๐ข ๐๐ง๐ญ๐ซ๐จ๐๐ฎ๐๐ข๐ง๐ ๐ญ๐ก๐ ๐๐๐
๐๐ ๐๐จ๐ซ๐ค๐๐จ๐จ๐ค ๐๐จ๐ซ ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐๐ง๐ญ๐ข๐ง๐๐ฅ!
Everyone who knows me knows how passionate I am about the ๐๐ฒ๐๐๐ซ ๐๐ก๐ซ๐๐๐ญ ๐๐ง๐ญ๐๐ฅ๐ฅ๐ข๐ ๐๐ง๐๐ (๐๐๐) discipline. Back in early 2020, just before the pandemic outbreak, I had the opportunity to travel to Luxembourg for hands-on training on the
@MISPProject and later on, attend two
@FIRSTdotOrg CTI events in Berlin. Since then, Iโve been fortunate to work on many CTI initiatives, especially during my tenure at Alpha Bank, where my team pioneered in this area within the FSI sector.
Over the years, the CTI discipline has significantly matured. With that evolution came frameworks, operational requirements, and the growing challenge of managing multiple intelligence feeds - many of which may not be relevant, actionable, or current enough to effectively protect an organization.
Inspired by the TIFCE framework introduced by Sergio Albea, I built the ๐๐๐
๐๐ ๐๐จ๐ซ๐ค๐๐จ๐จ๐ค ๐๐จ๐ซ ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐๐ง๐ญ๐ข๐ง๐๐ฅ.
๐
github.com/cyb3rmik3/KQL-thrโฆ
The workbook evaluates the four key pillars of the TIFCE framework:
โ
Which feeds provide unique intelligence?
โ
Which feeds are truly relevant to your environment?
โ
Which feeds correlate with confirmed malicious activity?
โ
Which feeds are fresh and actively maintained?
If you are using ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐๐ง๐ญ๐ข๐ง๐๐ฅ and the ๐๐๐๐๐ง๐๐๐ซ ๐๐๐ stack together with multiple ๐๐ก๐ซ๐๐๐ญ ๐๐ง๐ญ๐๐ฅ๐ฅ๐ข๐ ๐๐ง๐๐ feeds (MDTI, MISP etc), I encourage you to test the workbook and review the findings.
Feedback and contributions are always welcome - feel free to open an Issue or submit a PR with enhancements and ideas. I know already that more visuals and some tabs with more info are needed.
A huge thank you to my comrade Marios for his contributions, and to MVP brothers Sergio Albea,
@BertJanCyber, and Uros Babic for their valuable preview feedback.
#MicrosoftSecurity #MicrosoftSentinel #UnifiedSecOps #ThreatIntelligence #CyberThreatIntelligence #KQL #KustoQueryLanguage