
Our Cyber Threat Intelligence (CTI) service is crucial in getting external and Internal information on emerging threats and indicators of compromise (IOCs) related to the ICT assets of your organization.
The compilation and analysis related to threats, IOCs or attack typologies are studied by Axendit's experts to be compared with the Client's systems, evaluating whether they can generate a potential risk on them. The information issued has a preventive value that will help the client to define and adopt the best proactive and protection measures in their systems.
We use industry standard threat modeling techniques like MITRE ATT&CK framework and the objective of this is to determine:
- Current Threats and threat actors targeted at the industry the customer is recognized.
- Attack techniques that can be used in the client’s environment considering ITsec systems.
- Means of prevention/mitigation in relation to the identified techniques.
- Possible gaps and/or events logged in the environment for the purpose of detection of attack techniques.
- Periodic report with information on current IOCs and threats with possible impact on the Client.
- Recommendations on different aspects of application risk in the Client's specific security environment based on the research of intelligence gathered and solutions for mitigation, early detection and prevention of attacks.
Our Open-Source Intelligence (OSINT) Service is important for assessing customers information and services available on the internet or social media that could be exploited while enabling the threat actors to gain access or further intelligence to further exploit a vulnerability, human or system vulnerability.
We carry out these tests and checks and share our findings to enable the customer/client based on our recommendation remove some of those information that are publicly available or use implementations that ensure they are monitoring the utilization of those information. Some of the checks and test we do during OSINTs are;
General Tests: - Searching for publicly available/shared sensitive information
- Verification of the presence of employee accounts/e-mail addresses in leaks
Network Tests:- Searching for publicly available/shared sensitive information
- Verification of the presence of employee accounts/e-mail addresses in leaks
DNS related tests:- Gathering information on available subdomains
- DNS configuration validation - e.g. zone transfer attempts
WWW survey:- Searching for publicly available/shared sensitive information
- Identification of the web software and its version
- Identification of the vulnerabilities of the CMS used
- Accessible pages, login panels etc. that should not be available to the public
- Verification of the presence of redundant files – remenants of the programmer’s work files and documents that should not be publicly available (e.g. Open Directory)