Slide 1

Slide 1 text

@sjr - 20230706 Exploring Threat Intelligence Insights + Tools from Vertex Synapse

Slide 2

Slide 2 text

YES THIS IS THE RIGHT WAY TO WRITE DATES!!! 20230706

Slide 3

Slide 3 text

While I’m at it… AND GMT IS THE ONLY TIMEZONE!!!!

Slide 4

Slide 4 text

Agenda Tell ‘em what you’re gonna tell ‘em… tell ‘em… tell ‘em what you told ‘em! • Me & Why You Should Listen to Me • The Briefest Intro to Threat Intelligence Imaginable • Synapse • Key Concepts • CRUD (actually RCUD) • Extras • A pile of homework to read later if you actually care…

Slide 5

Slide 5 text

Who Am I Anyway? Scott Roberts • Head of Threat Research @ Interpres • Adjunct Prof & CTF Coach @ USU • Author, Developer, & CTI Bon Vivant • 20+ years Intrusion Detection, Incident Response, Cyber Threat Intel @ Symantec, Mandiant, GitHub, Apple, Splunk

Slide 6

Slide 6 text

What is Threat Intelligence?

Slide 7

Slide 7 text

Cyber Threat Intelligence Analysis More like Q than James Bond… What I Actually Do What My Boss Thinks I Do What My Mom Thinks I Do What My Coworkers Think I Do

Slide 8

Slide 8 text

Cyber Threat Intelligence (For Real) I’m required to have actual, useful information… • A set of models, techniques, and procedures to develop an operational & strategic understanding of adversaries • Almost always decision support (which is just what it sounds like) • Help SOC Analysts Identify Intrusions • Help Incident Responders React E ff ectively to Intrusions • Help Leadership & Architects Plan Better for the Next Intrusion • Should be making everyone else’s life easier…

Slide 9

Slide 9 text

What is Synapse?

Slide 10

Slide 10 text

What is Synapse? It’s better than a spreadsheet… • Synapse is a versatile central intelligence and analysis system created to support analyst teams in every stage of the intelligence life cycle. • A hyper graph based data storage and manipulation layer. • Supports tons of integrations and automation.

Slide 11

Slide 11 text

Synapse: Key Concepts Fix your brain… • Not a tool, not a database, more of a programming language • Nodes (Facts) vs Tags (Assessments) • Pivoting is Life! • Types of reasoning (if you want to be all philosophical…)

Slide 12

Slide 12 text

Using Synapse

Slide 13

Slide 13 text

Reading Aka Lifts.

Slide 14

Slide 14 text

Creating Making new stu ff the same way you look up stu ff , but with [ ]

Slide 15

Slide 15 text

Updating Just like creating, new stu ff in [ ]

Slide 16

Slide 16 text

Updating Just like creating, new stu ff in [ ]

Slide 17

Slide 17 text

Updating Just like creating, new stu ff in [ ]

Slide 18

Slide 18 text

Updating Or use a secondary command… like | note.add

Slide 19

Slide 19 text

Updating Or use a secondary command… like | note.add

Slide 20

Slide 20 text

Updating Or use a secondary command… like | note.add

Slide 21

Slide 21 text

Updating Or use a secondary command… like | note.add

Slide 22

Slide 22 text

Updating Or use a secondary command… like | note.add

Slide 23

Slide 23 text

Deleting Sometimes we make mistakes…

Slide 24

Slide 24 text

Automation Making stu ff happen without making stu ff happen… • Macros: A macro is simply a stored Storm query / set of Storm code that can be executed on demand. • Cron: Within Synapse, cron jobs are used to create scheduled tasks, similar to the Linux/Unix “cron” utility. The task to be executed by the cron job is speci fi ed using the Storm query language. • Triggers: Within Synapse, a trigger is a Storm query that is executed automatically upon the occurrence of a speci fi ed event within a Cortex (such as adding a node or applying a tag). “Trigger” refers collectively to the event and the query fi red (“triggered”) by the event.

Slide 25

Slide 25 text

Power-Ups Making data easy! • Power-Ups provide speci fi c add-on capabilities to Synapse via Storm Packages and Services. For example, Power-Ups may provide connectivity to external databases, third-party data sources, or enable functionality such as the ability to manage YARA rules, scans, and matches. • Can be built by hand, pulled from Synapse, or even added from 3rd parties.

Slide 26

Slide 26 text

Synapse Optic $$$

Slide 27

Slide 27 text

In Closing…

Slide 28

Slide 28 text

https://interpressecurity.com/

Slide 29

Slide 29 text

While I’m plugging stuff… bit.ly/idirv2

Slide 30

Slide 30 text

Resources • https://synapse.docs.vertex.link/en/latest/ • https://sroberts.io/posts/getting-started-with-synapse/ • https://sroberts.io/posts/e ff ective-tagging-in-synapse/ • https://vertex.link/

Slide 31

Slide 31 text

Thanks & Questions