The original post: /r/cybersecurity by /u/MR_TR1 on 2024-10-07 23:07:04.

Hello, I have started my new position as CTI Analyst. My boss asked me to track APTs targeting our organisation. Right now we have bunch of feeds throwing iocs into MISP which I feel is not that intelligent. Can you help me where to start? How to collect threat intelligence and how to track down APTs.

Ideas I have

  1. Get some paid feeds and analyse them
  2. Go to OSINT and track posts related to specific APT.

Any suggestions are really helpful.