Why this exists
Putting notes on a page solves two problems. Future me will misplace handwritten notes, and present me needs something legible when studying. Thank me later.
CYSA+ study area.
Open source intelligence, indicator management, STIX, TAXII, and threat intelligence basics without pretending acronyms are personality traits.
Notes
Present me looking out for future me. Future me loses handwritten notes.
Putting notes on a page solves two problems. Future me will misplace handwritten notes, and present me needs something legible when studying. Thank me later.
Open source intelligence is information publicly available to everyone. It can come from online media, blogs, unclassified government data, academic publications, industry data, and gray literature.
Closed source intelligence usually requires a fee or subscription. The point is often timeliness, relevance, accuracy, and confidence. Analysts rely on data to make decisions. Bad data wastes time and can mislead the defense.
STIX is a structured language for communicating cyber threat information. TAXII is an application protocol for exchanging CTI over HTTPS. The useful part is not the acronym. The useful part is moving threat data between people and systems before the incident gets comfortable.