The Art of Pivoting

A primer on investigation from one of the creators of Sigma.

So I’m finally reading this in EPUB form. Seems like solid theory so far, but I’m curious how we feel about the AIL Project that’s pushed pretty heavily in the text (same creator)?

I installed AIL and tried using it for a bit, but I am not quite the target audience for the tool. It provided some interesting artifacts that I was not getting in URL investigations via my sandbox like the things mentioned in the book (which I really enjoyed), but I have not yet really put those artifacts to good use.

Mostly I think that AIL is the wrong tool for collecting those artifacts in a SOC context. I think you can use some of the systems it is built ontop of to collect those artifacts but then storing and processing them to be later consumed by intel analysis is done by typical SOAR mechanisms.

That all being said I love the discussion on how intel artifacts can be collected and which ones can tell which stories. That kind of tradecraft is :cook: .