取证指标聚合

原名:collecting-indicators-of-compromise

系统性地收集、分类和分发各类指标。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-25
TRACE 评分
3.4 / 5

内容概览

- During active incident response to identify and block adversary infrastructure - Post-incident to document all observed adversary artifacts for future detection - When sharing threat intelligence with ISACs, sector partners, or law enforcement - When building detection rules in SIEM, EDR, or network security tools - When enriching IOCs with threat intelligence context for risk scoring Do not use for behavioral TTP analysis without accompanying technical indicators; use MITRE ATT&CK mapping for behavioral characterization. - Access to incident evidence sources: SIEM logs, EDR telemetry, memory dumps, disk images, network captures - Threat intelligence platform (MISP, OpenCTI, ThreatConnect) for IOC management and sharing - IOC enrichment tools: VirusTotal, OTX (AlienVault Open Threat Exchange), Shodan, DomainTools - STIX 2.1 knowledge for structured IOC representation - Sharing agreemen…

查看 SKILL 详情