Disciplines

💻 Cyber Intelligence (CYBINT)

Adversary Activity in Networks and Systems
Cyber & Threat

Sources

0
0 no-auth

Mission domains

0
reach

Data points

0
covered

Related INT

0
disciplines

🔍 Lookup

📜 Playbook — Cyber Intelligence collection

  1. Direction — frame the requirement for Cyber Intelligence: what decision does this support, by when?
  2. Collection — collect from the 0 mapped sources (0 free) — filter the catalog by CYBINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Cyber Intelligence tracks threat actors, campaigns, tooling, and indicators of compromise, mapping adversary behavior to a common framework of tactics and techniques. It answers who is targeting the organization, what TTPs and tooling they use, and which indicators and known-exploited vulnerabilities demand immediate defensive action.

📡 Collection methods

  • Aggregating and deduplicating IOC feeds from open and community threat-sharing platforms
  • Mapping observed adversary behavior to MITRE ATT&CK techniques and building actor TTP profiles
  • Tracking threat-actor campaigns and infrastructure across reporting and telemetry
  • Correlating CISA KEV and exploited-CVE data against the organization's asset inventory
  • Sandbox and OSINT enrichment of indicators to add context and confidence scoring
  • Sharing and consuming structured intel via STIX/TAXII and MISP communities

🔧 Tools & frameworks

  • MISP
  • OpenCTI
  • ATT&CK Navigator
  • YARA
  • TheHive
  • Yeti
  • STIX/TAXII
  • Sigma

📜 Cyber Intelligence Tradecraft

  1. Collect IOCs and campaign reporting from feeds, sharing communities, and OSINT filtered to relevant sectors and geographies
  2. Normalize indicators, enrich with WHOIS/passive-DNS/sandbox context, and score confidence and false-positive risk
  3. Analyze clustered indicators and behaviors against ATT&CK to characterize the campaign's objectives and kill-chain stage
  4. Attribute activity to a named actor or cluster using TTP overlap, infrastructure reuse, and diamond-model pivots
  5. Disseminate finished intelligence, detection rules (YARA/Sigma), and priority-intelligence-requirement answers to defenders
  6. Push high-confidence indicators to blocking and detection controls and measure hits to validate and retire them

📊 Dashboard KPIs

Active campaigns trackedIOCs ingestedKEV exposureActor coverageDetection rules deployed
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php