When Threat Intelligence Outgrows the Spreadsheet: Moving to MISP
For a lot of teams, tracking indicators and notes in a spreadsheet, then feeding them manually into detection and prevention systems, works well for months or even years. As your program grows, you'll eventually want to do things that get harder in a flat table. None of that is impossible in a spreadsheet. It just gets slower and more fragile as volume and complexity grow. For most teams reaching that point, we recommend MISP as the next step. It gives you more structure, correlation, automation and sharing capability without requiring you to build an overly complex CTI environment from day one.
Stay in the loop
Get occasional updates from Cosive about cyber threat intelligence, fraud data sharing, and security operations.
What Cosive's ME Day Means to Me
Hi, I’m Prue Owen - Project Coordinator at Cosive. I know you don't hear from me much, but this one is important to me... Cosive ME Day Cosive gives all permanent staff 1 paid self-care day per month in addition to the usual 4 weeks of annual leave (that is: 12 additional days of leave per year to do things you find fulfilling). 3 small words that can mean so much.
Automating Anti Phishing Canary Credentials at Scale
In part 1 of our mini-series on canary credentials, we talked about what canary credentials are, why to use them, and how to use them well. It’s highly recommended to read part 1 first. So, let’s assume you’ve had some early success in manually using canary credentials in limited numbers - great! Now you’re looking to take your next steps. Arguably, the most powerful way to land a blow against phishing attackers and deter future attacks is using canary credentials at scale via automation. Here’s why.
How to Disrupt Phishing with Anti Phishing Canary Credentials
The traditional response to a phishing attack is to issue a take-down request and wait for the site to (possibly) be yanked offline. Take-downs, while necessary, just don’t hit phishers where it hurts - they still harvest plenty of stolen credentials while the site is up. In light of this, security teams are looking for new, more effective ways to fight back against phishers. Rather than be reactive, we want to disrupt phishers’ operations. A strategy rapidly gaining in popularity is the use of credential poisoning techniques, utilising what are referred to as ‘canary credentials’.
How to Communicate Remotely
Since our last post we've been inundated with requests asking for more details on how we work remotely at Cosive. For those who don't know us, we're a specialist IT security company that has been working completely remotely since 2015. And when I say we have been working remotely, I mean we don't have offices at all. We're fully online, with staff distributed across Australia and New Zealand.
Cosive’s Tips for Making a Happy and Productive Remote Team
As COVID-19 spreads globally, and employees are asked to work from home for the first time, we’ve seen many people looking for tips on managing a remote team. So, we decided to distill a few lessons we’ve learned at Cosive about how to make a cohesive remote team work well.
Why Rust is Worth the Struggle
The Rust programming language sent ripples through the programming community when it was first released in 2015, promising the blazing speed of lower-level programming languages without the accompanying sharp edges. Four and a half years on, many programmers still view Rust with a mix of intrigue and trepidation due to its appealing premise and notoriously difficult learning curve. We sat down with one of Cosive’s Senior Developers, Sid Odgers, to talk about why he believes more programmers should take the plunge and learn Rust.
Watching Them Watching You: Opsec for Security Investigators
This post is about how to protect your identity and cover your tracks when conducting security investigations. The recommendations here are part of on operational security (opsec) approach, conducting investigations in a way that denies your targets information about you and your activities and, ultimately, helps to keep you, and others, safe.
Don't Shoot The Messenger: Security.txt and Collaborating Effectively With Security Researchers
Security.txt is an effort to make life easier for security researchers and incident responders, and to increase the likelihood that the right people will get notified about security issues. The premise of the idea is that organisations add a ‘security.txt’ document under the ‘.well-known’ directory of websites so that people concerned about your organisation’s security know who to contact. Generally, this will be coupled with a ‘security@’ email address which goes directly to the person or team responsible for security. Here are reasons why adding a security.txt file to your website is probably a good idea.





