by Mike Bunner (B'Ad Samurai)
The general workflow for many teams is to review, extract, and validate the IOCs within an intel document. Then deploy the validated IOCs to your tools: SIEM, endpoints, network, email, and other security boundaries.
This is a companion discussion topic for the original entry at https://ifin-intel.org/blog/ioc-distillation/
First cross-post from blog to forum! Whoo!
But also, this “distillation” concept has been living in my head rent-free since @BadSamurai started discussing it. I think it has to be the way we move forward as defenders, especially as atomics become more and more ephemeral.
We’ll be talking a lot more about this.
This is awesome. Thank you!
I already do steps 1, 5, and 6 as they are simple things to add and I often am able to verify their validity as I chase the rabbit down the hole. But I will absolutely start thinking about 4 and 7 more.