Cloud Defense Strategies with Azure Sentinel by Marshall Copeland

Cloud Defense Strategies with Azure Sentinel by Marshall Copeland

Author:Marshall Copeland
Language: eng
Format: epub
ISBN: 9781484271322
Publisher: Apress


Email address

File hashes

IP addresses

Certificates

You continue to learn about criminal campaigns in reading the Microsoft Security Intelligence Report (SIR), Verizon Data Breach Investigations Report (DBIR), or Red Canary Threat Detection Report in Chapter 8. During the attacking campaigns processes from start-to-finish, you should realize the data attributes of the indicators of compromise are affected with quickly expiring values. The expiration can be seen in the confidence score because once the campaign, malware, and IOC are shared publicly, the attackers are already obscuring the weaponization stage of Cyber Kill Chain.

At this point in your learning processes it may be extremely helpful to have more details of the threat intelligence relationships between attributes of indicators of compromise using a learning example from a real-world cyber-attack. The example used is analyzing how the cyber-attack compromised the supply chain of SolarWinds. This example is for educational purposes only with IOC attributes, applying some of the knowledge about indicators of compromise shared between security providers, which is the focus for the example.

Analyzing Solarwinds Cyber-Attack Sidebar

The analysis framework is attributed to the Cybersecurity and Infrastructure Security Agency (CISA, www.cisa.gov/) (search for SolarWinds) and Center for Internet Security (CIS, www.cisecurity.org/solarwinds/).

Modern attacks are much more sophisticated than attacks in the past. One common tactic today is the use of lateral movement. In the SolarWinds attack, a software update process in a network management tool was compromised, and threat actors were able to gain deep access into targeted networks. The attackers were able to easily pivot from one system to another, gaining access and data as they moved.

1.

The IT company SolarWinds produced their Orion Platform, a monitoring platform that companies use to analyze computer network bandwidth and high availability of applications among other features.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.