
DOING THREAT INTEL THE HARD WAY - PART 5: ANALYZE THREAT INTELLIGENCE
The Analyst work flow must provide a repeatable process to analyze the output of the integrations you have created in the previous steps.
For example, if the SIEM determines that a server is communicating with a known botnet command and control domain, your analyst must be notified in some fashion (on screen prompt, email, SMS, IM, etc.).
The analyst must then evaluate the collected information and take appropriate action based on the information’s accuracy.
If the analyst determines that the notification is not valid, they should then document their findings for future reference and move on to the next analysis. If the analyst verifies that the notification is correct, they should begin a formal set of incident response steps. source
Leave DOING THREAT INTEL THE HARD WAY - PART 5: ANALYZE THREAT INTELLIGENCE to:
Read more #tech posts
Best Posts From jonsmith
We have not curated any of jonsmith's posts yet. But you can encourage our curation team to review posts by visiting them regularly and by referring other readers. Because we give priority to frequently read content.
More Posts From jonsmith
- AI provides an urgent solution to evolving ransomware threats facing healthcare
- McCaskill asks DHS about 'critical infrastructure' designation
- How AI Can Help Fight Healthcare Ransomware Threats
- AI provides an urgent solution to evolving ransomware threats facing healthcare
- Can Artificial Intelligence cure the Ransomware pandemic on Healthcare?
- SNYPR Recognized as a Strong Performer in The Forrester Security Analytics Wave Report
- A User and Entity Behavior Analytics Scoring System Explained
- Whats Next from Google Cloud: Scenes from Google Next
- Parsons Named as a World’s Most Ethical Company by Ethisphere Institute for Eighth Year in a Row
- DOING THREAT INTEL THE HARD WAY - PART 5: ANALYZE THREAT INTELLIGENCE