Кейсы и публикации
Публикация: Cyber OSINT — threat hunting, attribution, vulnerability intelligence, brand monitoring
Cyber OSINT Use Cases:
- Attack Surface Mapping: Subdomain enumeration (Amass, Subfinder), port scanning (Shodan, Censys), SSL cert transparency (crt.sh), technology fingerprinting (Wappalyzer, BuiltWith), cloud asset discovery (AWS/GCP/Azure metadata).
- Vulnerability Intelligence: CVE monitoring (NVD, GitHub Advisories, vendor advisories), exploit availability (ExploitDB, Metasploit, 0day.today), weaponization timeline, EPSS scoring для приоритизации патчинга.
- Threat Actor Tracking: Infrastructure mapping (passive DNS, WHOIS history, SSL cert pivoting), TTP profiling (MITRE ATT&CK), campaign clustering (malware config extraction, C2 protocol analysis), attribution confidence scoring.
- Data Leak & Credential Monitoring: Paste sites (Pastebin, Ghostbin), dark web markets, combo lists, stealer logs (RedLine, Raccoon, Vidar), GitHub/GitLab secrets (TruffleHog, Gitleaks), cloud storage exposure.
- Brand & Phishing Protection: Typosquatting detection (dnstwist), phishing kit tracking, logo/image abuse (reverse image search), fake social media accounts, mobile app impersonation.
Инструменты (Production Stack 2026):
- Passive DNS: DNSDB (Farsight), SecurityTrails, PassiveTotal
- SSL/Infrastructure: Censys, Shodan, ZoomEye, GreyNoise
- Vuln Intelligence: Vulners, VulnDB, Tenable.io, Qualys
- Dark Web: DarkOwl, Intel 471, Flashpoint, KELA
- Leaks: HaveIBeenPwned API, DeHashed, Intelligence X, custom stealer log parser
- Attribution: Maltego + custom transforms, VirusTotal Graph, AlienVault OTX
Воркфлоу Threat Hunting: Hypothesis → Data Collection (API/Scraping) → Enrichment (VT, OTX, PassiveTotal) → Clustering (graph analysis) → Attribution Scoring → IOC Generation → Detection Rules (Sigma, YARA, Snort) → SOC Handoff.
Скачать гайд (PDF + Sigma rules pack): pdf | sigma rules

