DiscoverTalos TakesInside the attack chain: A new methodology for tracking compartmentalized threats
Inside the attack chain: A new methodology for tracking compartmentalized threats

Inside the attack chain: A new methodology for tracking compartmentalized threats

Update: 2025-05-22
Share

Description

Edmund Brumaghin joins Hazel to discuss how threat actors (including state sponsored attackers), are increasingly compartmentalizing their attacks i.e they're bringing in specialist skillsets from other groups to handle different aspects of the attack chain. Edmund discusses why this is happening, and the challenges this poses for defenders when it comes to attribution and reporting. He then discusses several solutions which seek to evolve traditional threat modelling, and help provide clarity to defenders.

More details can be found in this blog https://blog.talosintelligence.com/compartmentalized-threat-modeling/

If you're interested in our other blog on initial access groups, that can be found at https://blog.talosintelligence.com/redefining-initial-access-brokers/


Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Inside the attack chain: A new methodology for tracking compartmentalized threats

Inside the attack chain: A new methodology for tracking compartmentalized threats

Cisco Talos