Ondra Rojčík

188 posts

Ondra Rojčík banner
Ondra Rojčík

Ondra Rojčík

@orojcik

Threat Intelligence Analyst @RedHat | implication hunter | CTI | conteXt | tweets are my own

Czechia Katılım Şubat 2015
826 Takip Edilen686 Takipçiler
Ondra Rojčík
Ondra Rojčík@orojcik·
"Boosting Your InfoSec Skills with Intelligence Analysis Mindset" Blog post on how intelligence analysis can sharpen your InfoSec skills @orojcik/boosting-your-infosec-skills-with-intelligence-analysis-mindset-db484e94f02e" target="_blank" rel="nofollow noopener">medium.com/@orojcik/boost… #cti #infosec #intelligenceanalysis #skills
English
0
0
5
266
Ondra Rojčík
Ondra Rojčík@orojcik·
CTI is still an evolving field — not as much is codified as we would like. This provides vital opportunities to enrich and cross-pollinate it with new perspectives that you could be bringing. Integrating diverse perspectives and expertise can enhance CTI
English
0
1
2
397
Ondra Rojčík
Ondra Rojčík@orojcik·
In what specific ways can specialists with non-technical background enhance hashtag#CTI? ➡ Complex problem solving and pattern recognition, threat actor profiling, effective communication and interdisciplinary collaboration, global context, critical thinking and many more
English
1
0
2
146
Ondra Rojčík
Ondra Rojčík@orojcik·
The Cyber Threat Intelligence field will likely remain the domain of technically focused experts. However, it is growing and opportunities for specialists with non-technical or non-traditional backgrounds are increasing.
English
1
0
4
154
Ondra Rojčík
Ondra Rojčík@orojcik·
Why a Non-Technical Background Does Not Prevent You from Succeeding in Cyber Threat Intelligence @orojcik/why-a-non-technical-background-does-not-prevent-you-from-succeeding-in-cyber-threat-intelligence-09b41194ee8c" target="_blank" rel="nofollow noopener">medium.com/@orojcik/why-a… #cti #infosec #intelligenceanalysis ➡ More on that
English
1
1
8
933
Ondra Rojčík
Ondra Rojčík@orojcik·
@orojcik/the-shades-of-doubt-a-guide-to-estimative-language-and-confidence-levels-in-cti-reporting-1545233f7470" target="_blank" rel="nofollow noopener">medium.com/@orojcik/the-s…
ZXX
0
0
0
97
Ondra Rojčík
Ondra Rojčík@orojcik·
This blog post attempts to call out the bad practice of communicating uncertainties in cyber threat intelligence and offer possible solutions to the CTI teams at different stages of maturity t.ly/uncertainties
English
1
4
26
2.7K
Ondra Rojčík
Ondra Rojčík@orojcik·
My colleague Vladimir Janout and I presented this simplified version of the Red Hat process for the development of Priority Intelligence Requirements (PIRs) for the first time at the 2023 FIRST CTI Conference #FIRSTCTI23 in Berlin. Now it is out as a GitHub blog post.
English
0
0
2
126
Ondra Rojčík
Ondra Rojčík@orojcik·
📢 Updated (simplified) Red Hat process (v1.1) for development of Priority Intelligence Requirements, which includes a detailed, step-by-step guide and templates is now available at GitHub: github.com/redhat-infosec… #CTI #PIR
English
1
2
18
2.9K
Ondra Rojčík
Ondra Rojčík@orojcik·
I'm focusing on categories that are as close as possible to the "Impact" part of the kill chain - i.e. they are not just a means to achieve something else: malware, SQL injection, DNS Spoofing etc. that you would find in the earlier stages of the kill chain
English
0
0
0
125
Ondra Rojčík
Ondra Rojčík@orojcik·
I'm struggling to find a descriptive classification of attack types with a direct impact on business. What classification you know and use apart of: - MITRE ATT&CK - techniques under Impact + Exfiltration - STRIDE - threat categories - Attacks on C.I.A. - VERIS Framework
English
1
0
2
430
Ondra Rojčík
Ondra Rojčík@orojcik·
A common shortcoming of #CTI reports is the tendency to admire the problem instead of delivering explanations, implications, and mitigation strategies. From Descriptions to Impact: Unlocking the Power of Basic Cyber Threat Intelligence Questions link.medium.com/ibDWZCNpzAb
English
0
8
37
5.8K
Ondra Rojčík
Ondra Rojčík@orojcik·
I look forward to reconnecting with many of you in Berlin once again. The (then) CTI Symposium last year was just an incredible experience!
English
0
0
2
122
Ondra Rojčík
Ondra Rojčík@orojcik·
Our workshop proposal on the development of intelligence requirements has been accepted for the #FIRSTCTI23 Conference. We will delve deeper into the process presented last year. Join us to learn about our approach (tinyurl.com/RHPIRs) to intell requirements development
English
2
2
12
1.7K
Ondra Rojčík
Ondra Rojčík@orojcik·
I did a blog post on what does the #CTI community know about the intelligence requirements process. I'm curious to know if you are aware of other relevant resources on CTI Priority Intelligence Requirements #PIR not mentioned in this literature review medium.com/p/58d2df0d7c62
Katie Nickels@likethecoins

This is a very cool process for creating intelligence requirements from the Red Hat infosec team! I'm a big fan of the Venn Diagram approach to explaining threat modeling. (h/t @cocaman) ✍️ Process: github.com/redhat-infosec… 📊 Spreadsheet: #gid=0" target="_blank" rel="nofollow noopener">docs.google.com/spreadsheets/d…

English
0
0
4
377
Ondra Rojčík
Ondra Rojčík@orojcik·
I love ChatGPT, I'm playing around with it all the time, but it is good to be aware of its limits
English
0
0
1
171
Ondra Rojčík
Ondra Rojčík@orojcik·
"Organizational context is the secret ingredient in scalable, enterprise-grade automation content. At this stage, ChatGPT and similar AI tools can’t provide a recommendation specific to your organization’s environment or products." ansible.com/blog/ansible-w…
English
1
0
3
322