Кейсы и публикации

Публикация: Cyber OSINT — threat hunting, attribution, vulnerability intelligence, brand monitoring

Cyber OSINT Use Cases:

  1. Attack Surface Mapping: Subdomain enumeration (Amass, Subfinder), port scanning (Shodan, Censys), SSL cert transparency (crt.sh), technology fingerprinting (Wappalyzer, BuiltWith), cloud asset discovery (AWS/GCP/Azure metadata).
  2. Vulnerability Intelligence: CVE monitoring (NVD, GitHub Advisories, vendor advisories), exploit availability (ExploitDB, Metasploit, 0day.today), weaponization timeline, EPSS scoring для приоритизации патчинга.
  3. Threat Actor Tracking: Infrastructure mapping (passive DNS, WHOIS history, SSL cert pivoting), TTP profiling (MITRE ATT&CK), campaign clustering (malware config extraction, C2 protocol analysis), attribution confidence scoring.
  4. Data Leak & Credential Monitoring: Paste sites (Pastebin, Ghostbin), dark web markets, combo lists, stealer logs (RedLine, Raccoon, Vidar), GitHub/GitLab secrets (TruffleHog, Gitleaks), cloud storage exposure.
  5. Brand & Phishing Protection: Typosquatting detection (dnstwist), phishing kit tracking, logo/image abuse (reverse image search), fake social media accounts, mobile app impersonation.

Инструменты (Production Stack 2026):

  • Passive DNS: DNSDB (Farsight), SecurityTrails, PassiveTotal
  • SSL/Infrastructure: Censys, Shodan, ZoomEye, GreyNoise
  • Vuln Intelligence: Vulners, VulnDB, Tenable.io, Qualys
  • Dark Web: DarkOwl, Intel 471, Flashpoint, KELA
  • Leaks: HaveIBeenPwned API, DeHashed, Intelligence X, custom stealer log parser
  • Attribution: Maltego + custom transforms, VirusTotal Graph, AlienVault OTX

Воркфлоу Threat Hunting: Hypothesis → Data Collection (API/Scraping) → Enrichment (VT, OTX, PassiveTotal) → Clustering (graph analysis) → Attribution Scoring → IOC Generation → Detection Rules (Sigma, YARA, Snort) → SOC Handoff.

Скачать гайд (PDF + Sigma rules pack): pdf | sigma rules


← Назад к списку новостей