Transferring Knowledge to Customers Through Software Technology
ID: 7910619c-150c-582d-8c90-10ed11df6b4c
STIX ID: report--7910619c-150c-582d-8c90-10ed11df6b4c
Feed Name: Dragos Blog
Dragos introduces recurring content packs for the Dragos Platform that codify its threat intelligence and Threat Operations Center expertise into behavior-based analytics and guided investigation playbooks, supported by Query Focused Datasets. The post explains why TTP-centric detections scale better than IOCs and illustrates with an example of detecting DNS exfiltration of HMI screenshots (e.g., activity associated with DYMALLOY). These packs aim to provide continuous, on-the-job training and actionable workflows so industrial defenders can more effectively detect, investigate, and respond to adversary behaviors without direct engagement with Dragos.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
