APT Rosetta Stone or A Plea To The Industry For Shared Names
Last night one of my CTI sharing groups was discussing a report from FireEye regarding APT29 and domain fronting ( https://www.fireeye.com/blog/threat-research/2017/03/apt29_domain_frontin.html ) when we all realized we had no clue who APT29 is in our own internal systems. One member finally shared this mess: https://www.google.com/url?sa=t&source=web&rct=j&url=https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/edit&ved=0ahUKEwjNhd-novjSAhVBC2MKHYglAgoQFghIMAQ&usg=AFQjCNFe0KMzzgH09bdHImCB5VxrXo2gIA&sig2=1CI3ffYHiBNLliisz6EbAw Nobody can agree on names. Even to the untrained eye it's obvious that there's a communication issue present here. The most amazing thing is how simple it would be to fix all of this, but none of these vendors have because #branding #sorrynotsorry #aptlolwut . The excuse "but we'd have to rename everything" is silly, because if you want to present the image of being a quali...