14 October 202612:30–14:30 CEST
Online
120 min·Track: Technik
What is Cyber Threat Intelligence, how does it differ from a Cyber Threat Model — and what makes a threat model defensible to a supervisor?
Lerninhalte
- Part 1 · What is Cyber Threat Intelligence (approx. 25 min)
- 1.1) Definition of Cyber Threat Intelligence (CREST, NCA and CIA definitions — intelligence supports decisions)
- 1.2) TIBER-EU — framework, roles and deliverables: Scoping Specification Document, Generic Threat Landscape, Targeted Threat Intelligence Report
- 1.3) Three levels of threat intelligence — strategic, operational, tactical — plus technical intelligence
- 1.4) Intelligence disciplines (INTs) and intelligence sources
- 1.5) The intelligence cycle — how bespoke CTI is produced
- 1.6) From data to intelligence — worked examples: Emotet (MUMMY SPIDER) and Ryuk (WIZARD SPIDER)
- 1.7) Threat actor attribution — why WIZARD SPIDER (CrowdStrike) is not necessarily FIN12 (Mandiant); AI acceleration as a new kind of intelligence source
- Part 2 · Cyber Threat Models (approx. 20 min)
- 2.1) Cyber Threat Intelligence vs. Cyber Threat Modelling — evidence-based knowledge about real attackers vs. structured representations of how attacks could occur
- 2.2) Definition of a Cyber Threat Model
- 2.3) Key elements: threat actors · adversary goals, intent and motives · capabilities and resources · attack vectors and paths · target assets and system components · consequences (confidentiality, integrity, availability)
- 2.4) The threat modelling process in TIBER-EU
- Part 3 · Formalised vs. non-formalised Cyber Threat Models (approx. 20 min)
- 3.1) Definition and categorisation of the frameworks by formalisation and modelling perspective — STRIDE, CBEST, TIBER-EU, CAPEC, MITRE ATT&CK
- 3.2) Why formalisation matters under DORA — a threat model that withstands challenge by supervisor, management, blue team and successor
- 3.3) Quality criteria for a governed Cyber Threat Model
- 3.4) Asset-centric, system-centric and threat-centric approaches
- Part 4 · Building the model — a TIBER-EU worked example (approx. 40 min)
- 4.1) The Intelligence Collection Plan, aligned with the TIBER-EU TTIR: business parameters, Critical or Important Functions (asset-centric)
- 4.2) System-centric modelling — decomposition along TIBER-EU operational depth 0 – 6: business context, function decomposition, supporting systems and services, technical components, technical reconnaissance, attack-path relevance, threat intelligence context and threat profiles
- 4.3) One intelligence requirement, end to end
- 4.4) Threat-centric modelling — from the Generic Threat Landscape to threat profiles: threat assessment and recent adverse cyber events, relevant threat actors of the German threat landscape, threat-scenario risk scoring, modi operandi (MUMMY SPIDER / Emotet, WIZARD SPIDER / Ryuk) and MITRE ATT&CK
- 4.5) Threat scenario 1 — attack tree mapped to operational depth, kill chain and modus operandi; CAPEC, CWE and CVE as the formalisation layer under the attack tree
- 4.6) Environmental effects (PESTLE-M) and the digital footprint — the attacker’s view
- 4.7) How the three perspectives converge in the threat scenario
- Q&A (approx. 15 min)
- What participants take home
- Participants can say what a Cyber Threat Model is, which elements it must contain, and what makes one defensible under DORA and TIBER-EU — and they have seen one built, from business parameters to a scored threat scenario with an attack tree.
Zielgruppe
- Security Consultants
- Security Analysts
- Security Investigators
- Threat Hunters
- Incident Responders
- CTI Analysts and CTI Managers
- TLPT / Red-Team Leads