In our World View and a majority of Use Cases, one needs to fully model all aspects of the Cyber-BattleSpace:
Adversaries
Adversary TTP*s (Black Hat)
Intermediaries
Intermediary TTPs (Grey Hat)
Targets
Target TTPs (White Hat)
* TTPs include assets and infrastructure in this model.
Since we don't currently represent Targets and Intermediaries in the current CTI Model, then the proposed modeling of related "White/Grey Hat" TTP relations won't be as obvious
Patrick Maroney
From: Jerome Athias <>
Date: Wednesday, October 28, 2015 at 5:22 AM
To: Trey Darley <>
Cc: Patrick Maroney <>, Anthony Rutkowski <>, Mark Davidson <>,
"" <>
Subject: Re: [cti-stix] STIX 2.0 Architecture - Relationships, Sightings, and Targeting
I guess so (Blue/Red teams), only covered, I would say by the 'exercise' flag but not in the vocabularies
On Wednesday, 28 October 2015, Trey Darley <> wrote:
On 26.10.2015 17:16:02, Patrick Maroney wrote:
>
> ...including the missing concepts of White Hat TTPs...
>
Hey, Pat -
When you say, 'White Hat TTPs', do you mean sharing intelligence
useful in identifying legitimate pen-tester activity?
--
Cheers,
Trey
--
Trey Darley
Senior Security Engineer
4DAA 0A88 34BC 27C9 FD2B A97E D3C6 5C74 0FB7 E430
Soltra | An FS-ISAC & DTCC Company
www.soltra.com
--
"Every networking problem always takes longer to solve than it seems
like it should." --RFC 1925