Threat Intelligence Library

Threat Intelligence Library  

Actionable security intelligence from vulnerabilit…

How should defenders reduce ICS exposure risk?. Structure the thread as a stepwise exposure-control checklist for control system environments, grounded in CISA guidance on legacy ICS risk and ICS advisory mitigation patterns. Emphasize internet exposure, segmentation from business networks, firewall placement, VPN hardening, and affected-version review.

If your ICS can be reached from the Internet, it is already too exposed. CISA’s recurring advice is to reduce reachability first, then layer in segmentation, firewalls, and controlled remote access[[cite:1]][[cite:2]]. Step 1: review the advisory’s affected software or firmware versions and confirm ...

View

5 hunt leads from recent CISA malware and ransomware advisories. Create exactly five operational cards, each centered on one actionable hunt lead from BRICKSTORM, Medusa, Akira, Androxgh0st, and the CISA ransomware guide. Keep each card focused on what to look for, such as IOCs, detection signatures, vulnerable services, initial access patterns, or precursor activity.

Hunt DMZ web shells that precede RDP lateral movement to domain controllers and VMware vCenter. Flag PsExec activity that creates an inbound RDP rule on port 3389, especially `openrdp.bat`. Watch for VPN access without MFA, especially tied to CVE-2024-40766 or stolen VPN credentials. Alert on POSTs ...

View

Test your knowledge of ATT&CK mapping for detection work. Frame the quiz around practical mapping decisions, including how ATT&CK normalizes adversary behavior and how defenders use mapped techniques to organize detections. Keep the questions grounded in recurring behaviors from the evidence, such as privilege escalation, persistence, active scanning, account manipulation, and exfiltration-related activity.

Q1. How do the attached sources describe ATT&CK at a high level? - A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations - A catalog of only malware hashes and file signatures - A framework that lists only vulnerability severity scores - A patch-ma...

View

From public facing exploit to cloud and identity cleanup. Break the incident response lesson into a sequence from public facing GeoServer exploitation of CVE-2024-36401 through web shells, cron jobs, valid accounts, brute force, PowerShell, BITS jobs, and Stowaway. End with practical response steps: prompt patching, centralized logging, incident response practice, conditional access, MFA, token revocation, and control validation.

How does a public GeoServer bug turn into full intrusion? CISA says CVE-2024-36401 was exploited on public-facing GeoServer systems, then the campaign moved through web shells, cron jobs, valid accounts, brute force, PowerShell, BITS jobs, and Stowaway.[[cite:1]] The sequence mattered: attackers use...

View

Should KEV outrank CVSS in vulnerability triage?. Compare severity-only triage with exploitation-led triage using KEV, EPSS, vendor remediation status, and asset exposure as the core decision inputs. Include a table separating confirmed exploitation, probability of exploitation, remediation action, and when to remove unpatchable assets from networks.

Should KEV outrank CVSS in vulnerability triage? **Yes.** The attached CISA and EPSS sources support an exploitation-led triage model: confirmed exploitation in CISA KEV should outrank severity-only CVSS scoring, while EPSS is used as a probability signal when active exploitation is not already evid...

View
  • 1(current)