Intel Node
From the field to the report and back again: How incident responders can use the Year in Review
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
The Year in Review distills Talos IR's observations into structured intelligence, but defenders should also be feeding this report back into their own preparation cycles. Here's how.
Every year, Cisco Talos publishes  Year in Review , a comprehensive look at the previous year’s threat landscape.  It’s drawn from an enormous volume of telemetry, such as endpoint detections, network traffic, email data, and boots-on-the-ground  Cisco Talos Incident   Response (Talos   IR)   engagements .
  As incident responders, we see threats mid-detonation in the wreckage of an Active Directory environment, or in the lateral movement artifacts left behind by an affiliate who got in using nothing more than a valid account. The Year in Review distills those raw observations into structured intelligence, but that intelligence loop works both ways.