Profile picture
CYINT_dude @CYINT_dude
, 9 tweets, 2 min read Read on Twitter
I’m a proponent of writing things down. As #threatintel analysts, a big part of our job is recognizing patterns and making connections. But sometimes, we don’t see the connections. Our brains can’t recall as much information as we think they can (1/x).
This is why it’s imperative to document and memorialize your knowledge. Use your IOC database, your commercial TIP, OneNote, Excel, Wiki, IR ticketing system, whatever you have to capture artifacts, IOC, notes (2/x).
Tag your data (hopefully you have a consistent tagging scheme); organize it; capture enrichment data and attributes that may allow for future correlation. Does this take extra time? Is it annoying sometimes in the face of an active campaign or IR operations? You bet (3/x).
BUT. It’s an awesome experience when you start examining new activity. “Hmm this doesn’t look familiar.” But you import and organize your data and, Voila! A correlation on past activity! (4/x)
You’ll thank your past self for taking the extra time to capture these details. It’s exciting seeing the patterns that emerge without having to exert the extra brain power to mentally catalogue everything (5/x)
So by “wrote it down,” I don’t necessarily mean a book report. It could be as simple as a handful of IOC, an email header, and a quick note. In some cases you will need more “contextual media” like timelines, queries, screenshots, tables, graphs, etc. (6/x)
In that case, as a best practice, make sure the analyst can navigate from point A to point B. But the take away is document enough to enable future correlation (7/x)
How much and how far to I document? No solid answer here. But the more dangerous the threat, the more time I spend pivoting and capturing that enrichment data (8/x).
In closing, write things down! Your future self (and your colleagues who need your insights) will thank you! #threatintel
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to CYINT_dude
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member and get exclusive features!

Premium member ($30.00/year)

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!