TLP WHITE - FINAL Element 3: Threat Intelligence Threat Intelligence is a core phase of the overall TLPT process. Threat intelligence providers use threat intelligence and reconnaissance focused on the entity to create credible threat profiles which, mimicking real-life cyber threat actors, are critical to the scoping of testing activities. The threat profiles contain cyber threat scenarios which help the Red Team develop test plans, used during the Penetration Testing phase. Roles and Responsibilities The threat intelligence provider is typically responsible for: (i) producing threat intelligence deliverables, aligned to the scope of test, and in accordance with direction provided by the entity; (ii) justifying the relevance of the threat intelligence deliverables; (iii) disseminating threat intelligence deliverables to the White Team; and (iv) providing support, as required, to the Red Team. This includes helping to develop the cyber threat scenarios, as well as fulfilling any new intelligence needs that occur as the Penetration Testing phase progresses. The entity should provide: (i) direction to the threat intelligence provider regarding functions or systems in scope; (ii) additional background information to assist the threat intelligence provider in the timely and effective development of the threat profiles; and (iii) threat intelligence deliverables to the penetration testing provider, appropriate stakeholders, and authorities as needed. Threat Intelligence Competencies Effective threat intelligence providers typically demonstrate the following minimum capabilities:  Ability to profile cyber threat actors relevant to the entity, sector and geographical region;  Ability to produce cyber threat scenarios, replicating the methodology of chosen threat actors;  Utilization of different methodologies and multiple sources and types of intelligence, such as Open Source Intelligence (OSINT) and industry related Indicators of Compromise (IoCs), to fully develop an accurate and up-to-date picture of an entity’s vulnerable attack surfaces, focusing on people, processes and technology; and  Multi-language intelligence collection ability. Threat Intelligence Deliverables For each TLPT engagement the threat intelligence provider should produce deliverables that contain the following types of information:  Threat Intelligence Report (TIR) – The TIR should contain profiles of cyber threat actors who represent a credible threat to the entity. Where no specific reporting relating to the entity is available, actors may be selected based on previous known activity within relevant sectors or regions. Each threat actor profile should contain a cyber threat scenario that best highlights the methodology and tools utilized by the threat actor. Cyber threat scenarios should be detailed enough to provide penetration testing providers with all relevant approaches and information required to formulate effective test plans.  Targeting Report (TR) – The TR should provide a profile of the entity that highlights vulnerable or exposed attack surfaces relevant to people, processes and technology, in accordance with the scope. The report should seek to provide the penetration testing provider with potential threat vectors into the target entity. TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 5

Select target paragraph3