News

May 22, 2023

OCA Breakfast at RSA 2023

In conjunction with RSAC, the Open Cybersecurity Alliance (OCA) hosted a breakfast event on Wednesday, 26 April. With over 200 people that signed up, the meeting was a mix of short presentations and lively discussions. Here are a few impressions from the event. If you are interested in learning more about OCA, or would like to get involved, you can find links […]
May 10, 2023

Machine Readable Representation of Adversary Behavior (video)

The OCA Indicators of Behavior (IOB) Project works to represent patterns of behavior associated with malicious cyber activity. Check out the overview video.
April 28, 2023

Detecting Malicious Remote Authentication Requests Using Graph Learning

This article introduces a new Kestrel analytics which detects lateral movement using graph learning.
February 27, 2023

A Kestrel Analytics to Detect Lateral Movement

Given the dramatic rise in number of cybersecurity attacks in the recent years, threat hunting is very important to secure businesses and enterprises. This post discusses a new approach to detect lateral movement and shows how this approach can be applied on the data read using STIX-Shifter in the Kestrel threat hunting platform.
February 15, 2023

Introducing the Indicators of Behavior (IOB) Sub-Project

Recently, the Open Cybersecurity Alliance announced that our Indicator of Behavior (IOB) Working Group has transitioned to an official sub-project within the Alliance. I wanted to share a little bit about this effort and explain why we want you to join us. The main goal of the IOB effort is to create a standard way to represent cyber adversary behaviors […]
January 18, 2023

Open Cybersecurity Alliance Adds Indicators of Behavior (IoB) Sub-Project

Security Practitioners to Create Standardized Approach for Representing Cyber Threat Actor Behaviors in a Sharable Format
October 31, 2022

Fun with securitydatasets.com and the Kestrel PowerShell Deobfuscator

Ready-made datasets from the Open Threat Research Forge meet Kestrel, featuring PowerShell Empire!
July 27, 2022

Try Kestrel in a Cloud Sandbox

Introducing the Kestrel cloud sandbox. Now learning and trying Kestrel is just a click away—no installation needed, no server needed.