A threat intelligence analyst at a cloud service provider is tasked with obtaining early-warning indicators regarding unpatched, zero-day vulnerabilities currently being offered for sale by illicit actors prior to public disclosure. Which threat intelligence source type should the analyst primarily monitor to fulfill this requirement?
- Dark web threat intelligence feedsAnswer
- BOpen-Source Intelligence (OSINT) repositories
- CNational Vulnerability Database (NVD) CVE entries
- DStrategic nation-state threat actor attribution reports
Answer
Dark web threat intelligence feeds serve as the primary source for monitoring illicit marketplaces and closed underground communities trading unpatched vulnerabilities and zero-day exploits.
Dark web threat intelligence involves monitoring underground markets, specialized forums, and anonymized networks where threat actors actively buy, sell, and share zero-day vulnerabilities, stolen credentials, and custom attack tooling before the broader cybersecurity community becomes aware of them.
Step-by-Step Solution
Key Concept
Threat Intelligence Sources (Dark Web vs. OSINT vs. Vulnerability Databases)
Estimated Time:1m 0s