It is really important, in infosec and natsec, to understand if your adversary is making a tactical or a strategic choice.
For instance, why are they moving laterally? Is it because they just aren’t able to get their tool to run, or because they know exactly what system they want to reach on your network?
Is the immediate attack a distraction, or is it the point?
Good analysis and Intel is very important, for this reason. Not just a bunch of IOCs. Real operational understanding and intelligence.
If you do not understand the difference between tactics, strategy, and logistics I highly, highly recommend you read up on this. It’s one of those military concepts that really does apply to cybersecurity and business. https://en.m.wikipedia.org/wiki/Tactic_(method)
You can follow @hacks4pancakes.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.