A SANS Webex I did... awhile ago?
Building EffectiveCTI Sharing
View Slide
Scott J Roberts
Comments? Use#ctisharingand/or@sroberts
Table Stakes
Talk to Legal
TLPhttps://www.us-cert.gov/tlp
● WWWWH&W● Example: My Story● What To Do Next?
Why?
Your SecurityWill Improve
You Will ImproveOthers Security
Share MoreGet More
A rising tideraises all boats
When?
Ingestion vs.Production
When You’reReady to Act
When You’re Readyto Reciprocate
When You Can BeConfident
Who?
Formal Groups
Open Source Groups
Informal Groups
BONUS: Orgs WithSimilar Technology...
BONUS: Competitors
What?
Indicators ofCompromise
Tactics, Techniques,& Procedures
Reports
Techniques,Methods, &Capabilities
(Legally Required) Pyramid of Painhttps://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html
Sharing Hierarchy of Value** The Author acknowledges this is a rip off
How?
Don’t Ask to Join
Be Trusting
Be Trustworthy
Be Action Oriented
BONUS: The BestGroups Have A WrittenSet of Expectations &Procedures
Where?
Mailing Lists
Chat
Semi Structured
Threat IntelligencePlatform
Hybrid
Example:My Story
This is Kyle@kylemaxwell
Kyle & Istarted a Slack
We Invited Folks We KnewShared Tools & TechniquesWe Invited More Folks
Kyle InvitedMark@markpars0ns
Mark InvitedMe to AnotherSlack
Met New FolksShared IntelligenceCollaborated On InvestigationsDemonstrated Value to My Boss
So I InvitedMy CoworkerJohn@swannysec
What ToDo Next?
What To Do Next●●●●●●
Go Make Friends &Share Intelligence
Join Me @SANS RockyMountain 2017for FOR578