Reference no: EM133459486
Case Study: You are a part of SOC (Security Operations Centre) team, and your role is of a threat researcher. Through the threat intelligence sources, your team has come to know that your organization faces a probable threat from the Conti ransomware group. The CISO has asked you to prepare a threat report, specific to this ransomware group.
Questions: You are expected to research and report the following for this group:
1. What is the origin of this group?
Hint: Try to determine the first known attack and examine if you can trace that attack to its originating country or known associates.
2. What is the motivation of the group?
Hint: Try to analyse the known attacks by the group to understand what did the group attain from that attack- was it financial profit or was it to gain sensitive information or is it nation-state sponsored.
3. Were there any past successful attacks? If yes, name at-least three.
4. Submit the MITRE ATT&CK navigator. (Excel format is preferred)
Hint: Recall from the learning videos of the first week of the moduleUnderstanding Cyber Attacks
5. What are the IOC's (Indicators Of Compromise) for this group? Mention atleast 4.
6. What are your recommendations to the security team?
7. Provide references of the data. It is mandatory to provide the references to the source of your data.