Threat Intelligence Began on Battlefields

โ–ถ Watch (0:21)

Threat intelligence did not start in SOCs. It began with intelligence bulletins from March 1945 on battlefields and in back rooms. The core question then and now: what is the enemy going to do next? Intelligence evolved from human agents and intercepted communications to logs and telemetry. Opponents shifted from nation states to criminal groups and teenagers who social engineer Fortune 500 companies through a help desk call. Campaigns now move from initial access to data exfiltration within hours. The instruments changed but the mission remains the same.

Why Atomic Indicators Fail

โ–ถ Watch (5:09)

Traditional CTI models collect feeds from commercial and open sources, enrich them through VirusTotal and Shodan, share with stakeholders, and block indicators. The structural problem: everything relies on indicators designed to burn. The pyramid of pain shows hashes and IPs cost attackers nothing to change. Domain names require minor effort. Network artifacts need more work. TTPs sit at the apex. Changing tactics is expensive for attackers. Most CTI programs focus on atomic indicators at the bottom of the pyramid. Defenders must chase chords, not notes.

Case Study: Scattered Spider and Shiny Hunters

โ–ถ Watch (11:19)

Scattered Spider and Shiny Hunters are two criminal groups with different origins but similar playbooks. Scattered Spider runs social engineering campaigns against large enterprises and SaaS platforms. Shiny Hunters operates pay-and-leak extortion sites. The groups now work together. Their identity compromise chord repeats across breaches: extensive OSINT on targets, a vishing call to the help desk, password reset or MFA transfer, then SSO compromise. This sequence hit MGM in a 10-minute call that caused a $100 million incident, then Caesars, Okta, Twilio, and others.

Case Study: Amos macOS Info Stealer

โ–ถ Watch (20:16)

Amos is a macOS info stealer circulating since April 2023. It targets keychain passwords, browser credentials, and crypto wallets. A campaign bought Google ad spaces for Mac OS troubleshooting searches. Users landed on AI chat pages that instructed them to paste a terminal command. That command downloaded the first stage, prompted for the system password, checked for VM environments, and downloaded the Amos payload. Samita tracked infrastructure across multiple domains. TLS issuer WE1 remained consistent. Endpoint naming conventions like cleaner_one_update persisted even as domains and hashes rotated.

Making Threat Intelligence Part of Your Band

โ–ถ Watch (29:46)

Making threat intelligence part of your practice requires four steps. Prioritize risks that matter to your organization and map them to industry context. Time-box research to prevent rabbit holing. Analyze for patterns, detection gaps, and coverage blind spots. Report concrete findings with documentation for others to pick up. Sustainability comes from formal CTI processes, feeds with rich context, and collaboration with industry peers. Start with identity abuse. Detect sequences of events rather than atomic alerts. Look at data movement across multiple sources.

Q&A

How do TTPs oriented around capability strengths apply to the chords concept? Chords represent layers like identity and infrastructure that persist across organizations, though the exact topology varies. SOC awareness of these patterns helps analysts alert better. โ–ถ 37:37

Have attackers created websites that poison LLM training to generate malicious instructions? Not at mass scale for major models like GPT, but custom models trained on specific data like Mac OS support could be influenced. โ–ถ 39:34

What tools speed up this slow process of pattern-based threat intelligence? AI and agentic workflows are being explored internally to automate infrastructure tracking and pattern detection. โ–ถ 41:08

Why do attackers maintain two certificates from different CAs for the same domain? Likely for backup and to rotate away from burned issuers like WE1 toward E7 and E8, even from the same intermediary CA. โ–ถ 42:09

Notable Quotes

data tells you what happens but context tells you what it means Karthika ยท โ–ถ 5:00

This has not changed in the last four years because it works Karthika ยท โ–ถ 19:31

This intrusion does not really rely on a particular malware Karthika ยท โ–ถ 16:56

labels may change. we should not really focus on you know the specific uh actor labels but focus more on their operational playbooks Karthika ยท โ–ถ 12:50

Key Takeaways

  • Track behavioral patterns (TTPs), not atomic indicators like IPs and hashes.
  • Identity compromise persists as the weakest link across modern intrusions.
  • Infrastructure preferences like TLS issuers outlive individual domains.