← Back to all guides
Cybersecurity·Feb 26, 2023

Using Threat Intelligence Tools to Investigate Cyber Attacks

TryHackMe Room: https://tryhackme.com/room/threatinteltools Threat intelligence tools allow us cyber security professionals to analyze security incidents. There are specific tools for investigating each kind of threat. Ranging from malicious URLs, malware, emails and IP addresses, analysts can utilize platforms to cond

TryHackMe Room: https://tryhackme.com/room/threatinteltools

Threat intelligence tools allow us cyber security professionals to analyze security incidents. There are specific tools for investigating each kind of threat. Ranging from malicious URLs, malware, emails and IP addresses, analysts can utilize platforms to conduct threat assessments.

Categories of threat intelligence

Threat intelligence often involves analyzing a large amount of data collected through SIEM software such as Splunk. To make sense of the events, we need the help of various threat intelligence tools. For example, a SOC analyst identified an IP address from Splunk’s log performing suspicious activities. The next step is often to perform a reputation check and see if the IP address has been previously reported. Depending on the result and standard operating procedure, a SOC analyst can take further action to address the threat.

Threat intelligence can be classified into several categories. Employees of different ranks use threat intelligence tools for different purposes. The following table provides an overview of threat intelligence categories mentioned in the TryHackMe room.

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

Threat Intelligence Tools

There are various threat intelligence tools available for analyzing security-related events. They are summarized in the table below.

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

1. UrlScan.io

1.1. Using UrlScan.io to identify Cisco Umbrella Rank

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

1.2. Using UrlScan.io to identify the number of domains associated with a website

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

1.3. Using UrlScan.io to find out the main domain registrar

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

1.4. Using UrlScan.io to identify the main IP associated with the website

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

2. Abuse.ch

2.1. Using ThreatFox to identify malware associated with an IP address

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

2.2. Locate malware information associated with a JA3 fingerprint on SSL Blacklist

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

2.3. Identifying ASN number(s) that host the most malware on URLHaus

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

2.4. Find out the country associated with a botnet IP address using FeodoTracker

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

3. PhishTool

3.1. Finding the impersonation target of an attacker

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

3.2. Finding the sender’s email address

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

3.3. Finding the recipient’s email address

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

3.4. Finding the originating IP address

On the webpage of urlscan.io, search for the domain name of the sender’s email address. The IP address of the domain name is displayed below.

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

3.5. Finding the number of hops which an email goes through to reach a recipient

4 hops are found within the source file of the email received. The source file can be viewed within Mozilla Thunderbird -> More -> View Source.

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

4. Cisco Talos Intelligence

4.1. Locate the listed domain of the IP address of the malicious email sender

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

4.2. Locate the customer’s name of the IP address via WHOIS

Go to the additional information section and check for the WHOIS information.

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks
Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

5. Scenario 1 (email2.eml)

5.1. Finding the recipient’s email address using PhishTool

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

5.2. Finding the alias of a malicious file from its hash value using PhishTool and Cisco Talos Intelligence

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks
Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

6. Scenario 2 (email3.eml)

6.1. Finding the name of the Email3.eml attachment using PhishTool

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

6.2. Finding the malware family associated with the attachment using Cisco Talos Intelligence

Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks
Illustration for Using Threat Intelligence Tools to Investigate Cyber Attacks

Comments

0 comments

Ask a question or share a practical note. Comments appear immediately after passing the spam check.

Loading comments…

Be constructive and specific.