to a particular organization is necessary to continue to receive fundraising, whether it’s a hacking group or a terrorist organization. In the marketing world, brand intelligence is a crucial piece in the following three elements to influence a person:
Open-source intelligence can be mined in a way that provides insights stronger than traditional marketing focus groups. While celebrities attract attention, people are likely to follow people like themselves, aka micro-influencers.
Quantitatively, numbers increasing in revenue, sharing, engagements are critical metrics. Qualitatively, marketing teams can mine social media data to determine what people are thinking about a particular product, but also to understand how the products are performing, and then design and build future products. The crowd will tell a brand what they want and they don't have yet, and you can use that data to build future products.
3) Where Marketing Meets Security: Threats to Brand Reputation
Security teams should work with marketing teams daily to protect the brand. In today’s threats to brands, the human dimension of what people say online is of equal credibility if not more important than technical signals that show a company has suffered a breach, particularly regarding misinformation and disinformation. The human dimension is converging with a technical dimension, and a true holistic hybrid model is needed for enterprise security and intelligence teams. An example of reputation threats that happen in business every day:
4) Where Security Meets Marketing: Privacy Taken Seriously That Enhances the Brand
On the flip side, marketing teams should look for ways to promote the security of their products as business differentiators. Marketing teams should also consult with the security teams to understand all the different data lakes that are available in social media, dark web, and open source to ensure they can collect on the proper type of sentiment where brands are being discussed.
In episode 64 of The Cyber5, we are again joined by John Marshall, Senior Intelligence Analyst at Okta.
We discuss building a threat intelligence program to protect executives, particularly on nuances of being a “solution-side security company”. We discuss a risk-based approach for protecting executives and the data that's important to aggregate and analyze. We also talk about success metrics for intelligence analysis when building an executive protection program.
Three Key Takeaways:
Regardless of industry, connecting with your executive team on a personal level to establish trust is the first step in any executive protection program. Communicating plans, actions, and milestones are critical. Within these three segments, intelligence requirements should be tiered into 3 groups - strategic, operational, and tactical.
2) Distinguishing Between Targets of Opportunity and Targets of Attack
Typical items to review when protecting executives:
The primary mechanisms to protect against targets of opportunity:
When mechanisms to flesh out targets of opportunity appear to escalate, where they become a target of the attack, often private sector security teams lack an action arm to dispel that threat and have to rely on law enforcement for investigations.
Intelligence analysis and determination of facts should be pursued on any threat so that security teams can effectively request law enforcement intervention - equipped with more information that will allow faster response.
3) Articulating Success Metrics
Pinpointing the right event is the most critical of success criteria. Executing the intelligence cycle of planning, collecting, exploiting, analyzing, and disseminating information that an executive can use to answer a “so what?” is still a nuanced concept for many private sector organizations.
Documenting “wins” and “losses” are equally critical. Security is a risk management function that exists to keep the workforce safe and doing their jobs.
Whether it's getting an executive out of a traffic jam or informing a team of a hurricane happening during a conference that mitigates injury, these should be documented for value-based metrics.
In episode 63 of The Cyber5, we are again joined by Sean O’Connor, Head of Global Cyber Threat Intelligence for Equinix.
We discuss attribution in the cyber threat intelligence and investigation space, and what the private sector can learn from public sector intelligence programs. We also discuss different levels of attribution, the outcomes, and the disruption campaigns that are needed to make an impact on cybercriminals around the world. We define the impact of attribution with different stakeholders throughout the business and how the intelligence discipline will likely evolve over the next five to 10 years.
Five Key Takeaways:
Many cybersecurity best practices and frameworks originate from the US public sector:
2) Attribution is Critical in Cybersecurity to Warrant an Action
Attribution to cyber threat actors by industry is still important as a starting point to derive appropriate controls for the SOC and the CERT within a large organization. How these threats pose a risk of monetary loss are important elements of context when providing these threats to business executives. Here are two typical starting points:
3) Disruption Campaigns Happen with Successful Information Sharing
Successful disruption campaigns come from non-public information sharing between vendors, enterprises, and public sector institutions like CISA or the FBI. They typically do not originate from marketing blog posts.
4) Threat Intelligence is a Service-Based Role that Goes Beyond the SOC
Success in cybersecurity (SOC and CERT) is keeping security incidents limited to “events” and ensuring they do not escalate into breaches. This occurs from multiple stakeholders having the proper visibility to ensure network telemetry is complete, accurate, and truthful. However, due to the services nature of intelligence work, it goes beyond just the SOC.
5) Threat Intelligence Should be a Floating Team to the Business
Threat intelligence should be a floating team that can operate outside of the SOC and is an asset to the overall business, not just limited to combating cyber threats. Often executives want intelligence on mergers and acquisitions and market entry in a given geopolitical area, and threat analysis needs to be tailored to different customers. A Chief Intelligence Officer may be more widely accepted in the future as the needs of the business expand and diversify.
In episode 62 of The Cyber5, we are again joined by Charles Finfrock, CEO and Founder of Black Hand Solutions. Charles was previously the Senior Manager of Insider Threat and Investigations at Tesla and prior to that, he worked as an Operations Officer for the Central Intelligence Agency.
We discuss the generalities of cryptocurrency and go into the tactics, techniques, and procedures for conducting cryptocurrency investigations. We also discuss some case studies and what proper outcomes look like for making it more expensive for the adversaries to conduct their operations in this generally unregulated world.
Three Key Takeaways:
In its simplest form, Cryptocurrency is digital coins or money (Bitcoin and Ethereum being the most popular). It is not run or governed by a central authority, but by a mathematical algorithm that verifies the transactions, controls the supply of the certain coin, and runs on the blockchain.
Blockchain, as it pertains to Cryptocurrency, is a ledger that verifies what has been sent and received from an account. It is pseudo-anonymous, it is not anonymous - which is why criminals have been leveraging it so aggressively.
When Bitcoin is transacted, the amount sent and received are recorded on the Bitcoin ledger (Blockchain) and associated with a Cryptocurrency wallet address. Criminals think they can hide their identities as a result of not needing a formally validated identity through a central authority.
Since Cryptocurrency is not controlled by a central government no one can modify the supply of the particular cryptocurrency. It derives value in the same way the US dollar used to derive value from gold - scarcity. The argument for Bitcoin's value is similar to that of gold—a commodity that shares characteristics with the Cryptocurrency. The cryptocurrency is limited to a quantity of 21 million. Bitcoin's value is a function of this scarcity.
2) Conducting Cryptocurrency Investigations - Decreasing Return on Investment to Criminals
When criminals first started using Cryptocurrency in 2012 it was because they thought they could hide their identity. At the time, tools were not available to law enforcement to unmask and attribute actions to persons. That has changed.
The two kinds of investigations that clients engage in are reactive and proactive. Reactive are when scams have already been perpetrated against their brand. Proactive are when security teams engage with actors to derive the scam before a significant amount of loss occurs.
Legal and technical methods can be deployed to “burn down the infrastructure” to decrease the return on investment for online criminals. Oftentimes an outcome can be to contact a centralized bank or Cryptocurrency exchange (i.e. Coinbase) that is linked to the Cryptocurrency as a means to “cash out” the criminal proceeds, report the fraud, and disrupt the activity, thus increasing the costs to the criminals.
3) Provenance and Repudiation To Understand Truth, Accuracy, and Completeness
As with any online crime investigation, investigative techniques identify stylometric attributes of the criminal infrastructure that reveal the provenance of data by the malicious actor. The end provides authorities the ability to repudiate this scheme in the future.
Often what we look for are lapses in operational security by the threat actors, which include but are not limited to the following:
Going a step further, we pivot from technical analysis to open source intelligence (OSINT) to add valuable context to the nature of the threat an organization faces. By exposing network infrastructure and drawing associations using threat information and other technology-enabled OSINT connections, we can determine the motivation and sophistication of the threat. We assess characteristics such as:
In episode 61 of The Cyber5, we are joined by Josh Shaul, CEO of Allure Security.
We discuss cybersecurity and account takeovers. We focus on the lifecycle of an account takeover , how to permanently solve it, and how to show a clear return on investment to small business owners. We also talk about how to impede attackers by making their efforts more costly and difficult.
Four Key Takeaways:
1) Account Takeovers
An account takeover is a form of identity theft and fraud, where a malicious third party successfully gains access to a user's account credentials. Previously targeted at large enterprises, these attacks are now targeting SMBs.
2) Disrupting the Return on Investment Against an Attacker
By Automating defenses and rapidly removing fake websites, attackers are faced with increased cost and less success.
3) Too Much marketing Focus on APTs
A lot of cybersecurity products and technology focus on advanced persistent threats (APTs) and ignore the threats that matter. Organizations can best protect themselves by mapping technology to the threats that are actually targeting them.
4) Intelligence Must be Actionable
Making intelligence actionable is necessary for proper security regardless of an organization’s size. For many organizations, this is most easily achieved through managed services providers that provide people, process, and technology that is otherwise not attainable for small enterprises.
From the publisher's feed