Главная
Study mode:
on
1
Intro
2
CTI, STIX, TAXI & STIX Preferred
3
Historical Timeline
4
STIX Data Model Key Concepts
5
Adversary Domain object: Campaign
6
Adversary Domain object: Intrusion Set
7
Adversary Domain Object: Threat Actor
8
Attack Based Properties - 2 Tips
9
TTP Domain object: Attack Pattern
10
TTP Domain object: Malware
11
TTP Based Properties - 2 Tips
12
Incident Response Properties - 2 Tips
13
Detection Domain object: Indicator
14
Detection Domain object: Observed Data
15
STIX 2.1 Enhancements
16
STIX 2.1 Confidence
17
Lime RAT Report Example...
18
Analysis & Mapping Lime Remote Access Tool 5
19
Threat Modelling Example #2...
20
TAXI 2 Key Definitions
21
TAXII 2 Key Definitions Continued
22
API Root Discovery
23
Collection Discovery
24
Collection Object Retrieval
25
Posting Data to a Collection
26
STIX v1 Interoperability Challenges
27
STIX TAXII 2 Preferred Introduction
28
STIX TAXII 2 Preferred - Persona
29
Learn More On Specifications & Tools...
Description:
Explore the latest standards for Cyber Threat Intelligence in this comprehensive conference talk from nullcon Goa 2019. Dive into the new features and changes of STIX/TAXII Version 2.0 and 2.1, including the Interop/STIXPreferred certification program. Learn about key concepts in the STIX Data Model, covering adversary domain objects, attack-based properties, TTP domain objects, incident response properties, and detection domain objects. Discover STIX 2.1 enhancements, including confidence levels, and examine real-world examples like the Lime RAT Report. Gain insights into TAXII 2 key definitions, API root discovery, collection management, and data posting. Address STIX v1 interoperability challenges and understand the STIX TAXII 2 Preferred introduction and persona. Presented by Allan Thomson, CTO of LookingGlass Cyber Solutions and co-chair of STIX/TAXII 2 Interoperability standards, this talk offers valuable knowledge for professionals in threat intelligence, security, and InfoSec fields. Read more

Introduction to STIX - TAXII 2 Standards

nullcon
Add to list
0:00 / 0:00