SlideShare a Scribd company logo
Understanding Indicators
Towards An Information Security
Ontology
Joe Slowik
An Overview Of Indicators
A Digression On Language
Reimagining Indicators & Observations
Conclusions
Today’s Agenda
An Overview
Of Indicators
© Huntress Labs. All rights reserved
Indicators
4
An Overview Of Indicators
© Huntress Labs. All rights reserved
What Is An Indicator?
5
An Overview Of Indicators
Indicator
“Data
Point”
Sign Of
Event
Enables
Sharing
© Huntress Labs. All rights reserved
“Indicators”
6
An Overview Of Indicators
© Huntress Labs. All rights reserved
“Indicators”
7
An Overview Of Indicators
© Huntress Labs. All rights reserved
“Indicators”
8
An Overview Of Indicators
“Indicator” Is An
Overloaded Concept!
© Huntress Labs. All rights reserved
“Indicators”
9
An Overview Of Indicators
“Indicator” Is An
Overloaded Concept!
Many Terms Used
Interchangeably
© Huntress Labs. All rights reserved
“Indicators”
10
An Overview Of Indicators
“Indicator” Is An
Overloaded Concept!
Many Terms Used
Interchangeably
Result Is Confusion In
Purpose, Meaning
© Huntress Labs. All rights reserved
“Indicators”
11
An Overview Of Indicators
© Huntress Labs. All rights reserved
Indicators In A Perfect World
12
An Overview Of Indicators
© Huntress Labs. All rights reserved
Indicators In A Perfect World
13
An Overview Of Indicators
Understand The Purpose, Function, & Significance Of A Given
Indicator, Why It Matters & When It Was Observed
Context
© Huntress Labs. All rights reserved
Indicators In A Perfect World
14
An Overview Of Indicators
Understand The Purpose, Function, & Significance Of A Given
Indicator, Why It Matters & When It Was Observed
Context
Indicator Is Tightly Correlated To Adversary Activity, Resulting In
High-Confidence Link To Malicious Behavior When Observed
Accuracy
© Huntress Labs. All rights reserved
Indicators In A Perfect World
15
An Overview Of Indicators
Understand The Purpose, Function, & Significance Of A Given
Indicator, Why It Matters & When It Was Observed
Context
Indicator Is Tightly Correlated To Adversary Activity, Resulting In
High-Confidence Link To Malicious Behavior When Observed
Accuracy
Indicator Enables Some Action Or Understanding To Take Place -
From A Simple Block/Alarm To Adversary Understanding
Applicability
© Huntress Labs. All rights reserved
Indicators In A Perfect World
16
An Overview Of Indicators
© Huntress Labs. All rights reserved
The “Birth” Of An Indicator
17
An Overview Of Indicators
© Huntress Labs. All rights reserved
The “Birth” Of An Indicator
18
An Overview Of Indicators
Continuous Refinement & Enrichment Is Necessary
To Go Beyond “Mere Data” To “Something Happened”
(Observable) To Something Of Interest Identified
(Indicator)
© Huntress Labs. All rights reserved
19
An Overview Of Indicators
“Indicator” & “IOC” Are
Used Interchangeably
Time & Events
© Huntress Labs. All rights reserved
20
An Overview Of Indicators
“Indicator” & “IOC” Are
Used Interchangeably
IOC Is A Sign Of Something
That HAPPENED
Time & Events
© Huntress Labs. All rights reserved
21
An Overview Of Indicators
“Indicator” & “IOC” Are
Used Interchangeably
IOC Is A Sign Of Something
That HAPPENED
How Do We Refer To
Things Yet-To-Be?
Time & Events
© Huntress Labs. All rights reserved
Time & Events
22
An Overview Of Indicators
Indicators Sourced OUTSIDE Of Or PRIOR TO An
Event Cannot Be Indicators Of (Known) Compromise -
So What Are These???
© Huntress Labs. All rights reserved
Time & Events
23
An Overview Of Indicators
Indicators Sourced OUTSIDE Of Or PRIOR TO An
Event Cannot Be Indicators Of (Known) Compromise -
So What Are These???
No (Good) Answers - Yet?
© Huntress Labs. All rights reserved
Indicators In Reality
24
An Overview Of Indicators
Lack Of Context
● Indicators Are Frequently Shared Absent Context!
● Minimal Enrichment & Metadata Provided To Disposition & Determine!
● Indicators Are Effectively “Raw Data”
© Huntress Labs. All rights reserved
Indicators In Reality
25
An Overview Of Indicators
Lack Of Context
● Indicators Are Frequently Shared Absent Context!
● Minimal Enrichment & Metadata Provided To Disposition & Determine!
● Indicators Are Effectively “Raw Data”
Limited Scope
● “Indicators” Are Provided “As Is”
● Difficult To Extrapolate From Single Technical Artifact To Something More
● Purpose, Function, & Creation Observations Are Not Considered
© Huntress Labs. All rights reserved
Indicators In Reality
26
An Overview Of Indicators
© Huntress Labs. All rights reserved
Indicators In Reality
27
An Overview Of Indicators
© Huntress Labs. All rights reserved
Indicators In Reality
28
An Overview Of Indicators
Indicators Have Effectively Become Equivalent With
Raw Data - Sense Of Context & Enrichment Is Lost Or
Ignored
© Huntress Labs. All rights reserved
Indicators & Adversary Operations
29
An Overview Of Indicators
© Huntress Labs. All rights reserved
Indicators & Adversary Operations
30
An Overview Of Indicators
Technical Indicators Are
SPECIFIC IDENTIFIERS
© Huntress Labs. All rights reserved
Indicators & Adversary Operations
31
An Overview Of Indicators
Technical Indicators Are
SPECIFIC IDENTIFIERS
PARTICULAR Example Of
A GENERAL Behavior
© Huntress Labs. All rights reserved
Indicators & Adversary Operations
32
An Overview Of Indicators
Technical Indicators Are
SPECIFIC IDENTIFIERS
PARTICULAR Example Of
A GENERAL Behavior
Focus On Indicators Ignores
What Gave Them Birth
A Digression
On Language
© Huntress Labs. All rights reserved
Isn’t This All Nitpicking?
34
A Digression On Language
© Huntress Labs. All rights reserved
But…
35
A Digression On Language
© Huntress Labs. All rights reserved
The Importance Of Accurate Language
36
A Digression On Language
© Huntress Labs. All rights reserved
The Importance Of Accurate Language
37
A Digression On Language
Language Defines How We Communicate &
Understand Concepts
© Huntress Labs. All rights reserved
The Importance Of Accurate Language
38
A Digression On Language
Language Defines How We Communicate &
Understand Concepts
Accurate Language & Its Use Facilitates
Follow-On Action & Comprehension
© Huntress Labs. All rights reserved
The Importance Of Accurate Language
39
A Digression On Language
Language Defines How We Communicate &
Understand Concepts
Accurate Language & Its Use Facilitates
Follow-On Action & Comprehension
We Need To Critically Examine How We
Describe Matters For Accuracy!
© Huntress Labs. All rights reserved
Outcomes Of Indifferent Language
40
A Digression On Language
© Huntress Labs. All rights reserved
Outcomes Of Indifferent Language
41
A Digression On Language
Overlapping
Meanings &
Purposes As
Terms Collide
© Huntress Labs. All rights reserved
Outcomes Of Indifferent Language
42
A Digression On Language
Overlapping
Meanings &
Purposes As
Terms Collide
Inhibits
Understanding,
Engenders
Confusion, &
Leads To Poor
Outcomes
© Huntress Labs. All rights reserved
Outcomes Of Indifferent Language
43
A Digression On Language
Overlapping
Meanings &
Purposes As
Terms Collide
Inhibits
Understanding,
Engenders
Confusion, &
Leads To Poor
Outcomes
Improper,
Inaccurate
Language Use
Results In
Suboptimal
Results!
© Huntress Labs. All rights reserved
Defining “Indicator”
44
A Digression On Language
The Word “Indicator” & Its Relatives May Appear
Inconsequential Save For Their Use - But Being
“Loose” With Details & Explanations Can Be
Dangerous!
© Huntress Labs. All rights reserved
Dangers Of Loose Language
45
A Digression On Language
Interpreting
Common Items
As Specific To
A Threat
Falsely
Identifying
Unique
Characteristics
Mis-Applying
Intelligence
Items To
Defense
Defending On
Lagging
Characteristics
Over
Confidence Based
On Specific
Observations
© Huntress Labs. All rights reserved
“Death Of The Indicator”
46
A Digression On Language
© Huntress Labs. All rights reserved
“Death Of The Indicator”
47
A Digression On Language
© Huntress Labs. All rights reserved
“Death Of The Indicator”
48
A Digression On Language
© Huntress Labs. All rights reserved
“Death Of The Indicator”
49
A Digression On Language
© Huntress Labs. All rights reserved
“Death Of The Indicator”
50
A Digression On Language
“Indicator” Has Become A “Bad Word” In Infosec &
CTI - But Maybe That’s Because We’ve Played
Fast-And-Loose With The IDEA Of An Indicator
Reimagining
Indicators &
Observations
© Huntress Labs. All rights reserved
What Is An Indicator?
52
Reimagining Indicators & Observations
© Huntress Labs. All rights reserved
What Is An Indicator?
53
Reimagining Indicators & Observations
Indicator
© Huntress Labs. All rights reserved
What Is An Indicator?
54
Reimagining Indicators & Observations
Indicator
Technical
Observable
Artifact Of
Compromise
Behavioral
Artifact
© Huntress Labs. All rights reserved
What Is An Indicator?
55
Reimagining Indicators & Observations
Indicator
Technical
Observable
Artifact Of
Compromise
Behavioral
Artifact
Communication
Object
Forensic
Item
Intelligence
Observable
© Huntress Labs. All rights reserved
One Indicator, Many Meanings
56
Reimagining Indicators & Observations
© Huntress Labs. All rights reserved
One Indicator, Many Meanings
57
Reimagining Indicators & Observations
Indicators Have MANY
Applications
© Huntress Labs. All rights reserved
One Indicator, Many Meanings
58
Reimagining Indicators & Observations
Indicators Have MANY
Applications
Multiple Applications
Lead To Multiple Views
© Huntress Labs. All rights reserved
One Indicator, Many Meanings
59
Reimagining Indicators & Observations
Indicators Have MANY
Applications
Multiple Applications
Lead To Multiple Views
Application-Centric
Understanding Is Necessary!
© Huntress Labs. All rights reserved
Indicators Pre- & Post-Action
60
Reimagining Indicators & Observations
© Huntress Labs. All rights reserved
Indicators Pre- & Post-Action
61
Reimagining Indicators & Observations
Indicators As
Technical
Observations
Of An Action
Or Event
© Huntress Labs. All rights reserved
Indicators Pre- & Post-Action
62
Reimagining Indicators & Observations
Origins Of The
Technical
Observation &
Its Behavior
Indicators As
Technical
Observations
Of An Action
Or Event
Applications
Of The
Indicator &
Its Use
© Huntress Labs. All rights reserved
Indicators Pre- & Post-Action
63
Reimagining Indicators & Observations
POST Observation Indicators Diversify Into Their
Applications & Use.
PRE Observation Characteristics Enable Researchers
To Identify Trends & Tendencies!
© Huntress Labs. All rights reserved
Creating Indicators, Revisited
64
Reimagining Indicators & Observations
Data Observation Indicator
© Huntress Labs. All rights reserved
Creating Indicators, Revisited
65
Reimagining Indicators & Observations
© Huntress Labs. All rights reserved
Creating Indicators, Revisited
66
Reimagining Indicators & Observations
Collection & Telemetry Provides Data
© Huntress Labs. All rights reserved
Creating Indicators, Revisited
67
Reimagining Indicators & Observations
Collection & Telemetry Provides Data
Data Is Refined Into Observations That Can
Relate To Activity Of Interest
© Huntress Labs. All rights reserved
Creating Indicators, Revisited
68
Reimagining Indicators & Observations
Collection & Telemetry Provides Data
Data Is Refined Into Observations That Can
Relate To Activity Of Interest
Analysis Of Observations & Incidents Ties
These To Activity - Producing Indicators
© Huntress Labs. All rights reserved
INDICATORS!!!
69
Reimagining Indicators & Observations
Indicators Are A Sign That “Something” Has Taken
Place - POST Observations Inform WHY Those
Actions Occurred - PRE Observations Tell Us HOW.
The Key To Cracking Indicators Is Breaking Them
Apart To Reveal More About HOW.
© Huntress Labs. All rights reserved
Indicators & Components
70
Reimagining Indicators & Observations
Malicious
File Object
File
Hash
ITW
Name
Compile
Info
Strings
Functions &
Actions
Meta-
Data
© Huntress Labs. All rights reserved
Indicators & Components
71
Reimagining Indicators & Observations
Network
Indicator
Registrar
TLD Or
Naming
Hosting
Provider
Name
Servers
SSL/TLS
Info
Hosting
Geo
© Huntress Labs. All rights reserved
Indicators As Composite Objects
72
Reimagining Indicators & Observations
© Huntress Labs. All rights reserved
Indicators As Composite Objects
73
Reimagining Indicators & Observations
Understanding Components
Reveals Indicator Complexity!
© Huntress Labs. All rights reserved
Indicators As Composite Objects
74
Reimagining Indicators & Observations
Understanding Components
Reveals Indicator Complexity!
Composite Nature Of Indicators
Reveals Underlying Behaviors!
© Huntress Labs. All rights reserved
Indicators As Composite Objects
75
Reimagining Indicators & Observations
Understanding Components
Reveals Indicator Complexity!
Composite Nature Of Indicators
Reveals Underlying Behaviors!
Enables Intelligence &
Forward-Looking Action!
© Huntress Labs. All rights reserved
Indicators As Composite Objects
76
Reimagining Indicators & Observations
Conclusions
© Huntress Labs. All rights reserved
Where Are We Now?
78
Conclusions
The Idea Of An “Indicator” Is A Surprisingly
Complex Topic!
Understanding WHAT They Are And HOW They
Are Created Is Vital!
© Huntress Labs. All rights reserved
Clarity In Language & Vision
79
Conclusions
© Huntress Labs. All rights reserved
Clarity In Language & Vision
80
Conclusions
Analysts Must
Understand
WHAT They’re
Communicating
& WHY
© Huntress Labs. All rights reserved
Clarity In Language & Vision
81
Conclusions
Analysts Must
Understand
WHAT They’re
Communicating
& WHY
Clarity In
Communication
SHOULD Lead
To Clearer
Results &
Action
© Huntress Labs. All rights reserved
Clarity In Language & Vision
82
Conclusions
Analysts Must
Understand
WHAT They’re
Communicating
& WHY
Clarity In
Communication
SHOULD Lead
To Clearer
Results &
Action
Focus On
What We
KNOW & How
To
Communicate
It To Others!
© Huntress Labs. All rights reserved
Toward A Recognized Ontology
83
Conclusions
Discipline Around “Indicator,” “Observable,”
“Data,” “IOC,” & Similar May Seem Pedantic.
But With Controlled Statements & Understanding
We Can Achieve Clearer, More Accurate
Communication - And Follow-On Action!
Understanding Indicators
© Huntress Labs. All rights reserved
Selected Resources
85
● Analyzing Network Infrastructure As Composite Objects, Joe Slowik
(https://www.domaintools.com/resources/blog/analyzing-network-infrastructure-as-composite-o
bjects/)
● Open IOC: Back To The Basics, Will Gibb & Devon Kerr
(https://www.mandiant.com/resources/blog/openioc-basics)
● Misunderstanding Indicators Of Compromise, Dave Dittrich & Katherine Carpenter
(https://threatpost.com/misunderstanding-indicators-of-compromise/117560/)
● Formulating A Robust Pivoting Methodology, Joe Slowik
(https://www.domaintools.com/wp-content/uploads/formulating-a-robust-pivoting-methodology.p
df)
● Thrunting Grounds, Amitai Cohen (https://amitaico.substack.com/p/thrunting-grounds)
© Huntress Labs. All rights reserved
Slides!
86

More Related Content

PPTX
HL7 Fhir for Developers
PDF
ATT&CKcon 5.0 Keynote - From Ticket Closers to Practitioners- How Great Secu...
PPTX
20140224 nfais-signal-economy-blossom
PDF
How to Use Open Source Technologies in Safety-critical Medical Device Platforms
PDF
Data Mining & Engineering
PDF
"Distributed Tracing: New DevOps Foundation" by Jayesh Ahire
PDF
The Value of Requirements Uncertainty, Louvain-la-Neuve, October 2013
PPT
07 software connectors (2)
HL7 Fhir for Developers
ATT&CKcon 5.0 Keynote - From Ticket Closers to Practitioners- How Great Secu...
20140224 nfais-signal-economy-blossom
How to Use Open Source Technologies in Safety-critical Medical Device Platforms
Data Mining & Engineering
"Distributed Tracing: New DevOps Foundation" by Jayesh Ahire
The Value of Requirements Uncertainty, Louvain-la-Neuve, October 2013
07 software connectors (2)

Similar to Understanding Indicators (20)

PPTX
Advancing Impact Measurement | Public Good App House
PPTX
Financial Industry Semantics and Ontologies
PDF
Measuring International Financial Supervisory Transparency
PPT
Communications management
PDF
Information Dashboard Science, Design and Development
PDF
slide deck for CLUTCH_SXSW Submission.pdf
PDF
So You Want a Threat Intelligence Function (But Were Afraid to Ask)
PDF
The Seven Deadly Sins of Incident Response
PDF
apidays LIVE London 2021 - Building Trust in API Ecosystems by David O'Neill,...
PPT
lecture7.ppt
PPT
lecture7.ppt
PDF
Impact Over Activity: Why Experimentation is the New Imperative for Scientifi...
PDF
Implementing PeopleSoft Financials and OBIA Together
PPT
Session15
PPT
From Search to Discovery
PDF
[Agile Portugal 2014] - Agile Decision Support System for Upper Management - ...
PDF
The Latest in DevOps: Elite Performance, Productivity, and Scaling - Google
PPTX
From Labs to Production: The Growing Ecosystem of LF Decentralized Trust
PDF
Identify Development Pains and Resolve Them with Idea Flow
KEY
Shaping strategies and Startups
Advancing Impact Measurement | Public Good App House
Financial Industry Semantics and Ontologies
Measuring International Financial Supervisory Transparency
Communications management
Information Dashboard Science, Design and Development
slide deck for CLUTCH_SXSW Submission.pdf
So You Want a Threat Intelligence Function (But Were Afraid to Ask)
The Seven Deadly Sins of Incident Response
apidays LIVE London 2021 - Building Trust in API Ecosystems by David O'Neill,...
lecture7.ppt
lecture7.ppt
Impact Over Activity: Why Experimentation is the New Imperative for Scientifi...
Implementing PeopleSoft Financials and OBIA Together
Session15
From Search to Discovery
[Agile Portugal 2014] - Agile Decision Support System for Upper Management - ...
The Latest in DevOps: Elite Performance, Productivity, and Scaling - Google
From Labs to Production: The Growing Ecosystem of LF Decentralized Trust
Identify Development Pains and Resolve Them with Idea Flow
Shaping strategies and Startups
Ad

More from Joe Slowik (12)

PDF
The Convergence of Threat Behaviors Across Intrusions
PDF
The Disclosure Dilemma - Ensuring Defense
PDF
Burrowing Through The Network - Contextualizing The Vulkan Leaks
PPTX
Assessing the Balance Between Visibility & Confidentiality in ICS Network Tra...
PDF
Thrice Is Nice: Ukraine In Review
PDF
Cyber consequences, operational dependencies, and full scope security
PDF
Mission kill process targeting in ics attacks
PDF
Full-Spectrum Information Operations for Critical Infrastructure Attacks
PDF
Past and future of integrity based attacks in ics environments
PDF
Aligning Threat Intelligence to Defender Needs - Identifying Activity Groups
PDF
EASE spectre meltdown_support
PDF
SANS DFIR Prague: PowerShell & WMI
The Convergence of Threat Behaviors Across Intrusions
The Disclosure Dilemma - Ensuring Defense
Burrowing Through The Network - Contextualizing The Vulkan Leaks
Assessing the Balance Between Visibility & Confidentiality in ICS Network Tra...
Thrice Is Nice: Ukraine In Review
Cyber consequences, operational dependencies, and full scope security
Mission kill process targeting in ics attacks
Full-Spectrum Information Operations for Critical Infrastructure Attacks
Past and future of integrity based attacks in ics environments
Aligning Threat Intelligence to Defender Needs - Identifying Activity Groups
EASE spectre meltdown_support
SANS DFIR Prague: PowerShell & WMI
Ad

Recently uploaded (20)

PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
The New Creative Director: How AI Tools for Social Media Content Creation Are...
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PDF
Introduction to the IoT system, how the IoT system works
PPTX
Slides PPTX World Game (s) Eco Economic Epochs.pptx
PPTX
Internet___Basics___Styled_ presentation
PDF
Sims 4 Historia para lo sims 4 para jugar
PPTX
artificial intelligence overview of it and more
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PPTX
SAP Ariba Sourcing PPT for learning material
DOCX
Unit-3 cyber security network security of internet system
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PPTX
presentation_pfe-universite-molay-seltan.pptx
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PDF
Cloud-Scale Log Monitoring _ Datadog.pdf
PPTX
artificialintelligenceai1-copy-210604123353.pptx
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
introduction about ICD -10 & ICD-11 ppt.pptx
international classification of diseases ICD-10 review PPT.pptx
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
The New Creative Director: How AI Tools for Social Media Content Creation Are...
Job_Card_System_Styled_lorem_ipsum_.pptx
Introduction to the IoT system, how the IoT system works
Slides PPTX World Game (s) Eco Economic Epochs.pptx
Internet___Basics___Styled_ presentation
Sims 4 Historia para lo sims 4 para jugar
artificial intelligence overview of it and more
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
SAP Ariba Sourcing PPT for learning material
Unit-3 cyber security network security of internet system
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
presentation_pfe-universite-molay-seltan.pptx
PptxGenJS_Demo_Chart_20250317130215833.pptx
Cloud-Scale Log Monitoring _ Datadog.pdf
artificialintelligenceai1-copy-210604123353.pptx
Design_with_Watersergyerge45hrbgre4top (1).ppt

Understanding Indicators

  • 1. Understanding Indicators Towards An Information Security Ontology Joe Slowik
  • 2. An Overview Of Indicators A Digression On Language Reimagining Indicators & Observations Conclusions Today’s Agenda
  • 4. © Huntress Labs. All rights reserved Indicators 4 An Overview Of Indicators
  • 5. © Huntress Labs. All rights reserved What Is An Indicator? 5 An Overview Of Indicators Indicator “Data Point” Sign Of Event Enables Sharing
  • 6. © Huntress Labs. All rights reserved “Indicators” 6 An Overview Of Indicators
  • 7. © Huntress Labs. All rights reserved “Indicators” 7 An Overview Of Indicators
  • 8. © Huntress Labs. All rights reserved “Indicators” 8 An Overview Of Indicators “Indicator” Is An Overloaded Concept!
  • 9. © Huntress Labs. All rights reserved “Indicators” 9 An Overview Of Indicators “Indicator” Is An Overloaded Concept! Many Terms Used Interchangeably
  • 10. © Huntress Labs. All rights reserved “Indicators” 10 An Overview Of Indicators “Indicator” Is An Overloaded Concept! Many Terms Used Interchangeably Result Is Confusion In Purpose, Meaning
  • 11. © Huntress Labs. All rights reserved “Indicators” 11 An Overview Of Indicators
  • 12. © Huntress Labs. All rights reserved Indicators In A Perfect World 12 An Overview Of Indicators
  • 13. © Huntress Labs. All rights reserved Indicators In A Perfect World 13 An Overview Of Indicators Understand The Purpose, Function, & Significance Of A Given Indicator, Why It Matters & When It Was Observed Context
  • 14. © Huntress Labs. All rights reserved Indicators In A Perfect World 14 An Overview Of Indicators Understand The Purpose, Function, & Significance Of A Given Indicator, Why It Matters & When It Was Observed Context Indicator Is Tightly Correlated To Adversary Activity, Resulting In High-Confidence Link To Malicious Behavior When Observed Accuracy
  • 15. © Huntress Labs. All rights reserved Indicators In A Perfect World 15 An Overview Of Indicators Understand The Purpose, Function, & Significance Of A Given Indicator, Why It Matters & When It Was Observed Context Indicator Is Tightly Correlated To Adversary Activity, Resulting In High-Confidence Link To Malicious Behavior When Observed Accuracy Indicator Enables Some Action Or Understanding To Take Place - From A Simple Block/Alarm To Adversary Understanding Applicability
  • 16. © Huntress Labs. All rights reserved Indicators In A Perfect World 16 An Overview Of Indicators
  • 17. © Huntress Labs. All rights reserved The “Birth” Of An Indicator 17 An Overview Of Indicators
  • 18. © Huntress Labs. All rights reserved The “Birth” Of An Indicator 18 An Overview Of Indicators Continuous Refinement & Enrichment Is Necessary To Go Beyond “Mere Data” To “Something Happened” (Observable) To Something Of Interest Identified (Indicator)
  • 19. © Huntress Labs. All rights reserved 19 An Overview Of Indicators “Indicator” & “IOC” Are Used Interchangeably Time & Events
  • 20. © Huntress Labs. All rights reserved 20 An Overview Of Indicators “Indicator” & “IOC” Are Used Interchangeably IOC Is A Sign Of Something That HAPPENED Time & Events
  • 21. © Huntress Labs. All rights reserved 21 An Overview Of Indicators “Indicator” & “IOC” Are Used Interchangeably IOC Is A Sign Of Something That HAPPENED How Do We Refer To Things Yet-To-Be? Time & Events
  • 22. © Huntress Labs. All rights reserved Time & Events 22 An Overview Of Indicators Indicators Sourced OUTSIDE Of Or PRIOR TO An Event Cannot Be Indicators Of (Known) Compromise - So What Are These???
  • 23. © Huntress Labs. All rights reserved Time & Events 23 An Overview Of Indicators Indicators Sourced OUTSIDE Of Or PRIOR TO An Event Cannot Be Indicators Of (Known) Compromise - So What Are These??? No (Good) Answers - Yet?
  • 24. © Huntress Labs. All rights reserved Indicators In Reality 24 An Overview Of Indicators Lack Of Context ● Indicators Are Frequently Shared Absent Context! ● Minimal Enrichment & Metadata Provided To Disposition & Determine! ● Indicators Are Effectively “Raw Data”
  • 25. © Huntress Labs. All rights reserved Indicators In Reality 25 An Overview Of Indicators Lack Of Context ● Indicators Are Frequently Shared Absent Context! ● Minimal Enrichment & Metadata Provided To Disposition & Determine! ● Indicators Are Effectively “Raw Data” Limited Scope ● “Indicators” Are Provided “As Is” ● Difficult To Extrapolate From Single Technical Artifact To Something More ● Purpose, Function, & Creation Observations Are Not Considered
  • 26. © Huntress Labs. All rights reserved Indicators In Reality 26 An Overview Of Indicators
  • 27. © Huntress Labs. All rights reserved Indicators In Reality 27 An Overview Of Indicators
  • 28. © Huntress Labs. All rights reserved Indicators In Reality 28 An Overview Of Indicators Indicators Have Effectively Become Equivalent With Raw Data - Sense Of Context & Enrichment Is Lost Or Ignored
  • 29. © Huntress Labs. All rights reserved Indicators & Adversary Operations 29 An Overview Of Indicators
  • 30. © Huntress Labs. All rights reserved Indicators & Adversary Operations 30 An Overview Of Indicators Technical Indicators Are SPECIFIC IDENTIFIERS
  • 31. © Huntress Labs. All rights reserved Indicators & Adversary Operations 31 An Overview Of Indicators Technical Indicators Are SPECIFIC IDENTIFIERS PARTICULAR Example Of A GENERAL Behavior
  • 32. © Huntress Labs. All rights reserved Indicators & Adversary Operations 32 An Overview Of Indicators Technical Indicators Are SPECIFIC IDENTIFIERS PARTICULAR Example Of A GENERAL Behavior Focus On Indicators Ignores What Gave Them Birth
  • 34. © Huntress Labs. All rights reserved Isn’t This All Nitpicking? 34 A Digression On Language
  • 35. © Huntress Labs. All rights reserved But… 35 A Digression On Language
  • 36. © Huntress Labs. All rights reserved The Importance Of Accurate Language 36 A Digression On Language
  • 37. © Huntress Labs. All rights reserved The Importance Of Accurate Language 37 A Digression On Language Language Defines How We Communicate & Understand Concepts
  • 38. © Huntress Labs. All rights reserved The Importance Of Accurate Language 38 A Digression On Language Language Defines How We Communicate & Understand Concepts Accurate Language & Its Use Facilitates Follow-On Action & Comprehension
  • 39. © Huntress Labs. All rights reserved The Importance Of Accurate Language 39 A Digression On Language Language Defines How We Communicate & Understand Concepts Accurate Language & Its Use Facilitates Follow-On Action & Comprehension We Need To Critically Examine How We Describe Matters For Accuracy!
  • 40. © Huntress Labs. All rights reserved Outcomes Of Indifferent Language 40 A Digression On Language
  • 41. © Huntress Labs. All rights reserved Outcomes Of Indifferent Language 41 A Digression On Language Overlapping Meanings & Purposes As Terms Collide
  • 42. © Huntress Labs. All rights reserved Outcomes Of Indifferent Language 42 A Digression On Language Overlapping Meanings & Purposes As Terms Collide Inhibits Understanding, Engenders Confusion, & Leads To Poor Outcomes
  • 43. © Huntress Labs. All rights reserved Outcomes Of Indifferent Language 43 A Digression On Language Overlapping Meanings & Purposes As Terms Collide Inhibits Understanding, Engenders Confusion, & Leads To Poor Outcomes Improper, Inaccurate Language Use Results In Suboptimal Results!
  • 44. © Huntress Labs. All rights reserved Defining “Indicator” 44 A Digression On Language The Word “Indicator” & Its Relatives May Appear Inconsequential Save For Their Use - But Being “Loose” With Details & Explanations Can Be Dangerous!
  • 45. © Huntress Labs. All rights reserved Dangers Of Loose Language 45 A Digression On Language Interpreting Common Items As Specific To A Threat Falsely Identifying Unique Characteristics Mis-Applying Intelligence Items To Defense Defending On Lagging Characteristics Over Confidence Based On Specific Observations
  • 46. © Huntress Labs. All rights reserved “Death Of The Indicator” 46 A Digression On Language
  • 47. © Huntress Labs. All rights reserved “Death Of The Indicator” 47 A Digression On Language
  • 48. © Huntress Labs. All rights reserved “Death Of The Indicator” 48 A Digression On Language
  • 49. © Huntress Labs. All rights reserved “Death Of The Indicator” 49 A Digression On Language
  • 50. © Huntress Labs. All rights reserved “Death Of The Indicator” 50 A Digression On Language “Indicator” Has Become A “Bad Word” In Infosec & CTI - But Maybe That’s Because We’ve Played Fast-And-Loose With The IDEA Of An Indicator
  • 52. © Huntress Labs. All rights reserved What Is An Indicator? 52 Reimagining Indicators & Observations
  • 53. © Huntress Labs. All rights reserved What Is An Indicator? 53 Reimagining Indicators & Observations Indicator
  • 54. © Huntress Labs. All rights reserved What Is An Indicator? 54 Reimagining Indicators & Observations Indicator Technical Observable Artifact Of Compromise Behavioral Artifact
  • 55. © Huntress Labs. All rights reserved What Is An Indicator? 55 Reimagining Indicators & Observations Indicator Technical Observable Artifact Of Compromise Behavioral Artifact Communication Object Forensic Item Intelligence Observable
  • 56. © Huntress Labs. All rights reserved One Indicator, Many Meanings 56 Reimagining Indicators & Observations
  • 57. © Huntress Labs. All rights reserved One Indicator, Many Meanings 57 Reimagining Indicators & Observations Indicators Have MANY Applications
  • 58. © Huntress Labs. All rights reserved One Indicator, Many Meanings 58 Reimagining Indicators & Observations Indicators Have MANY Applications Multiple Applications Lead To Multiple Views
  • 59. © Huntress Labs. All rights reserved One Indicator, Many Meanings 59 Reimagining Indicators & Observations Indicators Have MANY Applications Multiple Applications Lead To Multiple Views Application-Centric Understanding Is Necessary!
  • 60. © Huntress Labs. All rights reserved Indicators Pre- & Post-Action 60 Reimagining Indicators & Observations
  • 61. © Huntress Labs. All rights reserved Indicators Pre- & Post-Action 61 Reimagining Indicators & Observations Indicators As Technical Observations Of An Action Or Event
  • 62. © Huntress Labs. All rights reserved Indicators Pre- & Post-Action 62 Reimagining Indicators & Observations Origins Of The Technical Observation & Its Behavior Indicators As Technical Observations Of An Action Or Event Applications Of The Indicator & Its Use
  • 63. © Huntress Labs. All rights reserved Indicators Pre- & Post-Action 63 Reimagining Indicators & Observations POST Observation Indicators Diversify Into Their Applications & Use. PRE Observation Characteristics Enable Researchers To Identify Trends & Tendencies!
  • 64. © Huntress Labs. All rights reserved Creating Indicators, Revisited 64 Reimagining Indicators & Observations Data Observation Indicator
  • 65. © Huntress Labs. All rights reserved Creating Indicators, Revisited 65 Reimagining Indicators & Observations
  • 66. © Huntress Labs. All rights reserved Creating Indicators, Revisited 66 Reimagining Indicators & Observations Collection & Telemetry Provides Data
  • 67. © Huntress Labs. All rights reserved Creating Indicators, Revisited 67 Reimagining Indicators & Observations Collection & Telemetry Provides Data Data Is Refined Into Observations That Can Relate To Activity Of Interest
  • 68. © Huntress Labs. All rights reserved Creating Indicators, Revisited 68 Reimagining Indicators & Observations Collection & Telemetry Provides Data Data Is Refined Into Observations That Can Relate To Activity Of Interest Analysis Of Observations & Incidents Ties These To Activity - Producing Indicators
  • 69. © Huntress Labs. All rights reserved INDICATORS!!! 69 Reimagining Indicators & Observations Indicators Are A Sign That “Something” Has Taken Place - POST Observations Inform WHY Those Actions Occurred - PRE Observations Tell Us HOW. The Key To Cracking Indicators Is Breaking Them Apart To Reveal More About HOW.
  • 70. © Huntress Labs. All rights reserved Indicators & Components 70 Reimagining Indicators & Observations Malicious File Object File Hash ITW Name Compile Info Strings Functions & Actions Meta- Data
  • 71. © Huntress Labs. All rights reserved Indicators & Components 71 Reimagining Indicators & Observations Network Indicator Registrar TLD Or Naming Hosting Provider Name Servers SSL/TLS Info Hosting Geo
  • 72. © Huntress Labs. All rights reserved Indicators As Composite Objects 72 Reimagining Indicators & Observations
  • 73. © Huntress Labs. All rights reserved Indicators As Composite Objects 73 Reimagining Indicators & Observations Understanding Components Reveals Indicator Complexity!
  • 74. © Huntress Labs. All rights reserved Indicators As Composite Objects 74 Reimagining Indicators & Observations Understanding Components Reveals Indicator Complexity! Composite Nature Of Indicators Reveals Underlying Behaviors!
  • 75. © Huntress Labs. All rights reserved Indicators As Composite Objects 75 Reimagining Indicators & Observations Understanding Components Reveals Indicator Complexity! Composite Nature Of Indicators Reveals Underlying Behaviors! Enables Intelligence & Forward-Looking Action!
  • 76. © Huntress Labs. All rights reserved Indicators As Composite Objects 76 Reimagining Indicators & Observations
  • 78. © Huntress Labs. All rights reserved Where Are We Now? 78 Conclusions The Idea Of An “Indicator” Is A Surprisingly Complex Topic! Understanding WHAT They Are And HOW They Are Created Is Vital!
  • 79. © Huntress Labs. All rights reserved Clarity In Language & Vision 79 Conclusions
  • 80. © Huntress Labs. All rights reserved Clarity In Language & Vision 80 Conclusions Analysts Must Understand WHAT They’re Communicating & WHY
  • 81. © Huntress Labs. All rights reserved Clarity In Language & Vision 81 Conclusions Analysts Must Understand WHAT They’re Communicating & WHY Clarity In Communication SHOULD Lead To Clearer Results & Action
  • 82. © Huntress Labs. All rights reserved Clarity In Language & Vision 82 Conclusions Analysts Must Understand WHAT They’re Communicating & WHY Clarity In Communication SHOULD Lead To Clearer Results & Action Focus On What We KNOW & How To Communicate It To Others!
  • 83. © Huntress Labs. All rights reserved Toward A Recognized Ontology 83 Conclusions Discipline Around “Indicator,” “Observable,” “Data,” “IOC,” & Similar May Seem Pedantic. But With Controlled Statements & Understanding We Can Achieve Clearer, More Accurate Communication - And Follow-On Action!
  • 85. © Huntress Labs. All rights reserved Selected Resources 85 ● Analyzing Network Infrastructure As Composite Objects, Joe Slowik (https://www.domaintools.com/resources/blog/analyzing-network-infrastructure-as-composite-o bjects/) ● Open IOC: Back To The Basics, Will Gibb & Devon Kerr (https://www.mandiant.com/resources/blog/openioc-basics) ● Misunderstanding Indicators Of Compromise, Dave Dittrich & Katherine Carpenter (https://threatpost.com/misunderstanding-indicators-of-compromise/117560/) ● Formulating A Robust Pivoting Methodology, Joe Slowik (https://www.domaintools.com/wp-content/uploads/formulating-a-robust-pivoting-methodology.p df) ● Thrunting Grounds, Amitai Cohen (https://amitaico.substack.com/p/thrunting-grounds)
  • 86. © Huntress Labs. All rights reserved Slides! 86