Alright, so now we are able to identify a specific actor's general profile and have made ourselves hardened targets. Now, how do we make correlations across various boxes, networks, and organizations? One helpful model for this is the Diamond Model.
- For each corner of the diamond, write a few sentences on what they are.
- Write a few sentences on how correlation between breaches can be done using the Killchain and the Diamond Model.
- What is a threat group/activity group? (You may need Google)
- Write a few sentences on how you can use these pieces of information to build an identity for an activity group.
- Write about what the benefits are of creating a named threat/activity group