2024 SANS CTI report summary
In last year's annual cyber threat intelligence (CTI) research report from the SANS Institute, SANS CTI Survey 2024: Managing the Evolving Threat Landscape, the report delves into several important topics related to cyber threat intelligence (CTI), including:
- Geopolitical and regulation landscapes are critical in a CTI team’s tasks
- Threat hunting is now the top use case for CTI
- AI is making its mark on CTI, with nearly one-quarter of respondents leveraging AI in their CTI program
SANS findings: Threat hunting
One of the key findings that the report highlights is significant and underscores the value of threat intelligence. For the first time in the survey’s history, threat hunting is the top use case for CTI. Roughly 75% of respondents said CTI data is used for this purpose. The next two use cases are incident response (73.5%) and vulnerability management (66.3%).
As stated in the SANS report, “Threat hunting is a proactive approach for detecting threats that are either unidentified or not yet remediated within an organization’s network… Respondents report they ‘leverage threat intel to scope and target threat hunts against the organization’ and ‘create threat hunt packs for particular malware or APTs.’”
Threat hunting is a constant game of cat and mouse. It’s about finding the threat actors before they find you. It's thrilling to see that CTI is widely embraced for the value it brings to threat hunting, an activity that we spend a fair amount of time doing.
Why is CTI so important to effective threat hunting?
There are many use cases for real-time, contextual CTI, including threat hunting. The deep-dive investigative capabilities afforded by comprehensive CTI empower threat-hunting teams to find the highest-priority threats to remediate.
Asset monitoring
A real-time CTI solution can compile, manage, and monitor the organization’s complete asset inventory across any external source to include the deep and dark web, messaging platforms, and more through automated capabilities. We call this “threat monitoring,” referring to the continuous nature, rather than “threat hunting,” which is manual. This process identifies potential risks and exposures and helps security teams understand threat actors’ potential attack vectors and TTPs to proactively expose and prevent emerging cyber-attacks before they are weaponized. For example, CTI can identify malicious links published in external sources, extract the URLs, and then block it on the corporate firewall, triggering playbooks on the organization’s SIEM, SOAR, EPP, or VM platforms before others have a chance to download or click on it.
Data integration
Threat-hunting activities often span multiple tools and data sets. An effective CTI solution should allow security engineers to integrate and easily cross-reference data between their tools to save time and resources. For example, a security engineer should be able to review logs within their SIEM for suspicious activity or indicators and immediately enrich those indicators with CTI to know whether or not a threat exists.
Protecting sensitive data
Threat hunting, or monitoring, is also essential to protect credentials, methods of payment, and sensitive data. Continuous, real-time monitoring of the company’s critical assets, brand, and employee and customer data across the surface web and cybercriminal underground is foundational. This continuous monitoring ensures that security teams receive early warnings of active threats relevant to the organization as they surface so they can take proactive defensive measures to protect the organization, its assets, and customers.
Incident detection
As shown in the SANS CTI survey results, incident (detection and) response and vulnerability management also rank in the top three CTI use cases. The value of the insights gained from comprehensive, contextual CTI in helping these efforts cannot be understated. The autonomous, continuous collection of CTI across the deep, dark, and clear web and monitoring of an organization’s attack surface means security teams can be alerted to potential threats and incidents so they can respond with preemptive action before threats materialize into an attack.
Vulnerability detection
Additionally, comprehensive, real-time contextual threat intelligence with attack surface scanning can inform a security team of what vulnerabilities the organization has. But more than that, it also indicates the specific vulnerabilities that threat actors are currently exploiting, highlighting those that put the organization at risk – which is critical for prioritizing remediation efforts.