Organizations

Weve been waiting for someone like you

When and How to Hire a Threat Intelligence Analyst

WHEN… Threat Intelligence has become the latest marketing buzzword, often abused and misused in an effort to impress a customer base. So, when do you need threat intelligence and when is the right time to hire someone to “provide customers” with threat intelligence? Well, you should never hire someone specifically to provide customers with threat […]

When and How to Hire a Threat Intelligence Analyst Read More »

Meeting in session. Shot of a business meeting on the go.

Three Myths About Threat Intelligence

For new readers, welcome, and please take a moment to read a brief message From the Author. 1. Threat intelligence is something you should provide your customers If threat intelligence products are not your flagship product or primary business function, then threat intelligence is not something you should provide as a product or service directly

Three Myths About Threat Intelligence Read More »

Designer woman drawing a website outline and website ux app development on mobile phone.

Outlining a Threat Intel Program

(estimated read time 27min) For new readers, welcome, and please take a moment to read a brief message From the Author. Executive Summary I recently crunched the high level basics of setting up a threat intelligence (abbreviated as Threat Intel) program into a 9-tweet thread, which was met with great appreciation and the feedback solicited unanimously

Outlining a Threat Intel Program Read More »

Computer hacker.

Hacking Critical Infrastructure

For new readers, welcome, and please take a moment to read a brief message From the Author. Please accept my apologies in advance if you were hoping to read about an actual technical vulnerability in critical infrastructure or the exploitation thereof. Today we discuss a plausible strategic cby3r threat, and how one might go about

Hacking Critical Infrastructure Read More »

Act of kindness

Phishing the Affordable Care Act

Recently, while working on a project I was asked to gather some information on Blue Cross Blue Shield (BCBS) and something scary began to unfold.  I noticed that states have individual BCBS websites, and that there is no real consistency in the URL naming convention.  Then I began imagining the methods an attacker could use

Phishing the Affordable Care Act Read More »

Photo of business meeting in expensive hotel

Stop Having Sex for the First Time – part 2

In the first part of this article, I gave some various examples of how InfoSec teams are structured to fail or at the very least function very inefficiently. Next we’ll talk about how to achieve a more effective *INTEL* team – and how it will enable the development of intelligence in the organization. FIRST: Specialization

Stop Having Sex for the First Time – part 2 Read More »

Multiracial business team having a meeting in the office

Stop Having Sex for the First Time – part 1

As someone who’s been working on an OSINT project lately, I’ve had many surprises and hurdles because there’s poor organization to our execution and little to no information sharing between security functions in the same department. I recently got access to a very important piece of information/tool that resulted in a huge discovery…..this is Oct,

Stop Having Sex for the First Time – part 1 Read More »