A security operations team is refining its threat intelligence research workflow during an active incident investigation involving suspicious PowerShell scripts executed on an endpoint. An analyst needs to correlate newly identified command-and-control (C2) domains against publicly accessible registration data, historic passive DNS records, and peer-reviewed technical blogs without transmitting internal organization telemetry to external partners or incurring subscription fees. Which of the following threat intelligence source categories best satisfies these operational constraints?
- Open-Source Intelligence (OSINT)Cevap
- BInformation Sharing and Analysis Center (ISAC) feeds
- CCommercial or proprietary threat intelligence feeds
- DNational Vulnerability Database (NVD) records
Cevap
Open-Source Intelligence (OSINT) is the correct choice because it relies entirely on publicly available resources such as WHOIS databases, open passive DNS repositories, and public research write-ups without requiring subscription costs or sharing sensitive internal telemetry.
Open-Source Intelligence (OSINT) refers to intelligence derived from publicly accessible information, including WHOIS registries, open passive DNS databases, threat research publications, and code repositories. It allows analysts to research infrastructure indicators freely and passively without transmitting private incident data to third parties.
Adım Adım Çözüm
Anahtar Kavram
Threat Intelligence Sources (OSINT vs. Closed/Proprietary vs. ISAC vs. Vulnerability Databases)