A security operations center (SOC) analyst is investigating an active phishing campaign. The analyst needs to rapidly collect publicly accessible domain registration details, IP reputation scores, and security blogs without requiring commercial licensing or sector-specific trust memberships. Which of the following intelligence source categories should the analyst consult?
- Open-Source Intelligence (OSINT)Cevap
- BInformation Sharing and Analysis Center (ISAC)
- CProprietary commercial threat feed
- DDark web threat actor forum profiling
Cevap
Open-Source Intelligence (OSINT)
Open-Source Intelligence (OSINT) refers to intelligence collected from publicly available resources, including WHOIS data, public code repositories, DNS records, and open security blogs, fulfilling the analyst's requirement for free and accessible data.
Adım Adım Çözüm
Anahtar Kavram
Threat Intelligence Sources - OSINT vs Closed Sources