Question
Group/section restrictions. Must post first. This week, we dive deeper into the practical aspects of Cyber Threat Intelligence (CTI), focusing on the extraction and analysis of Indicators of Compromise (IOCs) from real-world scenarios. Understanding and correctly identifying atomic, computed, and behavioral IOCs, and their relationship with MITRE ATT&CK Tactics and Techniques, is crucial for cybersecurity professionals. This exercise builds directly upon your foundational knowledge of MITRE ATT&CK and STIX introduced in Weeks 1 and 2. Scenario Overview: In Week 3, we present a challenging intrusion event that requires you to sift through narrative reports to identify atomic and computed IOCs. You will then progress to constructing behavioral IOCs from these findings and map them to specific ATT&CK Tactics and Techniques. This exercise aims to refine your analytical skills and deepen your understanding of the dynamic interplay between different types of IOCs and the broader strategic implications of cyber threat behaviors. Spoiler Alert: One of the MITRE ATT&CK Groups from Weeks 1 & 2 discussions conducted this attack! Task Description: Your task involves three main components: Identification and Listing of IOCS: Based on the scenario document (CYBV435_ioc_Scenario_3C.pdf in Cyber 3 content), identify and list the atomic and computed IOCs. You will have to do this for the quiz. So, get a head start on it in the discussion. Construction of Behavioral IOCS: Utilizing the identified atomic and computed IOCs, construct clear and concise behavioral IOCs. Each behavioral IOC should illustrate a narrative that describes a specific malicious behavior, incorporating relevant ATT&CK Tactics and Techniques. Mapping to MITRE ATT&CK: For each behavioral IOC you construct, map it to the corresponding ATT&CK Tactics and Techniques. Highlight how these IOCs provide insight into the adversary's objectives and methods. Questions to Consider: • How can atomic and computed IOCs be effectively integrated into behavioral IOCs to provide a more comprehensive view of an intrusion event? • What challenges do you encounter when trying to map behavioral IOCs to specific ATT&CK Tactics and Techniques? How can these challenges be overcome? • In what ways do behavioral IOCS enhance our understanding of threat actors and their methodologies compared to atomic and computed IOCS alone? Original Post Requirements: • Summarize your analysis and findings in a narrative format, incorporating discussion on the transition from atomic and computed IOCs to behavioral IOCs and their mapping to ATT&CK Tactics and Techniques. . . Provide examples from the scenario to illustrate your points. Pose at least one question to your peers to encourage further discussion./n 1 CYBV435_PQ3_SCENARIO_3C Extracting Indicators of Compromise from Narrative Reporting This week, we discussed extracting atomic, computed, and behavioral indicators of compromise (IOC) from narrative reporting. Mastering this skill is essential for all cyber professionals, particularly those interested in cyber intelligence. For this practical quiz (PQ), you must identify and list the IOCs by type in the scenario starting on the next page. About Hyperlinks in the Scenario Hyperlinks to additional background information are embedded in the text. Hyperlinks enclosed in {braces} lead to cyber industry resources. Follow and read these web pages to improve your understanding of the incident and general cybersecurity knowledge. Bookmark these sites for future reference. • Embedded Hyperlinks. You will find hyperlinks that provide additional background information throughout the text. Follow and read the web pages linked through these hyperlinks to deepen your understanding of the incident and general cybersecurity knowledge. These are crucial for understanding the context and technical details of the scenario. Industry Resource Links. Hyperlinks enclosed in {braces} specifically lead to valuable cyber industry resources. Bookmark these sites for future reference, as they are valuable resources for anyone in the field of cyber threat intelligence. These are not just optional reads; they are part of the learning experience for this PQ. By actively engaging with these links, you will answer the PQ more effectively and enrich your overall understanding of cybersecurity. CYBV435_PQ3_SCENARIO_3C IOC Scenario 3C This Indicators of Compromise (IOC) scenario has a difficulty level of 3 out of 5. The narrative report at this level will be unordered, and the sequence of events will be interspersed with moderate amounts of irrelevant information, such as additional software running on the compromised system or unrelated network traffic. Students sift through the noise to identify the relevant IOCs, put them into chronological order, and construct a coherent Behavioral IOC narrative. Scenario 2 Background Three notional aviation-industry companies, all headquartered in Cyberapolis with additional international branches, are pivotal to this scenario. You will not need all the details for this IOC activity, but they may be necessary for the attribution practical quiz in a later week. 1. Hitchcock Avia. This medium-size company provides unmanned aerial systems (UAS) to government and commercial entities. Two years ago {2014 in real-time}, Hitchcock Avia secured a contract to deliver McGuffin UAS vehicles to the Republic of Korea (ROK). Subsequently, they established a manufacturing plant in Daegu to produce the UAS vehicles. 2. AirHammett, Inc. A general aviation company, AirHammett specializes in twin- seat, propeller-driven airplanes. The company operates a dealership and service center in Riyadh, Saudi Arabia. 3. Hedren Aviation Supply. Recognized as a key supplier in the aviation sector, Hedren supports both Hitchcock Avia and AirHammett. An unknown Chinese company based in Shanghai provided most of Hedren's products. CYBV435_PQ3_SCENARIO_3C Relationships. Hitchcock and AirHammett operate in different market segments and maintain a friendly rapport. Hedren plays a vendor role for both. The leadership triad - Ms. Hammett of AirHammett, Mr. Hitchcock of Hitchcock Avia, and John Smith, the COO of Hedren share a U.S. Air Force background. Their bond has only strengthened over the years, as - evidenced by their annual visits with spouses to the EAA AirVenture show in Oshkosh, Wisconsin. Regular interactions like email communications and website visits are commonplace among these companies, and several employees have had tenure across all three firms. Your Role in the Scenario You are the newest member of the Security Operations Center (SOC). Here is the welcome message you received on your first day. Welcome to the Security Operations Center (SOC) at Hitchcock Avia! The SOC at Hitchcock serves as the central nerve of our cybersecurity efforts. As a medium-sized entity in the aviation sector, the need to protect our sensitive data, intellectual property, and operational systems is paramount. Our SOC is equipped with state-of-the-art technology and tools that monitor, assess, and defend our digital environments from potential threats 24/7. Staffed by a dedicated team of cybersecurity professionals, the SOC's primary objectives are to detect, respond to, and mitigate security incidents in real time. Our analysts closely monitor network traffic, user activities, and system behaviors for unusual patterns. Our incident response team springs into action when a potential security incident is identified, ensuring minimum disruption and risk to our operations. As a key hub for threat intelligence, the SOC also plays a role in proactively identifying vulnerabilities and strengthening our defense mechanisms. Collaborative efforts with 3 CYBV435_PQ3_SCENARIO_3C other departments ensure that the company is aware of and aligned with our security protocols and policies. As a new member of the SOC, you are now an integral part of a team that safeguards Hitchcock Avia's reputation, assets, and future. You will start on the Swing Shift from 5:00 p.m. to 2:00 a.m. Welcome aboard, and here's to fortifying our skies and systems! Narrative Report of Cyber Incident 4 This morning, Hitchcock's Intrusion Detection System (IDS) alerted on the exfiltration of a large amount of data from the machine of one of your company's senior engineers working on the UAS's guidance system. A quick-thinking security analyst stopped the exfiltration before too large an amount of data was compromised. The initial investigation into the incident shows that the senior engineer, Melanie Daniels, received an email bearing the subject line “AirHammett Job Oportunitees" [sic] {T1566}. The email contained a Portable Document File (PDF) attachment that, when opened, resulted in downloading a file called edg32.dll from http[:]//www[.] hedren [.] com/edg32[.] d11 to her machine {T1204.002}. This file subsequently established an encrypted connection to a host at IP address 104.151.248 [.] 173. {Internet Storce Center (ISC) / VirusTotal (VT)} The malicious email was sent from jsmith[@]hedren [.] com, and the attached PDF was named Available_Postions.pdf [sic]{T1544.001}. The edg32.dll file's encrypted connection to IP address 104.151.248 [.] 173 was established using an HTTPS connection {T1071.001} between port 8352 {IANA / ISC} on the victim machine and port 1913 {IANA / ISC} on the adversary's machine {T1571}. The malware then searched for accounts with a lockout threshold of zero {T1087}, saving that information to a file named wordsearch.xlsx. The edg32.dll then conducted a Boolean search of the infected system for document files using CYBV435_PQ3_SCENARIO_3C the string ".xls or .xlsx or .doc or .docx or .pdf" {T1083} and transmitted them to the previously mentioned C2 server. The PDF file had a Message Digest 5 (MD5) hash value of 4c18ea5860e91988aef25601fa4c7934e. The malicious downloaded DLL file had an MD5 hash value of 7c3243895a3de83ec48ead3271405849. The created XLSX file had an MD5 of e83ec43895a3d14058498ead3277c324. Timeline of Cyber Incident - Day 1 (Today's month and day in 2016) – Day Shift (9:00 am to 6:00 pm local time) 1. 09:00 AM: Melanie Daniels, a senior engineer, starts her workday and checks her email. 2. 10:15 AM: Melanie receives an email with the subject line "AirHammett Job Oportunitees" [sic] from jsmith[@]hedren[.]com. 3. 10:30 AM: Melanie opens the PDF attachment named "Available_Postions.pdf" [sic] from the email. 4. 10:32 AM: The PDF triggers the download of edg32.dll from http://www[.]hedren[.]com/edg32[.]dll. 5. 10:35 AM: edg32.dll establishes an encrypted HTTPS connection to IP address 104.151.248[.]173. 6. 10:40 AM: Hitchcock's Intrusion Detection System (IDS) alerts the Security Operations Center (SOC) about a potential data exfiltration from Melanie's machine. 7. 10:42 AM: A security analyst in the SOC identifies the alert and takes immediate action to stop the data exfiltration. 8. 10:45 AM: The security analyst isolates Melanie's machine from the network to prevent further data loss. 5
Question image 1