Initial access brokers are cybercriminals who steal sensitive information and sell it in dark web marketplaces to hackers who will use it to gain unauthorized network access. From there, the hackers can do just about anything. But what drives initial access brokers and their activities? Infostealer malware. A good piece of malware can fill a log with thousands of harvested credentials, active session tokens, and more. The logs are then distributed across Telegram channels and a variety of dark web sites.
Unfortunately, scanning the logs has a tendency to trigger a staggering number of external alerts analysts then need to analyze. Manual analysis is impossible for all practical purposes. Security teams are left to deal with severe alert fatigue and burnout, leading to high-risk exposures that slip through the cracks. SOAR providers capable of automating intake, parsing, and remediation are the solution.
Industrialized Logs Dominate the Dark Web
Manual intake and analysis were no big deal back in the day when infostealer logs were nothing more than niche anomalies. But those days are gone. Modern infostealer logs have been industrialized. They are highly structured, automated packages consisting of stolen data. They are so big that a threat actor could easily publish millions of unique lines of text in a single file. It is easy to see why analysts are overwhelmed.
The problem is further exacerbated by a simple truth: finding a compromised password or username is only half the battle. Analysts must verify the associated account is active, evaluate whether the user has access to critical systems, and determine if the threat actor was able to secure active session cookies capable of bypassing multi-factor authentication (MFA). Trying to do all of this manually virtually guarantees paralysis.
Automating the Pipeline With SOAR
With the problem clearly outlined, let us talk about the solution: SOAR integration. SOAR providers offer platforms designed to shift the burden of data extraction and playbook execution from human analysts to automated systems. DarkOwl’s threat intelligence software offers continuous darknet data streams fed directly into an organization’s SOAR platform. That means the entire lifecycle of an infostealer alert is managed machine-to-machine.
When new infostealer logs or credential packages are indexed, DarkOwl’s Entity API instantly flags any incidents involving the customer’s corporate assets. Rather than sending raw data to a human analyst who is likely to consider it noise, the data goes to a SOAR layer where an automated playbook is executed. Several things are accomplished:
- Triage and Enrichment – The SOAR engine parses the data and immediately queries internal systems to verify questionable accounts and their privileges.
- Risk Scoring – The platform also checks automatically for active session tokens or plain-text credentials. Risk is scored accordingly. Scoring might indicate that one threat can be de-escalated while another is immediately escalated to a human analyst.
- Mitigation – In the case of critical exposures, the SOAR platform immediately executes a containment strategy without any need for human intervention. It can do things like automatically terminate active user sessions and trigger enterprise-wide password resets.
Automation is the key to taming the modern infostealer deluge. Automated systems work at lightning speed compared to human analysts.
Analysts Can Handle More Important Tasks
The automation capabilities brought to bear by SOAR providers are invaluable to security analysts. SOAR automation frees analysts from the hamster wheel of data analysis and password resets. They can invest themselves entirely in threat actor tracking and other aspects of dark web investigations. Any SOC trying to function without comprehensive SOAR integration is doing things the hard way. The security team probably knows that all too well.
