AI Security News Analyst
An AI Security News Analyst monitors, researches, and reports on emerging threats, vulnerabilities, incidents, and policy developm…
Skill Guide
The systematic process of identifying, collecting, and validating intelligence from publicly accessible data across the indexed web (surface), encrypted/unindexed networks (dark web), and peer-reviewed repositories (academic channels), followed by the prioritization of sources based on reliability, relevance, and timeliness.
Scenario
A mid-sized company hires you to audit its public-facing digital exposure before a security audit.
Scenario
A consumer electronics brand suspects its intellectual property (e.g., firmware, device schematics) is being sold on dark web marketplaces.
Scenario
As a threat intelligence lead, you must build a persistent collection system to monitor for credential dumps, phishing infrastructure, and emerging fraud tactics targeting the institution.
Use Maltego for complex relationship mapping across surface and dark web data. Shodan/Censys are for technical infrastructure intelligence (servers, IoT). Google Dorks are the foundational surface web collection tool. Tor/Tails are essential for secure, anonymous dark web access. SpiderFoot and TheHarvester automate initial collection and enumeration phases.
Apply the OSINT Lifecycle as your overarching project management framework. Use the Admiralty Code or SIRI to objectively triage and grade every piece of collected information before it enters analysis, preventing 'garbage in, garbage out'.
Academic channels provide peer-reviewed, high-reliability information on emerging threats, vulnerabilities, and methodologies. Paste sites and code repositories are critical for monitoring accidental data leaks and tracking threat actor toolkits.
Answer Strategy
Structure your answer using the OSINT Lifecycle. Emphasize defining a precise IR first. For collection, mention surface (LinkedIn, corporate website for org chart), dark (hacking forums for mentions of the company or stolen credentials), and academic (research on insider threat indicators). For triage, explicitly state you would use a grading system like the Admiralty Code, prioritizing sources with direct evidence over hearsay. Sample answer: 'First, I would draft a precise IR statement focusing on data exfiltration indicators. My collection plan would span: surface web for the employee's professional footprint and any public code commits; dark web forums and markets for corporate credential dumps; and academic sources for validated behavioral indicators. I would triage every source using the Admiralty Code, assigning a grade (e.g., A2 for 'usually reliable' source with 'usually truthful' data). A dark web post selling company data would be graded lower than a direct paste site leak until verified against internal assets. This ensures the analysis is built on the most reliable evidence.'
Answer Strategy
This tests your critical thinking and source evaluation process. Focus on methodology over intuition. Describe a specific scenario (e.g., a data breach claim) and the channels involved. Explain your step-by-step verification process. Sample answer: 'I encountered conflicting breach claims on a dark web forum and a surface paste site. I applied a multi-point verification framework: 1. Provenance: The forum poster was anonymous (low reliability), while the paste site data was a direct SQL dump. 2. Corroboration: I cross-referenced the dump's email addresses with haveibeenpwned.com's API. 3. Context: I checked if the purported victim company had any recent vulnerability disclosures in academic or security blogs. The paste site dump passed two checks, the forum post none. I trusted the paste site data but flagged both with their respective reliability grades for the final report.'
1 career found
Try a different search term.