A security operations team at a commercial enterprise needs to proactively monitor illicit underground marketplaces and non-indexed digital forums for stolen employee credentials and compromised API keys. Which threat intelligence source type best fulfills this requirement?
- Dark web threat intelligence feedsAnswer
- BNation-state threat actor motivation advisories
- CInline Web Application Firewall threat feeds
- DNational Vulnerability Database repository feeds
Answer
Dark web threat intelligence feeds are designed to monitor non-indexed networks and underground marketplaces for leaked organizational assets such as employee credentials.
Dark web threat intelligence specializes in crawling and analyzing darknets, hidden services, and invite-only criminal cyber forums. It allows organizations to proactively identify leaked sensitive data, such as compromised employee logins or secret keys, before attackers leverage them for initial access.
Step-by-Step Solution
Key Concept
Threat Intelligence Sources and Research