Sep 23, 2026Building an Intelligence Plan WorkshopOn September 23rd, Intel 471’s SVP of Intelligence Operations, Garrett Carstens, and Senior Director of Customer Engagement, Kevin Williams will lead the half-day workshop.
Sep 16, 2026Threat Hunting Workshop: Hunting for Discovery - Level 2Build confidence identifying discovery behaviors by applying structured hunting techniques across realistic datasets in this Level 2 workshop.
Aug 26, 2026Operation Fake KickOff: Fake Recruiters, Real Credential TheftA closer look at Operation Fake KickOff, a phishing campaign using fake recruiter identities and interview scheduling pages to hijack corporate sessions and bypass MFA in real time.
Aug 17, 2026The New Strategic Arena: AI and Geopolitics Ryan Grace, Geopolitical Analyst II at Intel 471, unpacks AI's role in U.S.-China rivalry, sovereign AI, and nation-state cyber threats.
Jul 29, 2026Know Thy Environment: Putting Your Data to WorkA podcast episode discussing data dictionaries, field mapping, baselining, and the visibility gaps that shape every hunt.
Jul 28, 2026Poisoned Trust: How Supply Chain Attacks Weaponize Developer EcosystemsSoftware supply chain attacks continue to evolve, with one worm lineage changing how attackers target developers.Download PDF
Jul 21, 2026AI’s Impact on the Vulnerability Landscape: Current State and OutlookThis webinar covers AI's current and emerging impact on vulnerability discovery, exploit development, and what it means for how security teams prioritize and respond.
Jul 1, 2026Threat Hunt Report: Q2 2026 A practitioner-focused report on the behaviors, tradecraft, and trends that shaped Q2 2026 and what they mean for threat hunters.Download PDF
Jun 24, 2026Threat Hunting Workshop: Hunting for Credential Access - Level 2A fully interactive, hands-on workshop where threat hunters work through real credential access scenarios using real data.
Jun 17, 2026Threat Hunting Management Workshop 8: Building the Bridge Between Intelligence and the HuntA leadership-focused discussion on turning CTI and threat hunting from parallel efforts into a connected operating model.
Jun 9, 2026Recruit, Dupe and Coerce: How Threat Actors Are Targeting Cloud InsidersThis Intel 471 report delivers a comprehensive look at how cybercriminals exploit, manipulate and recruit cloud insiders, and what organizations can do to reduce their exposure.Download PDF
Jun 2, 2026FIFA 2026 World Cup: Top Cyber ThreatsThis report takes an activity-centric view of threats based on our underground observations. We map the most likely threats to four primary target categories: event participants, corporate sponsors, host city entities and essential tournament infrastructure.Download PDF
May 28, 2026Know Thy Environment: Building Context for Effective Threat HuntingThis live episode focuses on how to profile your environment, work through both existing and newly onboarded datasets, and build a clear picture of what normal actually looks like across your telemetry.
May 22, 2026The 2026 SANS Cyber Threat Intelligence Survey What CISOs Want: Intelligence-Driven DecisionsThis year's SANS CTI Survey reveals where CTI programs are falling short of executive expectations, and what leading teams are doing to close the gap. Download PDF
Apr 22, 2026Intelligence-Driven Threat Hunting Workshop: Vulnerability Post-Exploitation BehaviorsA hands-on, intelligence-driven workshop on how vulnerabilities gain traction, move toward exploitation and can be investigated through live threat hunting.
Apr 20, 2026Ransomware negotiations: What CISOs should know before negotiatingThis report breaks down how negotiations work in practice and what CISOs should expect across the full lifecycle—from first contact to either payment and decryption or public data exposure on a leak site.Download PDF
Apr 15, 2026Threat Hunt Report: Q1 2026 A practitioner-focused report on the behaviors, tradecraft, and trends that shaped Q1 2026 and what they mean for threat hunters.Download PDF
Apr 14, 2026The Escalation of KYC Bypass in Financial ServicesThis 45-minute briefing examines the modern KYC bypass landscape, detailing the tools, deepfake technologies, and identity fraud techniques adversaries use to exploit digital onboarding processes.
Apr 8, 2026Enterprise Cyber Risk in Latin America: Criminal Ecosystems and State OperationsHow criminal ecosystems and state linked activity in Latin America are shaping enterprise cyber risk.
Mar 25, 2026Guess Who: The Malware EditionA live, interactive malware analysis challenge where you follow behavioral clues in real time and determine which malware family is behind the campaign before the final reveal.
Mar 18, 2026Threat Hunting Management Workshop: Rethinking PriorityExplore how to prioritize threat hunting based on visibility gaps, detection coverage, and unknown risk rather than severity alone, providing a structured framework for building measurable and sustainable program maturity.
Mar 15, 20262026 Phishing Outlook: From Credential Theft to Network IntrusionThe 2026 Phishing Outlook: From Credential Theft to Network Intrusion is a comprehensive analysis of the evolving phishing landscape in the cyber underground. Download PDF
Mar 11, 2026Ni8mare or Noise? Evaluating the Real Risk of CVE 2026-21858An intelligence-driven analysis of CVE-2026-21858 (“Ni8mare”) to determine whether its 10.0 severity translates to real-world exploitation risk.
Feb 13, 2026Region Report: Latin America 2025Intel 471’s report dissects the Latin America threat landscape to clarify what changed in 2025, how adversaries operate and what defenders should prioritize next.Download PDF
Feb 11, 2026Threat Hunting Workshop: Hunting for Privilege Escalation - Level 2Build confidence identifying privilege escalation behaviors by applying structured hunting techniques across realistic datasets in this Level 2 workshop.
Feb 3, 20262026 Cyber Threat Trends & OutlookExplore our comprehensive assessment of 2025’s cyber threat landscape and a forward-looking view of what these developments signal for defenders in 2026.Download PDF
Jan 30, 2026Threat Hunting Year in Review: 2025 Trends and What’s NextJoin a live, interactive threat hunter’s year in review as we break down the trends that defined 2025 and what they signal for the year ahead.
Dec 16, 2025Battling check fraud in the U.S.Eric Huber is Cybercrime Research Leader with TD Bank. In this Studio 471, he discusses why check fraud is such a huge problem in the U.S. and how banks can counter it.
Dec 12, 2025Cybercrime Exposed: The Hacker Who Slipped AwayA Russian cybercriminal known for his circuit board tattoo is forced to confront the consequences of his outspoken criticism of his homeland after authorities pursue him for his involvement in online theft.
Dec 3, 2025Intelligence-Driven Threat Hunting Workshop: Operationalizing Geopolitical IntelOn December 3, 2025, this workshop shows how geopolitical context can directly inform and shape real threat hunts, guiding analysts from strategic insight to practical hunt execution.
Nov 24, 2025Black “Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector This Holiday Season.Download PDF
Nov 21, 2025Frost & Sullivan Executive BriefTransforming Cyber Threat Intelligence (CTI) into Action: The Case for an Integrated CTI Platform from Intel 471Download PDF
Nov 19, 2025Guess Who: The Adversary EditionA live, interactive episode of Out of the Woods: The Threat Hunting Podcast where hosts walk through a real nation-state campaign step by step, revealing tradecraft clues and behavioral patterns as attendees analyze the evidence and attempt to identify the adversary before the final reveal.
Oct 30, 2025Tracking down The ComIn this Studio 471, Michael Fletcher, a former Cybercrime Technical Analyst with the Australian Federal Police, describes the origin of The Com and how threat actors in this sphere pose a threat.
Oct 29, 2025Threat Hunting Management Workshop: The Business Value of Threat HuntingOn October 29, Sr. Threat Hunt Analyst Scott Poley will share how security leaders can demonstrate the business value of threat hunting and show measurable results, even with limited resources.
Oct 6, 2025Precision Deception: Rise of AI-Powered Social EngineeringRead our report Precision Deception: Rise of AI-Powered Social Engineering, which offers Intel 471’s comprehensive analysis of the growing role of AI in supporting social engineering schemes.Download PDF
Oct 2, 2025Detecting cybercriminal activity on TelegramTelegram hosts significant cybercriminal activity. In this Studio 471, Sayak Saha Roy of Louisiana State University discusses a research project leveraging a language model that can identify cybercrime-related postings.
Sep 24, 2025Threat Hunting Workshop 16: Hunting for Persistence – Level 2On September 24, 2025, from 12:00–1:00 PM ET, this hands-on workshop will strengthen your skills in detecting persistence techniques that adversaries use to maintain long-term access.
Sep 11, 2025AI for Security Teams: Scaling Impact Without Losing ControlThe next live Out of the Woods: The Threat Hunting Podcast explores how AI is reshaping security operations, from insider threat detection to faster triage and incident response. We’ll cover practical wins, common pitfalls, and the critical role of human expertise, while addressing risks like hallucinations, bias, and deepfake-enabled attacks.
Aug 27, 2025Drawing value from cyber threat intelligenceKobe Shwartz is a former Russian cybercrime analyst who is the Head of Cyber Threat Intelligence and Analysis at Signify. In this Studio 471, he discusses how to structure a CTI program and measure return on investment.
Aug 26, 2025An Anatomy of “Pig-butchering” ScamsSo-called “pig-butchering” scams have evolved into highly complex and profitable operations. Intel 471’s latest intelligence report dissects the structure of these scams, showing how threat actors leverage artificial intelligence (AI) and the cyber underground to enhance their operations’ scale and effectiveness.Download PDF
Aug 15, 2025Cybercrime Exposed Podcast: The Duke is DeadDukeEugene is a Russian hacker, heavily tattooed with a large swastika on his chest. He specializes in developing malicious software for Android phones.
Jul 29, 2025The Black Basta BlueprintA deep-dive into the leaked internal chat logs for the Black Basta ransomware group and demonstrate how our expert analyses of the group’s malware tools and tactics, techniques, and procedures (TTPs) can be operationalized to harden your defenses against future attacks.Download PDF
Jul 22, 2025Defending against doxingIn this Studio 471, Jacob Larsen discusses the effects of doxing, how sites like Doxbin take advantage of legal loopholes and how to defend against being doxed.
Jun 25, 2025Intelligence-Driven Threat Hunting Workshop: Analyzing Malware BehaviorsJoin Intel 471 On July 31, 2025 from 11:00 AM - 1:00 PM ET for a live, hands-on workshop that bridges malware intelligence and threat hunting. Learn how to extract IOAs from real reports and apply the
Jun 22, 2025UK 2025 Threat Landscape ReportThe U.K. government announced their plans to introduce the landmark “Cyber Security and Resilience Bill”. Designed to elevate national security standards and protect critical infrastructure, it places greater responsibility on organisations to manage and withstand cyberattacks.Download PDF
Jun 17, 2025The Intersection of AI and Threat Hunting: What Problems Emerge, What Problems Get SolvedA live episode exploring how AI is being applied in threat hunting workflows, what problems it helps solve, and where new challenges are emerging.
Jun 4, 2025Top Cybercrime Threats Targeting the Automotive IndustryThe automotive industry faces increasing cybercrime threats that are impacting organizations throughout the sector. Understanding these risks is crucial for safeguarding assets and operations.Download PDF
May 28, 2025Fingerprinting threat actors by their anonymity techniquesCybersecurity consultant Mick Deben of DMC Group created a knowledge base of attacker anonymity techniques for his master’s thesis. In this Studio 471 podcast, he discusses how practitioners can use it to fingerprint threat actors.
May 27, 2025Threat Hunting Management Workshop: Structuring Collaboration Across TeamsDiscover how better coordination across teams can increase the impact of your threat hunting program. Register now for our June 18 workshop and earn your Cross-Team Collaboration certificate.
May 21, 2025Executive Brief: Cyber Threat Intelligence for C-Suite Strategic GoalsThis Intel 471 paper is purposefully designed to assist senior business executives who increasingly instruct and influence CTI priorities according to findings from the survey.Download PDF
May 14, 2025The Business Value of Threat HuntingThreat hunting has become indispensable for finding advanced criminal, nation-state, and state-backed threats that use popular techniques to evade detection.Download PDF
May 14, 2025SANS 2025 Threat Hunting Survey: Staged for SuccessIn this paper, we examine these major trends in detail, and explore how Intel 471’s HUNTER platform provides solutions to the issues presented.Download PDF
May 14, 2025Maximizing returns on cybersecurity investments with Intelligence-Driven Threat HuntingThis webinar offers security leaders and decision makers useful strategies to build a successful threat hunt program aligned with their corporate goals.
May 5, 2025Managing a cyber crisisIn this Studio 471, Tom Bolitho of FTI Consulting shares how IT security incidents can be managed to minimize reputational damage.
Apr 30, 2025Threat Hunting: Inmersión en MalwareDescubre cómo potenciar tu programa de CTI y mejorar tus defensas partiendo desde IOCs a implementar threat-hunting basado en comportamiento. Únete a Jorge Rodríguez, director de malware research en I
Apr 17, 2025Threat Hunting Workshop 15: Hunting for Execution - Level 2Sharpen your ability to detect malicious execution activity through hands-on threat hunting and intelligence-led analysis.
Apr 7, 2025Guess Who: The Adversary EditionThis special edition episode of Out of the Woods: The Threat Hunting Podcast walks through a real-world threat actor activity one clue at a time, challenging listeners to analyze behavior, map tradecraft, and consider attribution as the activity unfolds.
Mar 26, 2025SANS 2025 Threat Hunting Survey ReportThe SANS 2025 Threat Hunting Survey: Advancements in Threat Hunting Amid AI and Cloud Challenges provides key insights and threat trends to help you drive structured threat hunting processes and stay ahead of evolving adversary techniques.Download PDF
Mar 26, 2025Writing high-quality IDS detection rulesIn this Studio 471, Jeremy Kirk sits down with Luca Allodi and Koen Teuwen of Eindhoven University of Technology who co-authored a recent academic study that examines how to write lower-noise rules for intrusion detection systems (IDSs).
Feb 27, 2025Intel 471 Annual Threat Report 2024 & Outlook for 2025The year 2024 has been marked by substantial disruptions and transformations within the underground cyber world, impacting both businesses and individuals. Our detailed report analyzes the evolving tactics of cybercriminals, the notable rise and fall of ransomware groups, and the ongoing challenges presented by emerging vulnerabilities. Download PDF
Feb 26, 2025The evolution of Russian cybercrimeIn this Studio 471, Roman Sannikov, Founder of Constellation Cyber shares his insight into the Russian cybercriminal landscape, the evolution of online crime and what lies ahead with ransomware.
Feb 25, 2025Decoding the Ransomware Playbook: Threat Hunting Opportunities to Thwart Bassterlord’s TechniquesJoin Intel 471 for our webinar “Decoding the Ransomware Playbook: Threat Hunting Opportunities to Thwart Bassterlord’s Techniques” to discover how your teams can use intelligence-driven threat hunting
Feb 6, 2025Top Cover 4 – Threat Hunting Management Workshop: Hiring Effective Threat HuntersIntel 471's Top Cover workshop invites you to this session on hiring threat hunters, where we’ll explore strategies for building and managing a high-performing team.
Feb 5, 2025NIS2: Achieving Digital Resilience Within Europe's Critical SectorsThis is a must-see webinar for all entities in scope of NIS2. Hosted by Intel 471 content manager Liam Tung, you’ll hear Dekker’s insights on how ENISA and the EU will help improve cybersecurity, resi
Jan 29, 2025How threat actors are using artificial intelligenceArtificial intelligence is a red-hot mess, filled with contradicting predictions over whether it will bring vast benefits. In this Studio 471, Ashley Jess shares her insight into how AI will shape the threat landscape.
Jan 13, 2025Threat Hunting Workshop 14: Hunting for Initial Access - Level 2Intel 471 is excited to introduce the first in our new Level 2 Threat Hunting Workshop series, designed for those ready to take on greater challenges. This inaugural session focuses on Initial Access,
Jan 8, 2025DORA: How Intelligence-Driven Security Strengthens Digital Resilience in the Financial SectorNew cyber security regulations like Europe’s Digital Operational Resilience Act (DORA), effective January 17, 2025, aim to enhance the financial sector’s resilience against cyber attacks and IT outages.Download PDF
Jan 5, 2025The Art of the Hunt: Turning Intel into ActionIn this episode, "The Art of the Hunt: Turning Intel into Action," our expert team explores the nuances of threat intelligence, including behavioral and indicator-based approaches, and how to effectively leverage them for superior outcomes.
Dec 17, 2024Collecting Useful CTI From Underground MarketsExtracting cyber threat intelligence on emerging threats and novel threat actors is challenging. Michele Campobasso completed his doctoral thesis in 2024 at Eindhoven University of Technology, and in Studio 471, he shares insights on these markets and maximizing CTI collection.
Nov 26, 2024Using CTI in Realistic Attack SimulationsIn this Studio 471, two experts from the cybersecurity consultancy CyberCX discuss how these exercises are developed and executed.
Nov 15, 2024Lifting the Covers on RansomHub's RiseRansomHub is now the top Ransomware-as-a-Service (RaaS) affiliate program since it hit the ransomware scene in February 2024. RansomHub claimed responsibility for 15% of over 1,000 ransomware breaches
Nov 5, 2024The Ideal Outcome: The Gift of a Well-Crafted Threat HuntIn this episode, "The Ideal Outcome: The Gift of a Well-Crafted Threat Hunt", our expert team dives into what it means to reach the “ideal outcome” as a threat hunter, offering actionable insights to help you build an effective and enduring approach.
Oct 24, 2024Pink Slime Journalism and the 2024 U.S. Presidential Election ReportThe rise "pink slime" news sites poses a significant threat to the integrity of online news and, by extension, to democracy itself. As both campaigns in the 2024 U.S. Presidential race began zeroing in on swing states, Intel 471 analysts surveyed some of the key organizations and people that color the pink slime landscape.Download PDF
Oct 23, 2024U.S. Elections 2024: What To Do About Pink Slime Overtaking Local News?So-called “pink slime” news sites are filling an information void left by a U.S. local news industry in rapid decline. What can be done to control the integrity of online news in this environment? And
Oct 22, 2024Will Processing CTI Become Legally Risky?In this Studio 471, Peter Swire discusses the regulatory environment, how it could impact the use of cyber threat intelligence and what could be done to ensure attackers don’t leverage these changes to their advantage.
Oct 22, 2024Threat Hunting Workshop 13: Hunting for Discovery - Level 1Our workshop will unpack the intricacies of the Discovery tactic, exploring the methods adversaries use to identify sensitive information and map out environments. We'll dive into the most prevalent t
Oct 13, 2024Threat Intelligence for NIS2 Ready Critical InfrastructureDiscover how Intel 471’s CTI solutions map to NIS2 risk management measures and reporting obligations in this Intel 471’s NIS2 Point of View report.Download PDF
Oct 1, 2024NIS2 Operationalising Cyber Threat Intelligence for Critical Infrastructure ResiliencyThis paper explores how entities in critical sectors can operationalise cyber threat intelligence (CTI) and intelligence-driven threat hunting practices to reduce cyber risk, anticipate threats, prioritise remediation of cloud resources and other IT assets, and continuously improve risk management measures to boost resilience and recovery.Download PDF
Oct 1, 2024Supercharge Your Security with Intelligence-Driven Threat HuntingThis whitepaper explores the core concepts of threat hunting and the effectiveness of intelligence-driven behavioral threat hunting programs. With HUNTER, security teams can scale their threat hunting efforts and enhance their defenses against evolving cyber threats.Download PDF
Sep 24, 2024Why Russia is a Hotbed of CybercrimeIn this Studio 471, Alec Jackson discusses how deep, institutional corruption ties Russian IT professionals, organized criminal groups and the state together and how Russia leverages this to its advantage.
Sep 23, 2024Blood, Sweat, and Threats: Carving the Perfect Threat HunterIn this LIVE episode, “Blood, Sweat, and Threats: Carving the Perfect Threat Hunter,” we’ll explore the full journey of a threat hunter, from their first steps into the field to mastering the tools of the trade.
Sep 18, 2024Frost & Sullivan Global Enabling Technology Leadership Award 2024Frost & Sullivan assessed the cyber threat intelligence (CTI) industry and, based on its findings, recognizes Intel 471 with the 2024 Global Enabling Technology Leadership Award.Download PDF
Sep 10, 2024Guests Check-in, Cybercriminals Cash-out: Protecting Payment Data from Phishing AttacksIn this webinar, you’ll learn how one cybercrime and fraud operation is targeting hotel guest payment card data in hotel booking systems. They’re not just abusing Booking.com’s brand in phishing email
Aug 29, 2024Cyber Geopolitical IntelligenceIntel 471’s Cyber Geopolitical Intelligence provides a comprehensive view of current affairs to help assess digital risks and enhance security measures.Download PDF
Aug 27, 2024External Attack Surface Management: Intelligence-Driven CybersecurityGain a deeper understanding of the significance of Cyber Threat Intelligence in External Attack Surface Management and learn about different methodologies and the benefits of CTI-led EASM, download our comprehensive whitepaper.Download PDF
Aug 27, 2024How to Comfortably Share Threat Intel with ISACsIn this Studio 471, Sydney Jones, Head of Threat Intelligence at CLS Group, discusses how she has set up several productive programs to share threat intelligence with Information Sharing and Analysis Centers (ISACs), helping the community reduce risk.
Aug 27, 2024Threat Hunting Workshop 12: Hunting for Collection - Level 1With Intel 471’s powerful in-depth cyber threat intelligence and HUNTER Platform, we will demonstrate how to effectively transition from intelligence to precise, operationalized threat hunting for col
Aug 19, 2024Cybercrime Exposed Podcast: TankIn 2006, a new type of malware appeared on the scene. Its name was Zeus. It was enormously profitable for its cybercriminal developers, who used it to steal tens of millions of dollars from businesses and organizations of all sizes.
Aug 5, 2024CTI Capability Maturity Model (CTI-CMM) HandbookBuilt by industry experts, the CTI Capability Maturity Model (CTI-CMM) can help your team build its capabilities and bridge the gap with stakeholders. Individuals from cross-organizational teams can use this Model to contribute to CTI program maturity.Download PDF
Jul 31, 2024How Cyber Insurance is Reducing RiskIn this Studio 471, Sezaneh Seymour, a vice president and head of regulatory risk and policy at Coalition, discusses how this approach is helping to reduce risk and incidents.
Jul 31, 2024Threat Hunting Workshop 11: Hunting for Command and Control - Level 1Our workshop will unpack the intricacies of command and control, exploring the methods adversaries employ to use this tactic. We'll explore the most prevalent techniques used for command and control a
Jul 16, 2024Are They Who They Say They Are? An Introduction to Know-Your-Customer Fraud April 2024Rapid digitalization and demand for online services have rendered Know-Your-Customer (KYC) identity verification processes a must for financial institutions and beyond to protect against fraud.
Jun 25, 2024What Can We Learn from Ransomware AttacksIn this Studio 471, Jamie MacColl, a research fellow with the Royal United Services Institute, discusses a recent study, “The Scourge of Ransomware Victim Insights on Harms to Individuals, Organisations and Society.” The study sought to understand the impacts of ransomware on multiple levels, from the IT people on the front line through to civil society.
May 29, 2024MITRE ATT&CK Looks at Cybercrime TechniquesIn this Studio 471, Patrick Howell O’Neill, who is a Lead Cyber Operations Analyst at MITRE, discusses cybercrime techniques and why ATT&CK is useful to security professionals.
May 20, 2024Cyber Threat Report for the DACH RegionFinancially motivated underground threat actors continue to impact entities in the DACH region.Download PDF
May 6, 2024The 471 Cyber Threat Report 2024The 471 Cyber Threat Report 2024 highlights shifting adversary alliances, a global surge in ransomware and advancements in deepfake technologies among the top threat landscape trends.Download PDF
Apr 23, 2024Deepfake vs Democracy The Impact of Disinformation Campaigns on 2024 ElectionAI tools could pose significant risk of amplifying political disinformation on a never-before-seen scale. This report provides insights into the current threat landscape, allowing for better preparation and protection against these emerging risks. Download PDF
Mar 28, 2024Five Top Information Stealer Malware FamiliesThis report offers a comprehensive analysis of five of the most popular infostealer families observed by Intel 471 across the reporting period from January 01 to December 01, 2023. Download PDF
Mar 27, 2024SANS 2024 Threat Hunting Survey: Hunting for Normal Within ChaosDiscover the Cutting-Edge of Cybersecurity in the “SANS 2024 Threat Hunting Survey: Hunting for Normal Within Chaos”Download PDF
Mar 20, 2024Countering Cyber Extortion and HacktivismIn this episode of Studio 471, we discuss two areas where Orange Cyberdefense has produced unique research in its Security Navigator 2024 report: cyber extortion and hacktivism. We tackle whether cyber extortion can be deterred and also the deeper effects of hacktivism, which can eclipse technical disruptions.
Mar 20, 2024On the Money: The Top Cyber Threats to the Banking Industry Mar. 2024Threat actors have the banking industry in their sights. The lucrative outcomes that a successful attack on an organization can provide and the industry’s growing digitization have created the perfect
Mar 20, 2024Threat Hunting Workshop 10: Hunting for Initial Access - Level 1Dive deep into the nuances of Initial Access, a critical area in the cybersecurity landscape. Our workshop will unpack the intricacies of this tactic, exploring the methods adversaries employ to escal
Mar 5, 2024Cybercrime Exposed Podcast: Crypto HeistIn this podcast, we explore the story of Axie Infinity and examine how cyber attackers from North Korea managed to steal almost $600 million worth of virtual currency in just a few minutes, as well as how investigators were able to trace them.
Mar 3, 2024Banking and Securities Industry Threat ReviewThis report explores the top five threats to the banking and securities industry across 2023 to empower organizations with the knowledge they need to navigate the complex cyber threat landscape.Download PDF
Feb 21, 2024The Four Phases of Information Stealing MalwareThis report covers a variety of distribution methods used by information stealers, including specialized installation services, malicious advertising (malvertising), search engine optimization (SEO) poisoning, and malicious spam (malspam).Download PDF
Feb 21, 2024Building Capable Threat Intelligence ProgramsIt's possible to build effective cyber threat intelligence programs with smaller teams, but stakeholder buy-in is important. John Fokker of Trellix describes how security teams can improve their CTI programs.
Feb 21, 2024Keys to the Kingdom: An Analysis of Ransomware and Access Trends in 2023 Feb. 2024Ransomware deployments are increasing each year, and so are the sophistication of the attacks. Without initial access to an organization, these attacks would not be possible. In today’s highly digital
Feb 12, 2024Unmasking Threats Impacting the Aerospace and Defense IndustryThis report provides an overview of critical threats impacting the Aerospace and Defense landscape and analyzes common attack vectors and tactics, techniques, and procedures (TTPs) utilized by threat actors targeting these industries.Download PDF
Feb 6, 2024Cybercrime Exposed Podcast: Botnet BreakupThe Qakbot or QBot botnet was used by cybercriminal gangs to infiltrate computers, steal their data, conduct financial crime and deploy ransomware. But in 2023, law enforcement hacked the hackers. Here's the story.
Jan 30, 2024Cyber Threat Health Check ReportMalicious cybercriminals frequently target the pharmaceutical, biotechnology, and life sciences sectors. Companies in these sectors must remain vigilant and take the necessary measures to protect their valuable assets.Download PDF
Jan 24, 2024Testing the Efficacy of Security SoftwareIn this edition of Studio 471, Simon Edwards of SE Labs walks through how his company tests security products based on the cyber kill chain and MITRE ATT&CK.
Jan 24, 2024Crashing the Party: How to Leverage CTI to Mitigate Supply Chain Risk Jan. 2024As supply chains have increased in complexity and interconnectivity, so too have operational demands for digital solutions to monitor and manage them more efficiently. In tandem with these development
Jan 24, 2024Threat Hunting Workshop 9: Hunting for Privilege Escalation - Level 1Get ready to elevate your threat hunting skills with Intel 471's exhilarating and interactive workshop, focusing on the pivotal MITRE ATT&CK Tactic: Privilege Escalation. This isn't just another works
Jan 15, 2024Leverage CTI to Mitigate Supply Chain RiskThis whitepaper provides an understanding of the who, what, and why behind supply chain attacks, empowering organizations to avoid these incidents in the future.Download PDF
Jan 9, 2024Cybercrime Exposed Podcast: The Xbox One HackIn the early 2010s, a group of malicious hackers had a goal: to build a Durango, which was the code name for Microsoft’s next-generation gaming console, eventually known as the Xbox One.
Dec 13, 2023Vulnerability Management and Patching: Outrunning AttackersIn this edition of Studio 471, Patrick Garrity of Nucleus Security shares the effects of the KEV list across the security industry, his research into the KEV, and how threat intelligence can guide patching efforts.
Dec 13, 2023Malware 101: Power up your investigations; Protect your organization. Dec. 2023Malware attacks continue to increase in velocity and sophistication. No industry is safe from being targeted by the threat actors driving them. Invaluable insights and details about a cyber incident c
Dec 12, 2023The Underground Carding MarketPayment card fraud remains a significant threat in the underground marketplace. Intel 471 details threats such as social engineering, information-stealer malware, and compromised databases that assist in perpetuating the threat from the carding market.Download PDF
Dec 6, 2023Cybercrime Exposed Podcast: Social EngineeringIn this episode of Cybercrime Exposed, Bluma Janowitz, a social engineer and red team agent, describes two of her engagements to test an organization’s defenses against malicious hackers.
Nov 28, 2023Mandiant’s CTO: A Bad Year for Ransomware and ExtortionIn this edition of Studio 471, Mandiant CTO Charles Carmakal says half of all ransomware or extortion victims are paying ransoms. Sometimes, that is to prevent the release of sensitive data, while others pay to speed up recovery – even if the organizations have backups.
Nov 15, 2023Bulletproof Hosting Landscape: Status Update on Actor yalishandaIntel 471 has been actively tracking Bulletproof Hosting (BPH) services and the threat actors behind them. One threat actor notably continues to provide one of the most popular malicious infrastructure services: yalishanda.Download PDF
Nov 8, 2023Mobile Malware Underground PerspectiveThis report discusses how mobile malware impacts Android devices from the perspective of cybercriminals and financially motivated threat actors. Get a deeper understanding of mobile malware attacks by downloading our whitepaper.Download PDF
Nov 7, 2023Cybercrime Exposed Podcast: The ExtortionistsIn one long weekend in May 2023, a cybercriminal gang called Clop conducted one of the largest data breaches on record.
Oct 24, 2023Should Ransom Payments Be Made Illegal?In this edition of Studio 471, Megan discusses the future of the Ransomware Task Force, whether ransom payments should be banned and how organizations are strengthening baseline security.
Oct 18, 2023Bypassing With Bots: How Adversaries Use Automated Services to Sidestep OTPs Oct. 2023Not all passwords are created equal. They may range from silly to scure, but one thing they have in common is that they’re the gateway into sensitive information. The good news is that tools like mult
Oct 16, 2023Gaining the Advantage with Covert Cyber HUMINTDelve deep into the world of Cyber Human Intelligence (HUMINT) — where traditional human intelligence meets the digital world. Discover the strengths, challenges, and best practices to arm your organization with advanced, holistic defense strategies.Download PDF
Oct 10, 2023Cybercrime Exposed Podcast: The PhishermanIn this episode of Cybercrime Exposed, Bex Nitert, an incident response and forensics professional in Australia describes herself as a digital firefighter who helps organizations after they’ve been hacked. She often investigates phishing, the term for stealing login credentials with the aim of taking over accounts and systems.
Sep 26, 2023Why Ransomware is Stubbornly Sticking AroundIn this edition of Studio 471, Jacqueline Burns Koven of Chainalysis discusses how ransomware is evolving and what challenges it poses for defenders.
Sep 13, 2023Q2 Ransomware 2023: Reviewing Third-Party Risk Sept. 2023Join Intel 471’s webinar as we shine a spotlight onto increasing ransomware attacks.
Aug 28, 2023Interactive Threat Hunting: Exploring Vegas Ransomware, Generative AI Scams, and Advanced Defense Strategies
Aug 16, 2023Know Your Adversaries and Where They Trade, To Stop Cyber Attacks Aug. 2023In this webinar we will show you how tracking adversaries and the tools they use can help you stay ahead of threats like ransomware and third party risk. We will demonstrate this using real world exam
Aug 15, 2023Busting a Myth: Overlap Between Nation State & Financially Motivated CybercrimeIn this webinar, you'll discover the undeniable link between Nation-State and Financially Motivated cybercrime.
Aug 15, 2023Using Intel 471 Intelligence to Prevent Ransomware AttacksThis webinar looks into the cyber underground and shows how you can identify precursors for a ransomware attack to orient your defenses and stay one step ahead of your adversaries.
Aug 14, 20237 Habits of CybercriminalsThis webinar presents the results of an analysis of more than 12 years of tracking and reporting on a variety of actors and groups in the cyber underground, which allowed us to identify seven specific
Aug 14, 2023Bottom Feeders: Initial Access Broker Activity ExaminedLearn about initial access offerings in the cyber underground and gain insights into the activity patterns of the most prominent IABs.
Aug 14, 2023Four Ways the Cyber Underground is like the Middle AgesIn many ways, the cyber underground strongly resembles Medieval Italy or the Wild West. This webinar discusses how to increase your cyber protection by learning from history.
Aug 14, 2023How a CTI Framework Catapults Your Cyber Security ProgramJoin us for a discussion on how to build the right CTI Framework, fueled by General Intelligence Requirements (GIRs), to help you elevate your cyber defense and catapult your cybersecurity program to
Aug 14, 2023Ransomware: Attackers vs DefendersJoin us as our presenters use Intel 471's knowledge of the underground and Unit 42's experience with ransomware incident response cases to reveal how threat actors find their victims, gain e
Aug 14, 2023Ransomware Dramas Why Focusing On Ransomware Itself is Not EnoughIn this session, we look at the ecosystem that aids in the deployment of ransomware as well as the key actors and steps involved in a typical attack
Aug 14, 2023Sidestepping a Cyber Car Crash in Matrix TimeRansomware is like a slow-moving car crash. Incidents don't occur in an instant. The cyber underground is ripe with indicators that can predict an attack weeks or months before the event occurs.
Aug 14, 2023Using A Data Driven Approach to Defend Against Cyber ThreatsLearn from CLEAR, Intel 471, and ThreatQuotient professionals, who share their tactical and strategic experience regarding how cybersecurity professionals have successfully addressed similar challenge
Aug 6, 2023The 471 Cyber Threat Report 2023This report analyzes the key trends that are gaining or losing momentum and predicts how they will shape cybercrime and the cyber underground in the coming year.Download PDF
Jul 12, 2023Stopping the Reuse of Credentials and Session TokensBrett Winterford of Okta and Intel 471’s Jeremy Kirk discuss strong authentication, paths to strengthening authentication and what Intel 471 analysts are observing around credential theft in the cybercriminal underground.
Jul 12, 2023AI: Ready for Underground Prime Time? July 2023Ever since the introduction of ChatGPT, Artificial Intelligence (AI) has remained in the spotlight, captivating businesses and the global community as they strive to comprehend the potential of this g
Jul 5, 2023Shot of Cyber with Mark ArenaGilad and Simon sit down for a chat with Mark Arena, founder and former CEO of Intel471. We discuss his incredible trajectory, the birth of Intel471, and what it’s like competing and growing a bootstrapped business. We discuss the importance of proactively building and enforcing a culture, especially when it hurts.
Jun 22, 2023Oil, Gas, Energy Cyber ThreatsCyber threats targeting critical national infrastructure (CNI) are becoming increasingly common.Download PDF
Jun 5, 2023Threat Hunting: Shifting Gears in Query TuningIn this informative session, we will guide you through the winding roads of query tuning, mapping out the 'why', 'what', and 'how' of the process.
May 11, 2023Mont4na Actor ProfileIntel 471 has monitored Mont4na, a well-known underground actor who has been active on forums since November 2020.Download PDF
May 2, 2023Threat Hunting Workshop 8: Hunting for Exfiltration - Level 1Are you ready to take your threat hunting skills to the next level and become an expert in the MITRE ATT&CK Tactic of Exfiltration (TA0010)?
Apr 27, 2023Mastering Cybersecurity: Exploring White Space, Tierless SOCs, and the Future of AI in Management
Apr 24, 2023Top Cover - Threat Hunting Management Workshop: Reporting & CommunicationJoin us for a unique interactive threat hunting management workshop where Intel 471's Senior Threat Hunter, Scott Poley, will guide you through the crucial skill of writing effective threat hunti
Apr 21, 2023RSAC Fireside Chat: How timely intel from the cyber underground improves counter measuresIn this RSAC Fireside Chat, Jason Passwaters, CEO of Intel 471, joins Byron V. Acohido for an enlightening discussion on leveraging timely intelligence from the cyber underground to bolster countermeasures.
Apr 4, 2023Threat Hunting Workshop 7: Hunting for Impact - Level 1In this immersive, educational, and fun workshop, Intel 471's expert instructors will guide you through the critical areas of impact, including the mechanics of impact and the most common tactics, tec
Apr 3, 2023Top Cover - Threat Hunting Management Workshop: From KPIs to MetricsJoin us for a unique interactive threat hunting management workshop where Intel 471's Senior Threat Hunter, Scott Poley, will guide you through the critical aspect of managing a threat hunting pr
Mar 31, 2023Hybrid Hunting: Threat Hunting in the Managed Security BattlespaceJoin our expert speakers, Scott Poley (Senior Threat Hunter, Intel 471y) and Justin Heard (Threat Intelligence Manager, Nuspire) for a comprehensive overview of the latest trends in hybrid hunting and
Feb 23, 2023Top Cover: The Threat Hunting Management WorkshopJoin us for a unique interactive threat hunting management workshop where Intel 471's Director of Threat Research, Brandon Denker, will guide you through the critical aspect of managing a threat
Feb 9, 2023Threat Hunting Workshop 6: Hunting for Lateral Movement - Level 1Join Intel 471's expert threat hunters as they dive into the interesting MITRE ATT&CK Tactic of Lateral Movement (TA0008).
Jan 24, 2023Germany Cyber ThreatsA significant number of businesses in Germany continue to be impacted by cybercrime each year, leading to substantial operational downtime and monetary loss.Download PDF
Jan 18, 2023Cybersecurity Essentials: Addressing BYOD Risks, Human Simulations, and Professional Development
Jan 18, 2023Threat Hunting Workshop 5: Hunting for Credential Access - Level 1Join Intel 471's expert threat hunters as they dive into the interesting MITRE ATT&CK Tactic of Credential Access (TA0006).
Jan 17, 2023Enhancing Cyber Resilience: Cloud Risks, Vulnerability Management, Home Labs, and Overcoming Imposter Syndrome
Dec 12, 2022Gaming Cyber ThreatsThe scope of analysis performed in this report provides a strategic-level overview of observed and potential threats to the gaming industry.Download PDF
Dec 12, 2022UK Cyber ThreatsThis report provides a strategic-level overview of threats identified impacting the U.K. and U.K. based businesses, including ransomware and initial access brokers (IABs), as well as common threat actor tactics, techniques and procedures (TTPs) observed.Download PDF
Nov 16, 2022Threat Hunting Workshop 4: Hunting for Defense Evasion - Level 1Join Intel 471's expert threat hunters as they dive into the interesting MITRE ATT&CK Tactic of Defense Evasion (TA0005).
Nov 7, 2022Empowering Security Teams: Innovative Logging, Red vs Blue Team Benefits, and Effective Table Tops
Oct 20, 2022Leading Ransomware Variants Q3 2022This report examines the leading ransomware variants related events for Q3 2022 specifically observed by Intel 471.Download PDF
Oct 12, 2022Threat Hunting Workshop 3: Hunting for Execution - Level 1Join Intel 471's expert threat hunters as they dive into the interesting MITRE ATT&CK Tactic of Execution (TA0002).
Sep 23, 2022Ransomware's Future: A Continuing Money SpinnerIntel 471's Michael DeBolt Says Anti-Ransomware Actions Will Take Time
Sep 8, 2022Rise of Black Basta RansomwareThis report uses the analytical technique known as strengths, weaknesses, opportunities, and threats (SWOT) analysis to conduct an assessment of the Black Basta ransomware group.Download PDF
Sep 8, 2022Crashing the Party: Leverage Threat Intelligence to Mitigate Third Party RiskLearn how cyber threat intelligence has helped to safeguard organizations like yours from third party risk.Download PDF
Aug 30, 2022Using Cyber Frameworks to Action CTI and Enhance Your Security PostureLearn how NIST, MITRE ATT&CK™ and other cyber frameworks can better leverage your threat intelligence and improve your security posture.Download PDF
Aug 1, 2022The 471 Cyber Threat Report: 2022-2023 Trends & PredictionsIntel 471 has identified a number of cyber threat trends that will likely dominate the landscape in 2023 and beyond.Download PDF
Jul 19, 2022Decipher Security Podcast: Mark ArenaMark Arena, CEO of Intel 471, joins the Decipher podcast to talk about the journey behind founding Intel 471 in 2014 and how cybercrime has evolved over the past few years.
Jun 29, 2022Dispatches from Somewhere ElseJoin our Hunt Team, featuring Scott Poley from Intel 471, and Richard “Chit” Chitamitre from Corelight, for a fun, technical, and in-depth hunting session to pursue the adversary, identify their tacti
Jun 1, 2022Commonly Observed Threats to Telecommunications SectorThis report examines threats posing exponential risk to the telecommunications sector observed by Intel 471.Download PDF
May 12, 2022Cybercrime and punishment - The CyberWireOur guest is Michael DeBolt of Intel 471 on the growing interest in Biometrics in the criminal underground. And cybercrime and punishment, Florida-man edition.
Apr 12, 2022Bulletproof Hosting Services and Cybercrime: Yalishanda Case StudyIntel 471 closely monitors numerous BPH operations, but one has grown in popularity across the underground, Yalishanda.Download PDF
Apr 5, 2022Initial Access Offers, Ransomware IncidentsPurchasing access to organizations allows threat actors to reduce the time it takes to enter an environment. In 2021, the average time between a network access offer and a ransomware-as-a-service (RaaS) affiliate program breaching the same entity was 71 days.Download PDF
Apr 3, 2022Michael DeBolt: From acting to cyber [Intelligence] - The CyberWireChief intelligence officer at Intel 471, Michael shares his story where he started as an actor and quickly changed over to intelligence and what the transition was like for him.
Apr 2, 2022A popular malware scheme and pay-per-install services - The CyberWireGuest Michael DeBolt from Intel 471 joins Dave Bittner on this episode to discuss one of the most popular commodity malware loaders on the underground – PrivateLoader.
Mar 30, 2022Threat Hunting Workshop 2: Persistence is Futile - Level 1Join our team of threat hunting instructors for a unique and immersive threat hunting workshop.
Mar 29, 2022Hunting for CONTI: TTPs Not IOCsJoin Intel 471's Scott Poley as he goes into a live threat hunt for the Conti ransomware using the latest threat intelligence reporting, and the very real pitfalls organizations face in trying to
Mar 22, 2022The Threat Hunter’s HypothesisA case for structured threat hunting and how to make it work in the real world.Download PDF
Mar 14, 2022Ransomware Variants Q4 2021This report examines the leading ransomware variants related events for Q4 2021 specifically observed by Intel 471.Download PDF
Feb 23, 2022Thinking Like a Threat Actor: Hunting the Ghost in the MachineThis webinar will demonstrate how organizations can overcome these internal blind spots, and hunt adversaries in real time across their network using telemetry from tools like NDR when coupled with ED
Feb 22, 2022Overview of Cyber Threat Trends to Beware of in 2022Cybersecurity increasingly has become a priority for organizations across all sectors as technology continues to advance worldwide. This report aims to provide a high-level overview of these threats, which likely will remain prevalent and worthy of continued focus throughout 2022.Download PDF
Feb 17, 2022Threat Actors Looking for a Steal: Key Threats Impacting the Retail IndustryThe retail industry is a highly targeted vertical, a trend Intel 471 assesses is certain to continue since defrauding retailers remains a lucrative pursuit for financially motivated threat actors.Download PDF
Feb 8, 2022Arrests in a cryptocurrency money-laundering case. - The CyberWireOur guest is Greg Otto from Intel 471 to discuss shifts in ransomware strains. And two arrests are made in a money-laundering case connected with the Bitfinex hack.
Jan 26, 2022Begin Your Hunt: The Threat Hunting WorkshopThat is why Intel 471 is offering a first-of-its-kind interactive threat hunting workshop where anyone can learn how to threat hunt in a safe, fun, and dynamic environment!
Dec 17, 2021Log4j Vulnerability Situation ReportThis report aims to provide you with a consolidated update of all of our findings regarding the Log4j aka Log4Shell vulnerability, tracked as CVE-2021-44228, up to December 16, 2021.Download PDF
Oct 28, 2021Good grammar is essential for business email compromise. - The CyberWireGuest Brandon Hoffman from Intel 471 is back sharing some research on business email compromise,
Oct 27, 2021The Callback is Coming From Inside the House!This webinar will demonstrate how threat hunting with EDR and NDR combined allows organizations to find what traditional security controls keep missing. It is guaranteed to terrify CISOs everywhere be
Oct 14, 2021The Online Criminal Underground: Cybersecurity and Corporate ThreatsGreg Otto, Chief Cybercrime Reporter at Intel 471 discusses prevention methods as well as how international agencies, businesses, the federal government, and insurance companies are working diligently to protect their own interests as well as our data
Sep 29, 2021Do You Even Threat Hunt, Bro? Hunting for WMIC AbuseJoin one of Intel 471's lead threat hunters, Scott Poley, as he demonstrates a technique used by adversaries and cyber criminals alike, by abusing WMIC to copy and execute payloads on remote endp
Sep 8, 2021Do You Even Threat Hunt, Bro? Hunting For HiveNightmare (CVE-2021-36934)Join one Intel 471's lead threat hunters, Lee Archinal, as he demonstrates hands-on practical session of true behaviorally-based threat hunting related to the vulnerability known as HiveNightmare
Aug 26, 2021Companies don't want their customers to be victims of fraud.Guest Brandon Hoffman from Intel 471 joins Dave to talk about how cybercriminals are going after large retail and hospitality companies, Joe shares some advice for college students to avoid scams and ID theft, Dave's got an edit to the tale of the lightning rod, our Catch of the Day comes from listener Shannon who received a beneficiary scam email.
Aug 19, 2021T-Mobile outlines what it’s offering customers hit by its data breachOur guest is Brandon Hoffman from Intel 471 on cybercriminals creating turbulence for the transportation industry. And a Bitcoin tumbler cops a guilty plea.
Jul 20, 2021451 Research Publishes Intel 471 ReportIntel 471 analysis identifies the most useful among forums and venues of greatest relevance to cyberthreats affecting its clients.Download PDF
Jul 1, 2021A cyber most-wanted list. Are the phone lines open? - The CyberWireOur guest is Brandon Hoffman of Intel471 with insights on China’s data underground. And, hey, it’s Dmitri from Yurga, long-time listener, first-time caller.
Jul 1, 2021Shining Light on the DarkSide - Part 3Join us for an interactive and lively panel discussion featuring Dave Amsler of Intel 471, Anuj Goel of Cyware, and Jim Linn of the American Gas Association as they discuss the short and long term eff
Jun 22, 2021Cybersecurity, Ransomware, and the NATO SummitIn this panel of former military personnel turned cybersecurity experts, we discuss the state of cybersecurity, ransomware, and the NATO Summit.
Jun 16, 2021Shining Light on the DarkSide - Part 2: UncutPrepare for an in-depth and uncut technical deep dive with Intel 471's Austin Jackson, into the actors' tools and TTPs and how organizations can hunt and detect them in their own environment
Jun 9, 2021Advice for military leavers transitioning to cyber security careers | Jason Passwaters (Intel 471)This episode with Jason Passwaters (COO & Co-Founder, Intel 471) is aimed at military leavers, how to best prepare for the transition and the lessons learnt from Jason's experience.
Jun 2, 2021Shining a Light on the DarkSide - Part 1Join Intel 471's Brandon Denker and Mike Mitchell as they provide insight into the attack against the Colonial Pipeline, and suggest strategies for earlier detection through threat hunting.
May 29, 2021EtterSilent: a popular, versatile maldoc builder. - The CyberWireGuest Brandon Hoffman of Intel 471 joins Dave Bittner to share his team's research & EtterSilent: the underground’s new favorite maldoc builder.
May 21, 2021Collaboration between network access brokers and ransomware actors deepensIn this Help Net Security podcast, Brandon Hoffman, CISO at Intel 471, discusses about the increased collaboration between network access brokers (NAB) and ransomware operators, and how they funcion it today’s threat landscape.
May 19, 2021Cobalt Strike - A Toolkit for Pentesters WhitepaperThe cybercrime underground’s adoption of Cobalt Strike correlates with the rise in ransomware activity over the past few years.Download PDF
May 19, 2021Thinking Like a Threat Actor: Cross Platform Hunting for PersistencePrepare for an in-depth, uncut, and interactive technical deep dive into persistence. Join Cyborg Security's Austin Jackson as he demonstrates various advanced persistence mechanisms in Windows,
May 18, 2021Frost & Sullivan 2021 Customer Value Leadership Award Intel 471For its strong overall performance, Intel 471 is recognized with Frost & Sullivan’s 2021 Customer Value Leadership Award.Download PDF
May 5, 2021Cybersecurity – Military Appreciation MonthCybersecurity has long been a part of the job description for these former servicemen. This Military Appreciation Month we talked with J.C. Vega, Jason Passwaters, and Barett Darnell about how their military experiences and skillsets transferred into the world of cybersecurity.
May 2, 2021Financial Services Threat Landscape UpdateJoin us in this webinar focusing on threats to the financial industry as Maurits Lucas, Director of Intelligence Solutions at Intel 471, looks at the after-effects in the underground of disruption ope
Apr 24, 2021Bulletproof hosting (BPH) and how it powers cybercrime - The CyberWireGuest Jason Passwaters of Intel 471 joins us to discuss his team's research into bulletproof hosting (BPH). The research team at Intel 471 defined what a typical BPH service offers and how these services can be stopped in order to limit the damage they have on enterprises, businesses and digital society itself.
Apr 22, 2021Threats Persist Against Financial Services Sector: Products, Goods, Services Continue to Fuel Attack SchemesThe financial services sector continues to garner serious interest from underground threat actors, and it is unlikely to change during the following year.Download PDF
Apr 12, 2021The benefits of cyber threat intelligenceIn this Help Net Security podcast, Maurits Lucas, Director of Intelligence Solutions at Intel 471, discusses the benefits of cyber threat intelligence. He also talks about how Intel 471 approaches adversary and malware intelligence.
Mar 31, 2021Thinking Like a Threat Actor: Structured vs Unstructured Threat HuntingThreat hunting is one of the most powerful capabilities an organization can have. It enables identification of new and emerging threats in an environment. Often long before other more reactive securit
Mar 26, 2021Leveraging Intel 471’s Malware Intelligence Data Using MISP WhitepaperUsing Intel 471’s Malware Intelligence with MISP provides clients with constant coverage of top-tier malware families.Download PDF
Mar 23, 2021 Threat Hunt Deep Dives Ep. 6 - Living off the Land (LotL) Pt. 2, RDP Hijacking with Tscon.exe
Mar 22, 2021Threat Hunting FrameworkThe Threat Hunting Framework lays out an operationalized methodology that organizations can use to begin threat hunting today.Download PDF
Mar 9, 2021Threat Hunt Deep Dives Ep. 5 - Living off the Land (LotL) - Downloading Files on Microsoft Windows
Feb 1, 2021Mobile Malware - Underground Perspective WhitepaperAs customers shifted to mobile banking, the focus of mobile malware also changed. Threat actors began to execute attacks on the infected device using overlays to phish data and two-factor authentication (2FA) tokens from victims.Download PDF
Dec 15, 2020Threat Hunt Deep Dives Ep. 3 - SolarWinds Supply Chain Compromise (Solorigate / SUNBURST Backdoor)
Dec 8, 2020Government Censorship, Surveillance Influence Chinese Cybercrime Underground WhitepaperThe underground marketplace functions like any other marketplace, including buyers and sellers with fluctuating supply and demand for different products and services.Download PDF
Nov 3, 2020The Content RevolutionQuality threat content can make or break threat hunting and detection efforts.Download PDF
Oct 20, 2020Validating Your Detections With Red Canary’s Atomic Red Team and Cyborg’s Cyber Threat Emulation
Aug 9, 2020Overcoming the Challenges of Cyber Threat Hunting with Contextualized ContentModern enterprises must proactively seek out the most dangerous cyber adversaries lurking in their networks today as those are the ones that cause the real or significant damage and loss to organizations.Download PDF
May 28, 2020Is Your Threat Hunting Effective?In this paper, we explore in more depth what exactly leads to the shortage of suitable personnel and how it affects security organizations’ capabilities to utilize threat hunting teams.Download PDF
May 10, 2020The 5 Traits of Effective Threat IntelligenceThreat intelligence, often referred to as cyber threat intelligence (CTI) or more simply, intelligence, can be a controversial subject.Download PDF
Adversary IntelligenceIntel 471's Adversary Intelligence provides proactive and groundbreaking insights into the methodology of top-tier cybercriminals.Download PDF
Malware IntelligenceIntel 471 Malware Intelligence allows you to actively track weaponized and productionized threats.Download PDF
Attack Surface ProtectionIntel 471’s Attack Surface Protection is our suite of solutions, each geared for different users at different stages in their attack surface journey.Download PDF
Geopolitical IntelligenceGeopolitical Intelligence from Intel 471 provides a unique lens to organizational leaders about shifting regional alliances, trade disputes, territorial conflicts and diplomatic crises that we believe will impact the cyber threat landscape.Download PDF
HUNTER Guided Threat HuntsIntel 471 HUNTER Guided Threat Hunts helps your threat hunters overcome these obstacles so your team can quickly find, neutralize, and report undetected threats.With the preview launch of Guided Threat Hunts, HUNTER now offers a Pivot Queries library for HUNTER hunt packages that helps hunters pivot on query result data and progress their hunt for adversary behaviors.Download PDF
The Hunt Management ModuleThreat hunt teams need tooling to manage hunt processes and ensure that hunt outcomes drive proactive security operations. The Hunt Management Module guides the management of hunts, including research, testing, results, and reporting, helping teams develop consistent, rigorous, and repeatable processes that improve the organization’s security posture, controls, and policies.Download PDF
Marketplace IntelligenceIntel 471 Marketplace Intelligence offers insights into the most important and active underground marketplaces.Download PDF
Cybercrime IntelligenceIntel 471's Cybercrime Intelligence provides proactive and groundbreaking insights into the methodology of top-tier cybercriminals - target selection, assets and tools used, associates and other enablers that support them.Download PDF
Vulnerability IntelligenceIntel 471’s Vulnerability Intelligence provides both relevant and timely intelligence information about the adversary.Download PDF
Behavioral Threat HuntingBehavioral threat hunting uses security event data to identify patterns of behavior based on adversary intelligence that reveal a specific actor’s tactics, techniques, and procedures (TTPs) inside an environment. By studying how specific threat actors have used tools, systems, and software to achieve their goals, threat hunters can identify expected behaviors within the “cyber kill chain” that indicate network pivoting, expansion or exfiltration.Download PDF
Credential IntelligenceIntel 471’s Credential Intelligence provides complete coverage across the underground marketplace.Download PDF