This is a personal blog to register my academic journey
This project is maintained by villacisJimmy
layout: post title: “Cisco - Threat Intelligence 101 with Cisco Talos” date: 2025-08-18 categories: [blog] —
Threat Intelligence 101 with Cisco Talos
What did I learned from this course?
We need to understand the technology, its capacities, and weaknesses to protect the systems, the technological assets, and the information.
There is the knowledge management pyramid, which helps us to achieve this goal. It helps us to understand the path process from collected data till it is converted in wisdom throughout the information and knowledge phases.
We can classify threat intelligence into the next three types:
Threat actors are classified as:
Patters (TTPs) -> These are related to the ATT&CK Framework
The curse teaches us about the intelligence cycle. It has to be used as a guide, but not considered as something immutable.
The cycle has different stages:
The majority of the course ramarks the relevance of apply a serie of steps to transform data into useful information to take decisions.
As the course progressed, I learned with respect to the “See it, Sense it, Share it, and Use it” model, designed for rapid sharing and practical use of intelligence within the private sector, focusing on quick interpretation and dissemination of data.
Other models are mentioned as:
There is a measure to estimate the validity of the data, and it works with three levels:
A key point at the moment to write a report is to consider the audience’s needs, separate facts from points of view.
For that aim, the course presents the Traffic Light Protocol (TLP)
Threat Hunting concept: Based on the search for information and evidence to inform those who are the decision makers. Focused on investigation.
Threat Hunting Loop
Logs Security Tools are a crucial part of this area.
The information collection is the key, then analyze and identify.
V Diagram Model
The investigation process: Require the evidence analysis before stating any kind of hypothesis.
TTP’s identifications, tools, and who or whose were the attack objective, all that knowledge works to anticipate future attacks.
I learned concepts related to the Kill Chain, which is a model that is used to define the 7 steps of a cyberattack:
Diamond Model -> Victim -> subjected to -> Attacker Capabilities -> Deploys -> -> Threat actor -> Uses -> Malicious Infraestructure -> Connects to -> Victim ->
Example attack Attributes
I conclude that we don’t need to trust in the information that we hear or we read beacuse it could be put in with the intention that create confusion, we need to have a criteria to filter and corroborated the information, create suppositions. It is the opposite that we need to do, and for that reason, there are many frameworks and methods to help us with that.
25 August 2025 [J x 2]