2 min read

Sources & Methods Newsletter #10 - July 2023

Hello! This month, I'm celebrating another milestone in this newsletter's humble historyโ€”issue number ten. Here's to many more.

Thanks for reading,

Matthew Conway (@mattreduce)

๐Ÿ“ Sources

EmailRep - I recently discovered EmailRep, an email reputation service and API from Sublime Security, that you can use to quickly judge an email sender based on various reputational factors. Its API is free up to 250 queries per month, but if you need a higher limit or would like support, there are also paid plans. Hope you find it useful.

๐Ÿ“ฐ Articles

Ondra Rojฤรญk - From Descriptions to Impact: Unlocking the Power of Basic Cyber Threat Intelligence Questions #reporting #tradecraft

Scott Roberts - Getting Started with Synapse #tooling

Jamie Collier - From Information Sharing to Building a Collective View of Intelligence #sharing #community

Vertex Project - From Group to Individual: Modeling InformNapalmโ€™s Article on Sergey Morgachev of APT28 #investigation #analysis #tooling

Matt Richard - Common Cyber Threat Intel Biases #analysis #bias

Wiz - Linux rootkits explained โ€“ Part 1: Dynamic linker hijacking #linux #rootkit #ttps

Atlantic Council - Cross-community perspectives on cyber threat intelligence and policy #policy

๐Ÿ›  Tools

Prot1ntelligence

github.com/C3n7ral051nt4g3ncy/Prot1ntelligence

Convenient Python script that talks to the ProtonMail API to validate PM email addresses, reveal catch-all addresses, and estimate account creation date.

CTI Blueprints

github.com/center-for-threat-informed-defense/cti-blueprints

The Center for Threat Informed Defense released CTI Blueprints, a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable reports more consistently and efficiently.

Evidence

github.com/evidence-dev/evidence

Evidence is an open source toolkit for building reports involving data analysis using SQL and Markdown, connecting to datastores including Snowflake, PostgreSQL, and SQLite.

github.com/bellingcat/osm-search

A user friendly way to search OpenStreetMap data for features in proximity to each other, from Bellingcat.

mitre_attack_csv

github.com/stmtstk/mitre_attack_csv

This project provides CSV files of STIX SDO and SRO objects that make up the MITRE ATT&CK dataset, as well as a Python script to generate the CSVs for the ATT&CK matrix of your choice.

powerup-assemblyline

github.com/usaa/powerup-assemblyline

This Power Up for Vertex Synapse integrates the analysis platform with Assemblyline, an open source pipeline for triaging and analyzing suspicious files.

๐Ÿ’ก Tip

Understanding the threat landscape as it relates to your organization is a powerful focusing and enabling factor for your entire security program. Don't hold out for perfection before you even get started on this workโ€”if you want to know where to start, check out the Threat Profiling guide I shared in issue #9 by Tidal Cyber.

๐Ÿ“† Events

USENIX Security '23

๐Ÿ“ Anaheim, CA, US
๐Ÿ“Š Conference Aug 9โ€“11
๐Ÿข Anaheim Marriott
๐Ÿ”— https://www.usenix.org/conference/usenixsecurity23

Underground Economy Conference 2023

๐Ÿ“ Prague, CZ
๐Ÿ“Š Conference Sep 4-7
๐Ÿข Prague Congress Center
๐Ÿ”— Conference https://www.team-cymru.com/ue2023

Objective by the Sea v6

๐Ÿ“ Marbella, ES
๐Ÿ“š Training Oct 9-11
๐Ÿ“Š Conference Oct 12-13
๐Ÿข Don Pepe (Gran Meliรก)
๐Ÿ”— Conference https://objectivebythesea.org/v6/cfp.html

hack.lu and CTI Summit

๐Ÿ“ Dommeldange, Luxembourg City, LU
๐Ÿ“Š CTI Summit Oct 16-17
๐Ÿ“Š Hack.lu Oct 18-19
๐Ÿข Alvisse Parc Hotel
๐Ÿ”— Conference https://hack.lu/

ATT&CKcon 4.0

๐Ÿ“ McLean, VA, US & Virtual
๐Ÿ“Š Conference Oct 24-25
๐Ÿข MITRE campus, McLean, VA
๐Ÿ”— https://www.mitre.org/events/attckcon-40