Joe Slowik · @jfslowik
1378 followers · 101 posts · Server infosec.exchange

The threat environment is interesting as, aside from ransomware shit, the threats are latent, dormant, or in development. The evolution of , identification of / , continued activity, identification of test labs for cyber physical capabilities... All indicate an environment under rapid development, but with fewer actual public examples than fingers on your hand. Circumstances make risk assessment (and cost forecasting) exceptionally difficult for asset owners... But the adversaries are out there, and as shown in , they are learning. Claiming adversaries will never figure out a cyber physical attack and that the future threat landscape is over hyped seems unhelpful, or motivated by feelings less than altruistic.

#ot #ics #berserkbear #incontroller #pipedream #xenotime #prc #industroyer2

Last updated 2 years ago

Joe Slowik · @jfslowik
1202 followers · 57 posts · Server infosec.exchange

Another bit of research I'm proud of, that I'm not sure if it ever gained any traction because of pandemic, was my 2021 research into . I think taking a "long view" of persistent threat actors is extremely beneficial in seeing now just how they evolve over time, but how past campaigns are reflected in current operations.

You can find the paper here:
vblocalhost.com/uploads/VB2021

#virusbulletin #cti #berserkbear #dragonfly #crouchingyeti

Last updated 2 years ago