HillviewCap / ironmonkey

1 stars 0 forks source link

APT Hub - Threat Actor Profiling and Campaign Tracking #16

Closed HillviewCap closed 1 day ago

HillviewCap commented 2 months ago

Enhancement: APT Hub - Threat Actor Profiling and Campaign Tracking

Description:

The APT Hub aims to provide a comprehensive view of Advanced Persistent Threats (APTs), enabling users to stay informed about emerging threats and actors. This enhancement focuses on developing threat actor profiling and campaign tracking capabilities to enhance the APT Hub's threat intelligence features.

Motivation:

Threat actor profiling and campaign tracking are critical components of threat intelligence, allowing users to understand the motivations, tactics, and techniques of threat actors. By developing these capabilities, the APT Hub will provide users with a more comprehensive understanding of APTs, enabling them to better anticipate and respond to emerging threats.

Proposed Changes:

Benefits:

Priority:

High

Estimation:

Dependencies:

HillviewCap commented 2 months ago

this would be a perfect primer for incorporating Attack Flow for visualizing the attack patterns. We could even go so far as using their Best Practices Guide to Open Source Report Selection This could be used as a prompt to identify high quality articles for consideration to enhance or change an attack flow. https://center-for-threat-informed-defense.github.io/attack-flow/example_flows/

HillviewCap commented 1 day ago

Created a new incident for the attack flow visualizations