{"id":71,"date":"2019-10-14T13:41:34","date_gmt":"2019-10-14T05:41:34","guid":{"rendered":"https:\/\/blog.billows.com.tw\/2019\/10\/14\/open-threat-exchangeotx%e7%9a%84%e6%96%b0%e5%8a%9f%e8%83%bd\/"},"modified":"2020-05-13T09:33:45","modified_gmt":"2020-05-13T01:33:45","slug":"open-threat-exchangeotx%e7%9a%84%e6%96%b0%e5%8a%9f%e8%83%bd","status":"publish","type":"post","link":"https:\/\/blog.billows.com.tw\/?p=71","title":{"rendered":"Open Threat Exchange(OTX)\u7684\u65b0\u529f\u80fd"},"content":{"rendered":"<p>AT &amp; T Cyber\u200b\u200bsecurity<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u4e00\u76f4\u5728\u52aa\u529b\u6301\u7e8c\u958b\u767c<\/span>Open Threat Exchange<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff08<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff09\u5e73\u53f0\u3002<\/span> <span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u4ee5\u4e0b\u662f\u6700\u65b0\u6d88\u606f\u548c\u4e0b\u4e00\u6b65\u7684\u6d88\u606f<\/span>\u2026<\/p>\n<p><strong>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u65b0\u529f\u80fd<\/span><\/strong><\/p>\n<p>AT&amp;T Alien Labs<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u548c<\/span>Open Threat Exchange (OTX)<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u958b\u767c\u5718\u968a\u4e00\u76f4\u5728\u52aa\u529b\u5de5\u4f5c\uff0c\u6301\u7e8c\u5c0d<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u5e73\u53f0\u9032\u884c\u7684\u958b\u767c\u3002\u4f60\u5011\u53ef\u80fd\u5df2\u7d93\u6ce8\u610f\u5230\uff0c\u53bb\u5e74\u6211\u5011\u589e\u52a0\u4e86\u4e00\u4e9b\u4ee4\u4eba\u8208\u596e\u7684\u65b0\u529f\u80fd\uff0c\u4f7f<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u793e\u5340\u5c0d\u4e0d\u65b7\u767c\u5c55\u7684\u5a01\u8105\u548c\u65b0\u51fa\u73fe\u7684\u5a01\u8105\u6709\u66f4\u591a\u7684\u4e86\u89e3\u3002<\/span><\/p>\n<p><strong><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u60e1\u610f\u8edf\u9ad4\u5206\u6790\u4f7f\u6240\u6709\u4eba\u53d7\u76ca<\/span><\/strong><\/p>\n<p>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u4e2d\u6700\u5927\uff08\u4e5f\u662f\u6700\u65b0\uff09\u7684\u65b0\u529f\u80fd\u662f\u80fd\u5920\u63d0\u4ea4\u5230\u6211\u5011\u7684\u5f8c\u7aef<\/span>AT&amp;T Alien Labs<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7cfb\u7d71\u4e2d\u9032\u884c\u5206\u6790\u6a23\u672c\u7684\u529f\u80fd\u3002\uff08<\/span>Alien Labs<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u662f<\/span>AT&amp;T<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7db2\u8def\u5b89\u5168\u7684\u5a01\u8105\u60c5\u5831\u90e8\u9580\u3002\uff09\u60a8\u73fe\u5728\u53ef\u4ee5\u4e0a\u50b3\u6587\u4ef6\u548c<\/span>URL<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u9032\u884c\u5206\u6790\uff0c\u4e26\u5728\u5e7e\u5206\u9418\u4e4b\u5167\u5f97\u5230\u7d50\u679c\uff0c\u53ef\u4ee5\u901a\u904e<\/span>OTX Portal<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff08\u5982\u4e0b\u6240\u793a\uff09\u6216\u4ee5\u7a0b\u5f0f\u901a\u904e<\/span>API<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u9032\u884c\u63d0\u4ea4\u3002<\/span><\/p>\n<p><a href=\"https:\/\/billows888.pixnet.net\/album\/photo\/168747624\"><img decoding=\"async\" title=\"a.png\" src=\"https:\/\/pic.pimg.tw\/billows888\/1571032549-687483710_n.png?v=1571032550\" alt=\"a.png\" \/><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"\" src=\"file:\/\/\/C:\/Users\/desiree\/AppData\/Local\/Temp\/msohtmlclip1\/01\/clip_image002.jpg\" alt=\"\" width=\"554\" height=\"280\" \/><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u5728\u201c<\/span> Submit Sample<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u63d0\u4ea4\u6a23\u672c\u201d\u9801\u9762\u4e0a\uff0c\u60a8\u5c07\u80fd\u5920\u770b\u5230\u6240\u6709\u63d0\u4ea4\u7684\u5167\u5bb9\u4ee5\u53ca\u6307\u5411\u7d50\u679c\u7684\u93c8\u63a5\u3002\u800c\u4e14\uff0c\u5982\u679c\u60a8\u64d4\u5fc3\u5305\u542b\u654f\u611f\u4fe1\u606f\u7684\u793a\u4f8b\uff0c\u60a8\u53ef\u4f7f\u7528<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u4ea4\u901a\u71c8\u865f\u5354\u8b70\uff08<\/span>TLP<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff09\u5c07\u63d0\u4ea4\u7684\u6587\u4ef6\u548c<\/span>URL<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u8a2d\u70ba\u79c1\u6709\u3002<\/span><\/p>\n<p><strong>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u589e\u5f37\u529f\u80fd<\/span><\/strong><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u60a8\u53ef\u4ee5\u901a\u904e\u55ae\u64ca\u6309\u9215\u8f15\u9b06\u5730\u5c07<\/span>result indicator <span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u65b0\u589e\u5230\u65b0\u7684<\/span>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u4e2d\u3002\u5be6\u969b\u4e0a\uff0c\u60a8\u4e5f\u53ef\u4ee5\u5f9e\u4efb\u4f55<\/span>indicator<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u8a73\u7d30\u4fe1\u606f\u9801\u9762\u4f7f\u7528\u65b0\u7684\u201c<\/span>Add to Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u201d\u6309\u9215\u3002<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"\" src=\"file:\/\/\/C:\/Users\/desiree\/AppData\/Local\/Temp\/msohtmlclip1\/01\/clip_image004.jpg\" alt=\"\" width=\"554\" height=\"145\" \/><a href=\"https:\/\/billows888.pixnet.net\/album\/photo\/168747711\"><img decoding=\"async\" title=\"b.png\" src=\"https:\/\/pic.pimg.tw\/billows888\/1571032596-1837203846_n.png\" alt=\"b.png\" \/><\/a><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u8ac7\u5230<\/span>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff0c\u6211\u5011\u5df2\u7d93\u5c07<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u53ef\u4ee5\u81ea\u52d5\u63d0\u53d6<\/span>IOC<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u6587\u4ef6\u985e\u578b\u6dfb\u52a0\u5230\u5217\u8868\u4e2d\uff0c\u73fe\u5728\u4e5f\u5305\u62ec<\/span>PCAP<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u548c\u96fb\u5b50\u90f5\u4ef6\u3002<\/span><\/p>\n<p><a href=\"https:\/\/billows888.pixnet.net\/album\/photo\/168748086\"><img decoding=\"async\" title=\"newpulse.png\" src=\"https:\/\/pic.pimg.tw\/billows888\/1571033327-3301469347_n.png\" alt=\"newpulse.png\" \/><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"\" src=\"file:\/\/\/C:\/Users\/desiree\/AppData\/Local\/Temp\/msohtmlclip1\/01\/clip_image006.jpg\" alt=\"\" width=\"554\" height=\"271\" \/><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u60a8\u9084\u53ef\u4ee5\u4e00\u6b21\u7de8\u8f2f\u591a\u500b<\/span>indicator<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff0c\u5f9e\u800c\u4f7f<\/span>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u5efa\u7acb\u66f4\u52a0\u5bb9\u6613\u3002<\/span><\/p>\n<p><a href=\"https:\/\/billows888.pixnet.net\/album\/photo\/168747900\"><img decoding=\"async\" title=\"aa.png\" src=\"https:\/\/pic.pimg.tw\/billows888\/1571032866-3232110730_n.png?v=1571032867\" alt=\"aa.png\" \/><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"\" src=\"file:\/\/\/C:\/Users\/desiree\/AppData\/Local\/Temp\/msohtmlclip1\/01\/clip_image008.jpg\" alt=\"\" width=\"553\" height=\"298\" \/><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u6211\u5011\u9084\u901a\u904e\u91dd\u5c0d\u60e1\u610f\u8edf\u9ad4\u5bb6\u65cf\u548c\u5a01\u8105\u53c3\u8207\u8005\u7684\u81ea\u52d5\u5efa\u8b70\uff0c\u4f7f<\/span>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u5728\u6dfb\u52a0\u66f4\u591a\u8a73\u7d30\u4fe1\u606f\u8b8a\u5f97\u66f4\u5bb9\u6613\u3002\u53ea\u9700\u5728<\/span>associated fields(<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u76f8\u95dc\u9818\u57df<\/span>)<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u9032\u884c\u8f38\u5165\uff0c<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u5c07\u63d0\u4f9b\u5efa\u8b70\u5217\u8868\u3002\u6b64\u5916\uff0c<\/span>OTX<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u4e5f\u6703\u5f9e\u8cc7\u6e90\uff08\u4f8b\u5982<\/span>Blog<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u6216\u5a01\u8105\u5831\u544a\uff09\u4e2d\u8b58\u5225<\/span>MITER ATT&amp; CK ID<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff0c\u4e26\u5c07\u6b64\u4fe1\u606f\u81ea\u52d5\u6dfb\u52a0\u5230<\/span>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u4e2d\u3002<\/span><\/p>\n<p><a href=\"https:\/\/billows888.pixnet.net\/album\/photo\/168747957\"><img decoding=\"async\" title=\"bb.png\" src=\"https:\/\/pic.pimg.tw\/billows888\/1571032898-444209756_n.png\" alt=\"bb.png\" \/><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"\" src=\"file:\/\/\/C:\/Users\/desiree\/AppData\/Local\/Temp\/msohtmlclip1\/01\/clip_image010.jpg\" alt=\"\" width=\"554\" height=\"575\" \/><\/p>\n<p><strong>CVSS v3<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u56b4\u91cd\u6027\u5206\u6578<\/span><\/strong><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u6211\u5011\u9084\u65b0\u589e\u4e86\u5c0d<\/span>CVSS v3<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u652f\u63f4\uff0c\u56e0\u6b64\u60a8\u73fe\u5728\u53ef\u4ee5\u5f15\u7528\u548c\u53c3\u8003<\/span>CVSS v2<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u548c<\/span>v3<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u56b4\u91cd\u6027\u4fe1\u606f\u3002<\/span><\/p>\n<p><a href=\"https:\/\/billows888.pixnet.net\/album\/photo\/168747960\"><img decoding=\"async\" title=\"cc.png\" src=\"https:\/\/pic.pimg.tw\/billows888\/1571032929-2851732374_n.png\" alt=\"cc.png\" \/><\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"\" src=\"file:\/\/\/C:\/Users\/desiree\/AppData\/Local\/Temp\/msohtmlclip1\/01\/clip_image012.jpg\" alt=\"\" width=\"554\" height=\"244\" \/><\/p>\n<p>And more<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff01<\/span><\/p>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u6211\u5011\u9084\u5c0d<\/span>Passive DNS data<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u9032\u884c\u4e86\u6539\u9032\uff0c\u4e26\u589e\u52a0\u4e86<\/span>Linux<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u6c99\u7bb1\u5c0d<\/span>ARM<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\uff0c<\/span>x86<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u548c<\/span>x64<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u652f\u63f4\u3002<\/span><\/p>\n<p><strong>What&#8217;s coming next&#8230;..<\/strong><\/p>\n<ul>\n<li><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u91cd\u65b0\u8a2d\u8a08\u4e26\u589e\u5f37\u4e86\u6587\u4ef6<\/span>indicator<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u7684\u8a73\u7d30\u4fe1\u606f\u9801\u9762<\/span><\/li>\n<li><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u6539\u9032\u7684<\/span>IoC<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u641c\u7d22\u529f\u80fd<\/span><\/li>\n<li><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u80fd\u5920\u5f9e<\/span>Pulse<span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u96fb\u5b50\u90f5\u4ef6\u4e2d\u555f\u52d5\u7aef\u9ede\u6383\u63cf<\/span><\/li>\n<\/ul>\n<p><span style=\"font-family: \u65b0\u7d30\u660e\u9ad4,serif;\">\u8acb\u6301\u7e8c\u95dc\u6ce8\uff0c\u56e0\u70ba\u6211\u5011\u9084\u6709\u66f4\u591a\u5f88\u68d2\u7684\u6771\u897f\u8981\u4f86\uff01<\/span><\/p>\n<p>Source: http:\/\/spr.ly\/60151EaFN<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AT &amp; T Cyber\u200b\u200bsecurity\u4e00\u76f4\u5728\u52aa\u529b\u6301\u7e8c\u958b\u767cOpen Threat Exchange <a class=\"read-more\" href=\"https:\/\/blog.billows.com.tw\/?p=71\">READ MORE<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[26,32],"class_list":["post-71","post","type-post","status-publish","format-standard","hentry","category-6","tag-alienlabs","tag-otx"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/71","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=71"}],"version-history":[{"count":2,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/71\/revisions"}],"predecessor-version":[{"id":126,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/71\/revisions\/126"}],"wp:attachment":[{"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=71"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=71"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.billows.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=71"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}