Giter Site home page Giter Site logo

tidalcyber / cyber-threat-profiling Goto Github PK

View Code? Open in Web Editor NEW
58.0 1.0 13.0 11 KB

A library of reference materials, tools, and other resources to aid threat profiling, threat quantification, and cyber adversary defense

Home Page: https://www.tidalcyber.com/ultimate-guide-to-cyber-threat-profiling

adversarial-attacks cybersecurity purpleteam ransomware risk threat-intelligence threat-modeling

cyber-threat-profiling's Introduction

Cyber Threat Profiling Resources

A library of reference materials, tools, and other resources to accompany The Ultimate Guide to Cyber Threat Profiling ebook, published by Tidal Cyber

"The concept of threat profiling offers the potential for threat prioritization, but even when security leaders choose to pursue it, misconceptions over its validity and utility and the lack of a clear and repeatable approach to profiling – as it relates to organization-wide threats – have all hampered its adoption. Even when teams do take steps to prioritize threats, efforts often prolong (in many cases indefinitely) or are impeded by a need for deep intelligence subject matter expertise."

The Guide was created to address each of these challenges, lower barriers to entry into cyber threat profiling, and drive its wider adoption.

Download the ebook here

The Ultimate Guide to Cyber Threat Profiling

Index

Frameworks & Methodologies

Cybersecurity & Cyber Threat Frameworks & Foundational Resources (General)

Threat Profiling/Modeling Frameworks & Methodologies

Adversarial Threat Profiling Guidance & Resources (General)

Threat Data Sources

Adversarial Threat Data (with Structured Metadata)

Niche & General Cyber Incident Data Sources

MITRE ATT&CK®

Working with ATT&CK Data

Threat Quantification

Threat-Informed Defense

  • Threat Informed-Defense Ecosystem start.me page: Living compendium of tools, trainings, & resources related to Threat-Informed Defense
  • Tidal Cyber Community Edition: A freely-available threat-informed defense platform for researching threat actors, building technique sets, and more. Community Edition users are able to share their work and participate in the larger Tidal Cyber community of defenders. (Transparency note: Tidal Cyber maintains this threat profiling resource repository!)

Detection Engineering, Threat Hunting, Adversary Simulation/Emulation, & Purple Teaming

Risk

Risk Resources (General)

Measurement & Estimation

Organizational Context

  • Developing Priority Intelligence Requirements: Guidance around alignment between elements of your organization’s business & strategy, its technological assets, and relevant risks (as they relate to the development of intelligence requirements)
  • U.S. SEC EDGAR Company Filings Database: Filings from public companies can be a great resource for surfacing high-level organizational priorities, objectives, and pressures (whether you are building a threat profile from inside or even outside of the organization (e.g. as an MSSP))

Workflow Resources & Tools

Cyber Threat Intelligence (CTI) Introductory Resources

MITRE ATT&CK® is a registered trademark of The MITRE Corporation

cyber-threat-profiling's People

Contributors

tropchaud avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.