As both a parent and a bit of a nerd, I have a lot of corny jokes in my arsenal that cover a wide range of topics including animals, food, science fiction and the like. One of my favorite jokes comes from my data science background: “I never metadata I didn’t like.” This joke has it all: wordplay, the spirit of a joke your uncle might tell and even a tangential “Star Trek” tie-in. It also relates to threat intelligence.

The Evolution of Threat Intelligence

When the IBM X-Force Exchange (XFE) launched over two years ago, the platform capabilities solidly supported collaboration and security investigation workflow. Since then, agile development has built up an even more robust set of features to make both collaboration and investigations even easier.

Orchestrate Your Security Defenses to Optimize the Impact of Threat Intelligence

In the past few months, on-platform notifications have gotten more robust. A user who is not logged in to the X-Force Exchange will be notified of updates to major capabilities in the upper right corner by the bell icon. A logged-in user will see a number of additional notifications available, ranging from feature updates to content and collaboration updates.

In addition to new capabilities, new content notices, such as groups to which you’ve been added or collections that have been shared with you, will be highlighted on the notifications page. The platform also displays recently published data from the IBM X-Force Research team.

Customizing the X-Force Exchange Experience

These public X-Force collections and advisories are incredibly helpful for security analysts because they provide ready-made, validated research and indicators of compromise (IoCs) for active campaigns such as the recent WannaCry and Petya malware outbreaks. Once viewing the collection, you can follow it to get on-platform notifications when new content is added or the notes are updated. You can even subscribe to off-platform notifications by adjusting the user settings on XFE if you’d like to be emailed when followed collections are updated.

By customizing the X-Force Exchange experience, you can ensure that you are receiving the content you need to facilitate investigations and remediation actions. Watch our on-demand webinar on maximizing the impact of threat intelligence to learn more about the platform and its capabilities.

More from Threat Intelligence

An IBM Hacker Breaks Down High-Profile Attacks

On September 19, 2022, an 18-year-old cyberattacker known as "teapotuberhacker" (aka TeaPot) allegedly breached the Slack messages of game developer Rockstar Games. Using this access, they pilfered over 90 videos of the upcoming Grand Theft Auto VI game. They then posted those videos on the fan website GTAForums.com. Gamers got an unsanctioned sneak peek of game footage, characters, plot points and other critical details. It was a game developer's worst nightmare. In addition, the malicious actor claimed responsibility for a…

Self-Checkout This Discord C2

This post was made possible through the contributions of James Kainth, Joseph Lozowski, and Philip Pedersen. In November 2022, during an incident investigation involving a self-checkout point-of-sale (POS) system in Europe, IBM Security X-Force identified a novel technique employed by an attacker to introduce a command and control (C2) channel built upon Discord channel messages. Discord is a chat, voice, and video service enabling users to join and create communities associated with their interests. While Discord and its related software…

Charles Henderson’s Cybersecurity Awareness Month Content Roundup

In some parts of the world during October, we have Halloween, which conjures the specter of imagined monsters lurking in the dark. Simultaneously, October is Cybersecurity Awareness Month, which evokes the specter of threats lurking behind our screens. Bombarded with horror stories about data breaches, ransomware, and malware, everyone’s suddenly in the latest cybersecurity trends and data, and the intricacies of their organization’s incident response plan. What does all this fear and uncertainty stem from? It’s the unknowns. Who might…

Old Habits Die Hard: New Report Finds Businesses Still Introducing Security Risk into Cloud Environments

While cloud computing and its many forms (private, public, hybrid cloud or multi-cloud environments) have become ubiquitous with innovation and growth over the past decade, cybercriminals have closely watched the migration and introduced innovations of their own to exploit the platforms. Most of these exploits are based on poor configurations and human error. New IBM Security X-Force data reveals that many cloud-adopting businesses are falling behind on basic security best practices, introducing more risk to their organizations. Shedding light on…