TIBER: connecting threat intelligence and red teaming

No ratings

Presented at FIRSTCyberThreatIntelligenceSymposium 2019 by

TIBER (Threat Intelligence Based Ethical Red Teaming) is a framework that aims to deliver attack simulations of the highest quality in order to test the financial sector’s resilience to cyber attacks. Since May 2018, it is accepted by the European Central Bank as the go-to cyber resilience testing framework for national and European authorities within the Euro zone. The framework has big aspirations, including the ambition to test TTPs employed by nation state actors in operations that run for multiple months. But is this even possible, and how?In this talk we will deep dive into the TIBER framework and our hands-on experiences with it, sharing best practices on how to connect threat intelligence with red teaming. Amongst others, the following topics will be addressed:How is TIBER different from other red teaming and threat intelligence frameworks (such as CBEST)?What threat intelligence does a red team need to perform a top notch test?Threat actor modelling in red teaming.Common OPSEC mistakes by blue teams during operational TI collection.RedELK: open source tooling for offensive TI during red teams operations.