NL

What is threat intelligence and how is it used in MDR?

Date: 01-10-2022

Threat intelligence is up-to-date knowledge about existing and emerging cyber threats. It can include suspicious IP addresses, domain names, malware, vulnerabilities and attack methods. Organisations use this intelligence to identify cyberattacks earlier, assess them more accurately and respond more quickly. SBL Cyber Monitoring uses threat intelligence as part of its Managed Detection & Response services. Through Connect2Trust, SBL receives relevant threat intelligence from a range of Dutch and international sources.

SBL Cyber Monitoring has become a Gold participant in the Connect2Trust Foundation. Connect2Trust is recognised as an information-sharing intermediary by the Dutch Ministry of Justice and Security. The threat intelligence it receives from sources including the Dutch National Cyber Security Centre and the Nederlands Security Meldpunt is now an integral part of SBL Cyber Monitoring’s services.

What does this mean for SBL and its customers?
 

How does threat intelligence work?

Threat intelligence is information about potential, current and emerging cyber threats. It can include technical data such as IoCs (Indicators of Compromise), URLs, domain names, IP addresses, file hashes and other malware characteristics. It can also provide broader insights into vulnerabilities, attack methods and cybercriminal activity.

Raymond Bierens, Chairman of the Board at Connect2Trust, explains: “We are recognised by the Ministry as an information-sharing intermediary. This means that we are a trusted hub recognised by the government. We receive information from a wide range of parties, including the US government, the Dutch government, numerous other government organisations and many non-profit organisations, about developments in the cyber threat landscape.”
 

What are the benefits of threat intelligence?

Threat intelligence plays an essential role in effective cyber monitoring for several reasons:

  • Early detection: Up-to-date threat intelligence enables security systems to identify potential threats more quickly and accurately.
  • Contextual insight: It provides context for detected anomalies, enabling security teams to make better-informed decisions.
  • Proactive security: Organisations can take preventive measures against emerging threats before they affect their networks and systems.
  • Rapid response: During an incident, threat intelligence can help security teams identify the threat more quickly, contain it and mitigate its impact.


Bierens emphasises the importance of speed: “Our objective is that, once a vulnerability is disclosed, an organisation should be able to address it within one hour. We use this one-hour target because the fastest attack we had seen at the time compromised a company within 63 minutes. That is one of our key performance indicators.”
 

How does Connect2Trust collect threat intelligence?

Connect2Trust is a non-profit foundation recognised as an information-sharing intermediary by the Dutch Ministry of Justice and Security. It plays an important role in collecting, analysing and distributing threat intelligence to participating organisations.

Connect2Trust can provide organisation-specific alerts. For example: “Your organisation uses a particular Microsoft product. A vulnerability has been identified, which means that the affected system must be updated to prevent attackers from exploiting it.” This is a targeted alert based on the devices and systems used by the organisation.

Connect2Trust also distributes general alerts. An example might be: “A new update is available for Windows or for a Siemens product.” These alerts are more general because organisations must determine whether the affected products are present within their own environments.
 

How is threat intelligence used within Managed Detection & Response?

By integrating threat intelligence into Managed Detection & Response solutions such as SBL Cyber Monitoring’s WatchEagle Detection & Response, organisations benefit from a stronger level of security. The automated system continuously analyses network traffic and other relevant data using the latest threat intelligence, enabling faster detection of and response to potential cyber threats.

WatchEagle Detection & Response is connected to Connect2Trust’s ThreatMatcher platform. WatchEagle automatically analyses network traffic from participating customers for technical indicators associated with known threats. These indicators can include IoCs (Indicators of Compromise), URLs, domain names, IP addresses, file hashes and other malware characteristics. When a potential threat is detected, the customer and, where applicable, its external IT service provider are immediately notified so that appropriate action can be taken.
 

SBL Cyber Monitoring customers can also participate in Connect2Trust

Each SBL Cyber Monitoring customer can join Connect2Trust as a Silver participant at no additional cost. This gives organisations access to specific threat intelligence concerning the systems and potential access points within their networks. When an alert requires further action, SBL Cyber Monitoring can assist customers in assessing the threat and determining the appropriate response.
 

Using threat intelligence effectively through cyber monitoring

Up-to-date threat intelligence delivers the greatest value when it is correlated with the network traffic and systems within your organisation. WatchEagle continuously analyses activity and uses current threat intelligence to identify potential cyberattacks more quickly.

Discover WatchEagle Detection & Response