/* ---- Google Analytics Code Below */
Showing posts with label recorded future. Show all posts
Showing posts with label recorded future. Show all posts

Wednesday, June 14, 2023

China Invests in Open Source Intelligence from Pentagon

 Christopher Ahlberg writes:

@cahlberg    Thrilled to see the @nytimes   write up on the great research by the Insikt team at 

@RecordedFuture  Quote Tweet The New York Times @nytimes Jun 1

China is investing deeply in open-source intelligence from the Pentagon, think tanks and private companies to learn more about the capabilities of the U.S. military in the Pacific and beyond, according to a new report. https://nyti.ms/43iXyZQ   ...  '  

Tuesday, May 09, 2023

Recorded Future and AI

Like the combination of Recorded Future and AI.   Naturally useful. Check it out, I plan to.

Introducing Recorded Future AI: AI-driven intelligence to elevate your security defenses

Posted: 11th April 2023,    By: Kalpana Singh and Jake Munroe

The new world order combined with traditional challenges brings more complexity to security teams

The world is growing increasingly complex, and organizations can't keep up with the risk and exposures they face. This is due to factors like geopolitical instability, innovative cyber threats, ongoing and future wars, rampant software vulnerabilities, and more. The risks that organizations face are more daunting than ever, and the attack surfaces they face are more extensive. Risk is no longer siloed and it can impact multiple parts of the organization. The World Economic Forum Global Security Outlook for 2023 mentioned that “the character of cyber threats has changed and now believe that cyberattackers are more likely to focus on business disruption and reputational damage.”

But they also have to stay ahead of complexity. For example, the amount of data organizations must process and analyze is growing exponentially. This can be hard for talented cybersecurity and intelligence workers, because the speed and scale of threats is overwhelming and hard to keep up with. This is also not ideal for organizations when they are facing an acute shortage of cybersecurity talent. In fact, a recent report from ISC² states that there is still a need for more than 3.4 million security professionals, an increase of over 26% from previous year’s numbers.

Organizations face many problems, from strategic risks to traditional challenges. To keep up, they need to use technology to automate basic tasks and allow analysts to do the work they're good at, analysis.

This should be no surprise with all of the news and application of it recently, but this is where the power of AI can drastically help and is why analysts and leaders alike should be excited to safely and correctly adopt AI to have it work with them to ease the pain of the factors highlighted above.

introducing-recorded-future-ai-fig-1.png

Announcing Recorded Future AI — automating the intelligence cycle

Recorded Future has been a pioneer in the field of intelligence since its founding in 2009. Over the past decade, we have developed advanced algorithms and analytics for collecting, processing, and analyzing over 100 terabytes of text, images, and technical data into relevant, refined intelligence.

By leveraging this data, we have enabled organizations and governments to identify potential threats and vulnerabilities and take proactive steps to prevent attacks before they occur. This has been especially valuable in the context of complex cyber and physical threat landscapes, where traditional approaches to threat intelligence may not be sufficient. Our focus has been to automate the early stages of the intelligence cycle to flip the 80/20 principle - where analysts spend 80% of their time doing things like collection, aggregation, and processing and only 20% doing actual analysis. Imagine if 80% of their time was freed up to actually spend on analysis, reporting, and taking action to reduce risk and secure the organization?

Now, with the launch of Recorded Future AI, we are taking our capabilities to the next level, making the world’s largest intelligence repository, the Recorded Future Intelligence Cloud, smarter than ever. By integrating AI and machine learning deeper in the intelligence cycle in the analysis, production, and dissemination stages, Recorded Future AI is able to quickly identify and prioritize the most important threats and vulnerabilities, and provide actionable intelligence to analysts in real time. Leveraging the power of AI, we are now able to automate many of the time-consuming tasks involved in threat analysis, freeing up analysts to focus on higher-level strategic activities. ....


Wednesday, December 14, 2022

What is Threat Intelligence?

Considerable and mostly non technical look at the idea of 'Threat Intelligence'. Nicely done overview.    From Recorded Future, a former collaborator to our enterprise.

What is Threat Intelligence?

Digital technologies lie at the heart of nearly every industry today. The automation and greater connectedness they afford have revolutionized the world’s economic and cultural institutions — but they’ve also brought risk in the form of cyberattacks. Threat intelligence, often synonymous with open source intelligence (OSINT) is knowledge that allows you to prevent or mitigate those attacks. Rooted in data, threat intelligence provides context — like who is attacking you, what their motivation and capabilities are, and what indicators of compromise in your systems to look for — that helps you make informed decisions about your security.

“Threat intelligence is evidence-based knowledge, including context, mechanisms, indicators, implications and action-oriented advice about an existing or emerging menace or hazard to assets. This intelligence can be used to inform decisions regarding the subject’s response to that menace or hazard.” — Gartner

For more detailed overview of all things Threat Intelligence, download our comprehensive Threat Intelligence Handbook or keep reading below.

Why Is Threat Intelligence Important?

Today, the cybersecurity industry faces numerous challenges — increasingly persistent and devious threat actors, a daily flood of data full of extraneous information and false alarms across multiple, unconnected security systems, and a serious shortage of skilled professionals. Additionally, the attack surfaces organizations have to understand and protect are bigger now than ever before. Threats aren’t coming from one angle, organizations need to understand business risk from cyber attacks, physical security and operational disruptions, attacks on their reputation, and more.

Some organizations try to incorporate threat data feeds into their network, but don’t know what to do with all that extra data, adding to the burden of analysts who may not have the tools to decide what to prioritize and what to ignore.

A threat intelligence solution can address each of these issues. The best solutions use a combination of machine learning to automate data collection and processing, integrate with your existing solutions, take in unstructured data from disparate sources, and then connect the dots by providing context on indicators of compromise (IoCs) and the tactics, techniques, and procedures (TTPs) of threat actors.

Threat intelligence is actionable — it’s timely, provides context, and is able to be understood by the people in charge of making decisions.

Who Can Benefit From Threat Intelligence?

All security & risk teams and leaders! Threat intelligence is widely imagined to be the domain of elite analysts. In reality, it adds value across security functions for organizations of all sizes.

When threat intelligence is treated as a separate function within a broader security team rather than an essential component that augments every other function, the result is that many of the people who would benefit the most from threat intelligence don’t have access to it when they need it.

Security operations teams are routinely unable to process the alerts they receive — threat intelligence integrates with the security solutions you already use, helping automatically prioritize and filter alerts and other threats. Vulnerability management teams can more accurately prioritize the most important vulnerabilities with access to the external insights and context provided by threat intelligence. And fraud prevention, risk analysis, and other high-level security processes are enriched by the understanding of the current threat landscape that threat intelligence provides, including key insights on threat actors, their tactics, techniques, and procedures, and more from data sources across the web.  .... ' 

Thursday, May 19, 2022

Combatting Brand Exposures with Trusted Intelligence

 Trusted Brand Intelligence

Combatting Brand Exposures with Trusted Intelligence

APRIL 7, 2022 • ELLEN WILSON

The only way to stay one step ahead of the adversary is by knowing their intent, toolset, infrastructure, target – and using this intelligence to inform action. As discussed in the recent webinar Dark Web Exposures Brought to Light, mitigating digital risk to your brand is not simply a matter of stumbling across a typosquatting domain or some isolated piece of stolen data. Both automation and human expertise are essential to proactively collecting mass amounts of data, sifting through thousands of data points, analyzing relationships among the data points, deciding on priorities, and ultimately taking action. 

This is especially true when trying to understand your brand exposure on the dark web. The dark web is where criminals sell leaked company data, ransomware actors buy direct access to corporate networks, threat actors coordinate attacks, and more. As such, it is a mine of valuable intelligence, but sources, such as forums, can be volatile and hard to track — not to mention noisy. They also frequently present technical and financial barriers to entry, making it difficult, inefficient, time consuming, and risky for an organization’s security team to access the relevant information and context.

To ensure security teams have access to relevant, real-time context on their brand exposure, Recorded Future pairs automation capabilities with our expert research team, Insikt Group, within the Intelligence Graph in order to discover, analyze, and map associations across billions of entities in real time. Our expert analyst team confirms the accuracy of the machine-generated links, trains the machine on new or important data points, and adds their own human-generated links based on advanced research and robust collections of special-access and dark web sources, based on years of experience, perception, and awareness that no machine could provide. 

With Brand Intelligence from Recorded Future, security teams can then make fast, informed decisions based on the most current intelligence related to threat actors, internet infrastructure, and attack targets. By collecting and scanning from the broadest range and variety of sources — not only from open web sources, but also from the dark web and technical sources — security teams have access to insights from the attacker to their victims, and can be more proactive, strategic, and effective in carrying out their security strategy to uncover and respond to brand exposures. 

Unmatched Brand Intelligence

The latest updates to the Brand Intelligence module are designed to help security teams focus their precious time on the most important and urgent brand-related threats:

Continuous monitor the dark web and beyond

By automatically collecting, aggregating, and analyzing data from an unrivaled range of sources spanning the open, closed, deep, and dark web, security teams are able to proactively detect and take down malicious sites faster and more efficiently. The Brand Intelligence module includes extensive visibility into domain registration data, malware logs, messaging platforms, social media profiles, and web pages with malicious content, saving analysts time in understanding and responding to brand-related threats. ... ' 

Wednesday, November 17, 2021

Open Source Intelligence

 Interesting podcast from Recorder Future, approach was new to me.

Maximizing the Value of Open Source Intelligence

Recorded Future Blog - Predictive Analyt...by Caitlin Mattingly 

Podcast Episode 230

Our guest this week is Harry Kemsley. He’s president of national security and government at defense intelligence organization, Janes. Prior to joining Janes, he spent 25 years in the Royal Air Force.

Harry Kemsley is author of a recent opinion piece published in The Hill, titled “In OSINT We Trust?” In it, he makes the case that many intelligence organizations around the world would do well to increase their use of open source intelligence. To do that, there are cultural issues regarding the reliance on classified sources that may need to be overcome, but in the end, he believes the benefits are worthwhile. .... ' 

Friday, November 12, 2021

Need of Authentication

Key security component is doing this well.

Why Strong Digital Identity Authentication Is More Important Than Ever

OCTOBER 27, 2021 • THE RECORDED FUTURE TEAM

79% of organizations experienced an identity-related breach within the past two years alone. And 85% of cybercriminals accessed critical systems and data using stolen credentials. These numbers are a frightening wake-up call that all organizations are targets –regardless of size, market, or industry– and that bad actors are constantly looking for new ways to exploit and breach your company. 

Particularly over the past couple of years, the rise of new technologies and new ways of working has significantly expanded the playing field for cybercriminals. Here’s why:

Security practices are outdated: While most business now takes place outside the four walls of the office via cloud, SaaS, mobile and IoT, many organizations are still focused on securing the perimeter – an approach that can’t scale to support today’s highly distributed workforce and the cloud-based applications they need to access to be productive. 

Ecosystems are more dynamic and complex: Every person within your ecosystem – employees, partners and customers – is a target for cybercriminals looking to steal credentials and gain access to critical systems or information. Those players within your ecosystem likely don’t always follow password and security best practices. But, it is your responsibility to monitor and verify their identity authenticity at all times.

Security, Operations and IT Teams are overwhelmed: The rapid shift to a mostly remote workforce created a spike in required credentials, with more people needing access to critical business systems, platforms and channels via multiple devices. Today’s security and IT teams are overwhelmed and, admittedly, far less optimistic about their abilities to secure employee identities.

Take control with proactive, intelligence-led identity fraud detection

Identity protection plays a critical role within an overall security strategy, which is why 80% of organizations have increased their focus on identity security over the past year. While you can’t stop cybercriminals from attempting an attack, you can outsmart, outmaneuver and stop them with the right solutions, processes and policies in place. With an intelligence-driven approach to identity fraud prevention, you can proactively defend your organization against identity compromises in real time and take action before damage to the business is done. ... ' 

Wednesday, August 04, 2021

Blackmatter Interview

 I see that the Podcast 'Security Now' has now published the 'Blackmatter' interview with the Recorded Future company.   We did some work with Recorded Future at the enterprise. The interview, I think is revealing regarding ransomware approaches and future.  See: 

https://twit.tv/shows/security-now/episodes/830?autostart=false    (Contains interview script) 

SECURITY NOW 830:  THE BLACKMATTER INTERVIEW

Hosted by Steve Gibson, Leo Laporte:  Bad News for Firefox, DarkSide Returns, Tailscale, Google to Assume HTTPS

Records live every Tuesday at 4:30pm Eastern / 1:30pm Pacific / 20:30 UTC.

Wednesday, May 19, 2021

Malware Tricks

 Recorded Future, a podcast and text. With a look to the future of cybersecurity. This is an area where you are likely to see advanced tech applied, for good and bad.  

Malware Party Tricks and Cybersecurity Trends

APRIL 26, 2021 •  Caitlin Mattingly

This week we welcome back to our program security pioneer Graham Cluley. After starting his career writing the original version of Dr. Solomon’s Antivirus Toolkit for Windows, Graham moved on to senior positions at Sophos and McAfee. In 2011 he was inducted into the Infosecurity Europe Hall of Fame. These days, he’s an independent blogger, podcaster and media pundit.

Our conversation takes a sometimes nostalgic look back at the origins of computer malware, what it was like fighting the good fight back then, how things have developed over the years, and what he thinks the future may hold.   ... " 

Sunday, April 18, 2021

Evolution of Ransomware and Related Extortion

Thoughtful podcast and transcript from Recorded Future, Telling the evolution of extortion methods and responses.

Ransomware and Extortion Evolve More Brazen Tactics  By Caitlin Mattingly   of Recorded Future.

For this week’s show we welcome back Allan Liska, a member of Recorded Future’s CSIRT security team. Allan updates us on the latest trends he and his colleagues are tracking on the ransomware and online extortion fronts. We discuss the growing sophistication of the tools and tactics attackers are using, and the remarkable brazenness with which they do their business.... " 

Saturday, March 13, 2021

IBM and Recorded Future Threat Webinar

Reported yesterday, have often mentioned Recorded Future now working with IBM on threat management here.  See upcoming Webinar, mentioned at the link.  

IBM Security and Recorded Future: Better Together  by Ellen Wilson

Today, IBM Security and Recorded Future are joining forces in a live webinar, Better Together: IBM Security + Recorded Future, to support security operations teams in developing an end-to-end threat management and security operations strategy. Now more than ever, speed to detect, investigate and remediate threats is key to reduce dwell time and impact of security cyberattacks. Register now to see how a tightly integrated end-to-end process of threat management can improve your team’s ability to make decisions quickly and mitigate risk.   ... '

Monday, March 08, 2021

Podcast: How Spies Think

At the link, podcast provided by Recorded Future, who we worked with long ago.  The link below leads you to the podcast.  Makes me think:  How do spies think differently, say since before computing?  Is that useful from a security perspective?   Will listen to the podcast, and likely read the book. 

A Call to Arms In Favor of Rationality   By  Caitlin Mattingly Recorded Future

Our guest this week is Sir David Omand. He is former director of GCHQ, one of the UK’s primary intelligence agencies, and is currently Visiting Professor in War Studies, King’s College London.

We’ll be discussing his career in intelligence and public service, the changes he’s seen along the way, and we’ll discuss his most recent book How Spies Think: 10 Lessons from Intelligence.  ... 

This podcast was produced in partnership with the CyberWire.  ... ' 

Monday, December 21, 2020

Security with Threat Hunting

Is this ultimately the means to thwarting security failures?

Threat Hunting Offsets the Technology Gaps

Caitlin Mattingly, Recorded Future

Our guest this week is John Ayers, Executive Vice President, Chief Strategy Product Officer and head of Security Operations at Nuspire, a managed security services company.

Our conversation centers on John’s assertion that threat hunting has become an indispensable element of security strategy for many organizations. He explains the evolution of threats that led him to that conclusion, and we’ll discuss how organizations can best approach implementing threat hunting into their own defensive plans.

This podcast was produced in partnership with the CyberWire.  ...   

Friday, November 27, 2020

Recorded Future Offers Handbook

 From a company we connected with in their early days, have not read this yet, looks to be of general interest.

Get Your Handbook for Disrupting Adversaries and Reducing Risk

OCTOBER 15, 2020 • THE RECORDED FUTURE TEAM

If 2020 taught the security industry anything, it is this: There has never been a better time to be a cybercriminal. From extortion ransomware to cyberespionage campaigns, adversaries are capitalizing on uncertainty, causing chaos, and cashing in.

The only defenders who will win are the ones focused on proactively disrupting attackers’ activities.

Security intelligence is an outcomes-centric approach to reducing risk. It fuses internal and external threat, security, and business insights across an entire organization — and it is the most powerful weapon defenders have against threat actors. Now, there’s a handbook on security intelligence to guide you in this battle!   ... 

Friday, November 20, 2020

Insikt Group to Reduce Risk

Like the idea of risk reduction being specifically included, rarely done well enough, and especially  useful ly and measurably.   Just brought to my attention.

How Insikt Group’s Operational Outcomes Team Drives Action to Reduce Risk  By Lindsay Kaye

I’m Lindsay Kaye, the director of operational outcomes for Insikt Group®. Insikt Group as a whole produces analyst-generated insights to generate validated intelligence sources within the Recorded Future® Platform. Insikt Group also performs novel security intelligence research in a variety of different areas, including nation-state threat actor groups, threat actors operating in the criminal underground, and all manner of technical topics.

Simply put, the operational outcomes team creates insights that drive action that can be taken to reduce the risk associated with an identified threat. Our team also specializes in technical research, supporting our own focus area and other specialized teams within Insikt Group.  ... " 


Monday, November 09, 2020

Podcast from Recorded Future on Trickbot

Been following the security implications.  Here a podcast by former security connections at Recorded Future on the topic: 

Trickbot is Down But Not Out    By Caitlin Mattingly

On today’s podcast episode we welcome back Recorded Future’s senior intelligence analyst Greg Lesnewich.

He shares his insights on what goes on behind the scenes with the Recorded Future’s Insikt Group   , and why he finds the work challenging and rewarding. Then, we discuss the latest on the Trickbot global botnet, how they operate, who they target, and the efforts by the intelligence community and private industry to take them down, or at the very least hinder their efforts.  ... "

Wednesday, July 01, 2020

Reduced Attack Surfaces

Quite a term: ... Attack Surfaces ... so government .... but a real issue now.   A former connection, 'Recorded Future' does a good job of talking it in the article pointed to below:

Reducing the Remote Education Attack Surface With Security Intelligence
JULY 1, 2020 • THE RECORDED FUTURE TEAM

This year, stay-at-home mandates issued by U.S. states and countries across the world for K-12 schools and higher-ed institutions created major challenges for educators, students, and families. Moving the entire education process online also opened a Pandora’s Box for security teams at education institutions.

This shift dramatically expands the attack surface for threat actors to go after — with ed-tech platforms, e-learning environments, video conferencing, email accounts, and websites managed by schools all presenting appealing targets. The amount of time students, teachers, and administrators spend connected to these environments will continue to be high in the coming months.  ... " 

Friday, May 15, 2020

Automating Threat Detection

Recorded Future talks about thread detection and response.   Recall we tessted some of their methods and wrote about them here in their early days.  Worth a look.   Much more at the link.

Automating Threat Detection and Response With Security Intelligence
• Recorded Future Team

Automating threat detection and response has historically been a very expensive and time-consuming process. However, with the prevalence of restful Application Programming Interfaces (APIs), commercial threat intelligence, and crowd-sourced feeds, it has never been easier and more cost effective to do so. Through careful thought and a little bit of Python, organizations can begin to adopt automation into their defenses.

Whether an organization is just starting to build its security capabilities or looking to bolster existing controls, there is much that can be achieved. By combining automation with security intelligence, and applying that to existing infrastructure, an organization can greatly improve their security posture.

Start Automating Security With DNS

Domain Name System (DNS) is essential to both the internet and private networks, but it’s a common service that can be overlooked when seeking to build a threat detection and response capability. DNS is frequently deployed as a centralized service, with visibility of the clients making requests, as well as the domains and Internet Protocols (IPs) being requested and returned — an ideal candidate when seeking ways to detect and respond to potential threats.

The Response Policy Zone (RPZ) is a function supported by most modern DNS servers, and provides a custom reply for any domain or IP address — aiding automated detection and response controls. If a client makes a request for something that is in the RPZ, a predetermined response can be returned. Combining security intelligence with an RPZ can supercharge what is commonly referred to as a DNS firewall by providing a broad effective coverage, which enables automated detection and response to the latest threats.

The first point of consideration when deciding to deploy an automated DNS blocking capability, is where the domains and/or IP addresses to be blocked can be sourced, and more importantly, how trustworthy those sources are. Crowd-sourced security intelligence is widely available — but might not contain the latest threats that could impact a business. In addition, poorly curated or maintained feeds such as those containing illegitimate destinations may impact an organization’s productivity.

In comparison, a curated intelligence feed — specifically, one regularly maintained in real time through automation — will more likely contain information about current infrastructure used by advanced attackers, along with additional context that can expedite the decision-making processes.  ...  "

Saturday, December 21, 2019

Recorded Future Engine for Security Intelligence

Interesting look at an analytical and visual approach that is worth a look. Note the long term use of data, and the Digital Twin model evoked.

The Engine RF Uses for  Security Intelligence Explained  By  Staffan Truve

Recorded Future captures all information gathered from the internet for over a decade and makes it available for analysis in a structured and organized way. We call this the Security Intelligence Graph, and it is at the heart of all services offered by Recorded Future.

Having all information readily available in the Security Intelligence Graph offloads a tremendous amount of work from analyst teams. It could take an organization thousands of man hours to build out a fraction of what is now available, and that time can instead be spent on analysis. By adding their own analyst notes, security teams can even connect their own findings to the Security Intelligence Graph. Navigation in the graph is what powers the easy pivoting between different views in the Recorded Future® Platform, and relationships in the graph underlie the risk score calculations that enable analysts to make quick, informed decisions.

To make full use of Recorded Future, it helps to have a good understanding of our underlying data model and design philosophies — explaining this is the purpose of this blog. The following is an excerpt from our Security Intelligence Graph white paper. To read the full white paper, download your complimentary copy today.

The Security Intelligence Graph Explained

Just as many industrial companies today are creating “digital twins” of their products, we aim to build a digital twin of the world, representing all entities and events that are talked about on the internet — with a particular focus on threat intelligence. The Security Intelligence Graph is that representation of the world, and our goal is to make this information available at the fingertips of all security analysts to help them work faster and better. ... "

Tuesday, September 10, 2019

Third Party Risk Analysis

Recorded Future writes about the topic.  We examined them for things like competitive risk.   But this topic, especially in today's realm of many technology mal-players, large and small, makes the issue of particular importance.   Below just an intro, much more at the link.

Third-Party Risk Intelligence: Past and Present
SEPTEMBER 10, 2019 • THE RECORDED FUTURE TEAM

After months of searching, budgeting, and vetting, you’ve found the perfect vendor to help take your product offering to the next level. You’re excited to start working together and you’ve initiated the onboarding process. The company has provided the requisite new vendor questionnaires and documentation, and your governance, risk, and compliance (GRC) system has assessed the company for risk and found its current risk score to be acceptable. Everything seems in order.

But what you don’t know is that your soon-to-be partner was the target of a highly stealthy and successful malware attack just nine months ago. They may have taken the appropriate steps to resolve the incident, but wouldn’t you still want to be aware of it?  .... " 

Tuesday, September 03, 2019

Making Threat Intelligence Actionable

Worked with Recorded Future Early on.   One of my jobs was to translate threats to execs.   Here is the last piece of their threat intelligence outline for executives.  Really the most essential part, how do you communicate threats to decision makers?   Links to all of the pieces at the link below:

Making Threat Intelligence Actionable at the Executive Level (Part 3)
Recorded Future Team

This is the last blog in a three-part series discussing how threat intelligence information can be communicated to C-level executives and the board of directors. In our first blog, we examined the information that security teams need to compile and communicate. In our second blog, we presented the information that the C-suite and the board can glean in reaction to the threat intelligence provided by the security team.

This blog outlines how a threat intelligence solution helps CISOs present information in a way that executives can easily interpret and take action such that the company is prepared to defend against attacks targeting their IT assets and sensitive information.  ... "