threat-intel
16 articles
Cybersecurity guides, tutorials, and insights about threat intel from Pwnsy.
The Bug Bounty Economy: Platforms, Triage & Payouts
How the bug bounty economy works: platforms, triage and payouts, VDPs versus paid programs, researcher incentives, and what bounties do and do not cover.
Coordinated Vulnerability Disclosure: From Finding to Fix
How responsible disclosure works: researcher to vendor to patch to publication, disclosure timelines, embargoes, and the full-disclosure debate.
CVSS Explained: How Vulnerability Scoring Actually Works
A plain, complete guide to CVSS: what base, temporal and environmental metrics measure, how the 0-to-10 score is built, v3.1 vs v4.0, and its limits.
Cybercrime-as-a-Service Explained: The Criminal Gig Economy
How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.
Dark Web Markets: How Criminal Marketplaces Work
A defensive guide to dark web markets: Tor hidden services, what gets traded, escrow and reputation, and why markets get seized and rebrand.
EPSS Explained: Scoring How Likely a Vuln Is to Be Exploited
EPSS predicts the chance a CVE is exploited within 30 days. How the model works, reading the score and percentile, and pairing it with CVSS and KEV.
Hacktivism Explained: When Hacking Is Driven by a Cause
Hacktivism is cause-driven hacking. Its common tactics, how it differs from criminal and state activity, and how to defend against it.
Initial Access Brokers: The Middlemen of Ransomware
Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.
Insider Threats: Malicious, Negligent & Compromised
How insider threats work: the three insider types, warning indicators, the role of access and privilege, and how to build a prevention program.
The KEV Catalog: CISA's List of Actively Exploited Bugs
What the CISA Known Exploited Vulnerabilities catalog is, how a CVE gets added, federal remediation deadlines, and why it means patch now.
The MITRE ATT&CK Framework: Tactics, Techniques & Coverage
What MITRE ATT&CK is: tactics vs techniques vs sub-techniques, the Enterprise, Mobile and ICS matrices, groups and software, and coverage mapping.
MITRE ATT&CK Tactics: The 14 Enterprise Tactics in Order
A one-line reference to the 14 MITRE ATT&CK Enterprise tactics in order: tactic name, tactic ID, the attacker's goal, and one example technique for each.
Nation-State Hacking: State-Sponsored Cyber Operations
How state-sponsored cyber operations work: their goals, typical targets, the main sponsoring regions, and why they operate differently from criminals.
The CVE System: How Vulnerabilities Get Their Names
How the CVE program works: CNAs, how an ID is reserved and assigned, the record lifecycle, and how CVE differs from the NVD that enriches it.
The Exploit Market: Bounties, Brokers & Zero-Day Trade
How the market for exploits works: bug bounties versus brokers versus the black market, what drives zero-day prices, and the ethics and policy debate.
What Is an APT? Advanced Persistent Threats Explained
What an Advanced Persistent Threat is: the three words decoded, how APTs differ from crime, the intrusion lifecycle, attribution, and naming schemes.