[Blackhat Europe tool] thethe: Simple, shareable, team-focused and expandable threat hunting experience
TheTHE is an environment intended to help analysts and hunters over the early stages of their work in an easier, unified and quicker way. One of the major drawbacks when dealing with hunting is the collection of information available on a high number of sources, both public and private. All this information is usually scattered and sometimes even volatile.
Perhaps at a certain point, there is no information on a particular IOC (Indicator of Compromise), but that situation may change within a few hours and become crucial for the investigation. Based on our experience in Threat Hunting, we have created a free and open-source framework to make the early stages of the investigation simpler from:
- Automation of tasks and searches.
- Rapid API processing of multiple tools.
- Unification of information in a single interface, so that screenshots, spreadsheets, text files, etc. are not scattered.
- Enrichment of collected data.
- Periodic monitoring of a given IOC in case new information or related movements appear.
TheTHE has a web interface where the analyst starts its work by entering IOCs that will be sent to a backend, where the system will automatically look up for such resource on the various configured platforms in order to obtain unified information from different sources and access related reports or data existing on them. Furthermore, any change in the resources to be analyzed will be monitored.
Everything is executed on a local system, without needing to share information with third parties until such information is not organized, linked, complete and synthesized. This allows that in case the information must be analyzed on any other platform later (such as a Threat Intelligence Platform), it can be done in the most enriching possible manner.
Copyright (C) 2019
- David Garcia
- Alvaro Nuñez-Romero
- Pablo San Emeterio
- Antonio Reina
- Carlos Avila