A lead security analyst at a online retail enterprise is evaluating threat intelligence options to proactively detect compromised corporate credentials being offered for sale on subterranean marketplaces. The organization requires actionable, curated threat feeds with tailored risk scoring and automated API integration to ingest indicators of compromise (IOCs) without dedicating internal staff to manually monitor dark web forums. Which threat intelligence source type should the analyst recommend to meet these requirements?
- Commercial threat intelligence feedAnswer
- BOpen-source intelligence (OSINT)
- CSector-specific Information Sharing and Analysis Center (ISAC)
- DNational Vulnerability Database (NVD)
Answer
Commercial threat intelligence feed
Commercial threat intelligence feeds are subscription-based services provided by security vendors who deploy dedicated researchers and automated tools to monitor dark web forums, paste sites, and subterranean channels. They curate this raw data, enrich it with contextual risk scores, and deliver actionable indicators automatically through API integrations, fulfilling all specified organizational criteria.
Step-by-Step Solution
Key Concept
Distinguishing characteristics and operational use cases of Commercial/Proprietary Threat Intelligence feeds compared to OSINT, ISACs, and Vulnerability Databases.
Estimated Time:2m 0s