Sept. 18, 2023, 4:04 p.m. | /u/AbracaBOOYAH

For [Blue|Purple] Teams in Cyber Defence www.reddit.com

My employer (based in the US) is wanting me to investigate moving to a ticketing system that will automatically take the IOCs and other useful intel-based information (domain registrar, registered email addresses, cert registered names, cert hashes, etc.) and tie them together.

Additional context: This is because of the US SEC ruling of having to report material breaches, and the employer wants to make sure that lots of "little attacks" over time are not part of a larger "material" breach. …

addresses blueteamsec cert context domain domain registrar email employer etc hashes incidents information intel iocs moving names registrar system ticketing track

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States