Skip to content

uliyach45/Cyber-Threat-Intelligence-Assignment

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 

Repository files navigation

Cyber Threat Intelligence — Assignment 1

Module: Cyber Threat Intelligence
Academic Year: 2024–2025


📋 Overview

This repository contains my academic assignment for the Cyber Threat Intelligence (CTI) module. The assignment covers in-depth analysis of CTI concepts, frameworks, and their practical application across multiple real-world scenarios.


📁 Contents

File Description
CTI.docx Full assignment with all questions answered and references
README.md This file

🧠 Topics Covered

The assignment is structured around 10 questions across multiple scenarios:

  1. Threat Intelligence Investigation — Dark web credential exposure & VPN brute-force attack; PIR design, collection planning, enrichment techniques
  2. CTI Frameworks & Defensive Strategy — Intelligence Lifecycle applied to APT defense; Diamond Model and Cyber Kill Chain analysis
  3. CTI Lifecycle Application — C2 communication detection in a financial organization; collection strategy and indicator analysis
  4. Analytical Reasoning & CTI Integration — Ransomware threat intelligence; Data → Information → Intelligence transformation; ACH methodology
  5. Malware Campaign Analysis — Phishing-to-persistence campaign; indicator classification, correlation, and attribution
  6. Building an Organizational CTI Capability — Healthcare sector CTI framework; threat data processing and stakeholder dissemination
  7. Intelligence Evaluation and Threat Modeling — Multi-source intelligence reliability assessment using the NATO Admiralty Code; threat modeling
  8. Intelligence Frameworks & Strategic Decision Making — ATT&CK TTP mapping; campaign pattern recognition; strategic intelligence reporting
  9. Intrusion Analysis Using Analytical Frameworks — Full Kill Chain reconstruction + Diamond Model applied to a targeted intrusion scenario
  10. Indicators, Tactics & Threat Hunting — IOC vs TTP comparison; threat hunting hypothesis design; SIEM/EDR detection engineering

🔧 Frameworks & Models Referenced

  • MITRE ATT&CK — Adversary tactic and technique mapping
  • Lockheed Martin Cyber Kill Chain — Intrusion stage reconstruction
  • Diamond Model of Intrusion Analysis — Adversary-infrastructure-capability-victim relationships
  • Analysis of Competing Hypotheses (ACH) — Structured analytical reasoning
  • Pyramid of Pain — IOC vs TTP defense value
  • NATO Admiralty Code — Source reliability and information credibility assessment
  • STIX 2.1 / TAXII 2.1 — Threat intelligence sharing standards
  • Intelligence Lifecycle — Plan → Collect → Process → Analyse → Disseminate → Feedback

📚 Key References

  • Caltagirone, Pendergast & Betz (2013) — The Diamond Model of Intrusion Analysis
  • Hutchins, Cloppert & Amin (2011) — Intelligence-Driven Computer Network Defense (Lockheed Martin)
  • Heuer, R.J. (1999) — Psychology of Intelligence Analysis (CIA)
  • Bianco, D. (2014) — The Pyramid of Pain
  • MITRE Corporation (2023) — ATT&CK Frameworkhttps://attack.mitre.org
  • OASIS (2021) — STIX 2.1 Standard

⚠️ Academic Integrity Notice

This repository is shared for portfolio and learning purposes only.
Please do not copy or submit this work as your own — that would constitute academic plagiarism.


📬 Contact

Uliya Fatima — Student ID: 232098

About

Academic assignment on Cyber Threat Intelligence — covering Kill Chain, Diamond Model, ATT&CK framework, threat hunting, and intelligence lifecycle analysis.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors