International Cyber Expo International Cyber Expo
  • About Us
Tuesday, 21 July, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Vintage threat intelligence still tastes good

by The Gurus
April 29, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

In the Spring of 2001 I attended a week long ‘ethical hacking’ course run by Internet Security Systems, a company that is now a security research team at IBM. The training was excellent, both explaining how to explore and break into systems then allowing students to exploit servers, steal information, crack passwords and deface websites. This was, naturally, conducted within a carefully controlled lab environment.
The course was based largely on a new series of books called Hacking Exposed. I went straight out and bought the second edition of Hacking Exposed from a local bookshop as soon as the course was over. I have picked up other versions over the years, but that second edition has aged well, the information remaining generally applicable to today’s environment. Vulnerabilities and tools may evolve, but the things hackers do are largely the same.
This is, in some ways, quite reassuring. Those who want to protect systems are well advised to keep abreast of the latest developments in how systems are breached. But could it be that reading a book on hacking every 15 years is nearly enough to keep you up to date in your mission to gather useful threat intelligence?
It’s a hard idea to swallow, especially if you are a CISO who is already spending hundreds of thousands of any western currency each year on so-called threat intelligence feeds. It means you need to do some reading, probably research further afield to fill in gaps and ultimately understand the problem at a lower level than you might have wanted. You can’t throw money at that – just time and brain cells. Many of us have less of the latter than the former, sadly.
It’s worth remembering that threat intelligence has to be relevant to you, otherwise it’s just plain information. A feed of malware hashes or IP addresses of command and control servers might seem useful, but only if some of that malware comes your way. Without analysis and a subsequent discovery that it is relevant the information does not graduate to ‘threat intelligence’.
For example, you may receive news that a madman is on the rampage with an axe in Croydon, UK. And you live in San Francisco. Unless you have people you care about living in Croydon this news is not threat intelligence, it is just information. If you remember that you have loved ones in the area then that analysis converts the information to useful threat intelligence upon which you should act as quickly as possible, by warning anyone who needs to know.
Let’s return to the idea that basic, general threat intelligence can be useful for a good, long time. The book simply provides information, remember. You need analysis to create threat intelligence. If you understand your business and its IT processes then you can distil threat intelligence from its pages. Of course, not every hacker is the same. Motivations and tactics vary, but ultimately you can boil down the basics to one sheet of A4, which you can find written inside the back cover of Hacking Exposed.
If you are sceptical that real black hat hackers would follow such apparently straight-forward processes and use freely-available tools you might be interested in a case in which an Italian security firm was breached, its data being leaked onto the internet in considerable quantities.
Hacking Team, which specialises (ironically) in providing software and services to agencies that want to breach the computers belonging to people of special interest, ought to have been a fairly hard target. However, we now know how its attacker managed to break in and steal passwords, files and access to other systems without resorting to brand new tools and techniques.
The details were published in English via the Pastebin website (http://pastebin.com/raw/0SNSvyjJ) on 15/04/2016. The document is very interesting because it gives the lowdown on how the self-professed “blackhat hacker” Phineas Fisher operated. His process will be familiar to anyone who has read Hacking Exposed or any similar guide to penetration testing.
Phineas details not only what he did but what his victims could have done to stop him. That free advice, which applies to nearly everyone, is valuable threat intelligence that is already of a good vintage and that should age well over foreseeable years.
 
 
@spgedwards
@selabsuk
www.selabs.uk
Simon is Director of SE Labs, a security consultancy company that specialises in testing security products and services using current threats. He is also Technical Director at global risk and security specialist BGS Intelligent Security Solutions. Operating as an IT journalist between 1995 and 2010, Simon worked on the UK’s biggest computer magazine titles. At Dennis Publishing these included titles such as Computer Shopper, PC Pro, Computer Active, Web User, Mac User and IT Pro. One of Simon’s areas of expertise is anti-malware testing and he was, until the end of 2015, Technical Director of Dennis Technology Labs, an independent security testing business that is part of the Dennis Publishing media company. A founder member of the Anti-Malware Testing Standards Organisation (AMTSO), Simon was chairman of the organisation’s Board of Directors between 2012 and 2015.

ShareTweet
Previous Post

What CISOs want in 2016

Next Post

TrueCrypter ransomware lets you pay with Amazon gift cards

Recent News

What Does the Cyber Industry Want to See From the New UK Government?

What Does the Cyber Industry Want to See From the New UK Government?

July 20, 2026
Purple Logo, capitalised letters: SALT.

Salt Security tackles AI governance challenge with 100 pre-built agentic security policies

July 20, 2026
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

July 20, 2026
Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

Scams Now Drive Almost Half of All Malware Detections as Attackers Weaponise Everyday Trust

July 20, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol