1、Low Sensitivity1Red Teams with ReceiptsOperationalizing CTI for Real Adversary SimulationsLow SensitivityRalph HittellNigel BostonJoined Grainger 2022Located Jacksonville,FLGym&Martial Arts enthusiastChess Player Muay Thai Joined Grainger 2017Located Jacksonville,FLMarried 18 years,14y/o Son2 Golden
2、doodlesActive in Defcon and CTFsWorking on my carThis initiative is designed to elevate our security posture by integrating cyber threat intelligence and threat hunting with a robust validation of detection controls and red teaming,all while engineering precise detection mechanisms for a risk-inform
3、ed defense strategy.SpeakersLow SensitivityRed Teams with ReceiptsOperationalizing CTI for Real Adversary SimulationsSlide 10Slide 12Slide 7Low SensitivityCyber Threat IntelligenceLow SensitivityI n t e l l i g e n c e L i f e c y c l e:P l a n n i n g a n d D i r e c t i o n C o l l e c t i o n P r
4、 o c e s s i n g A n a l y s i s a n d P r o d u c t i o n D i s s e m i n a t i o n Cyber Threat Intelligence Survey Threat Landscape Determine likely targets Evaluate based on business risk Designate attack exercises Recommend efforts for remediationLow SensitivityCyber Threat Intelligence1.COLLEC
5、TThreat reports,OSINT,vendor feeds,incident data,industry ISACs2.ANALYZEExtract TTPs,map to ATT&CK,identify tooling&infrastructure patterns3.OPERATIONALIZEBuild playbooks,configure tools,develop emulation plans4.EXECUTERun adversary emulation with receipts documented,mapped,defensibleWHAT CTI PROVID
6、ESThreat context,validated TTPs,actor profiles,targeting patterns,and the why behind adversary choicesWHAT RED TEAM DELIVERSRealistic testing against actual threats,detection gaps,and evidence-based security recommendationsLow SensitivityThreat HuntingLow SensitivityThreat Hunting Scope the Hunt:Def