# 🎯 Role Profile: CTI Team (Cyber Threat Intelligence)

![SOC CTI Avatar](../assets/SOC%20CTI%20Avatar.png)

## 📋 Role Overview
The **CTI Team (Cyber Threat Intelligence)** provides IOC enrichment and campaign intelligence, supports threat actor attribution analysis, tracks industry-wide threats and campaigns, and assists with threat intelligence correlation during active investigations.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- 🧠 **IOC Enrichment & Campaign Intel**: Provide IOC enrichment, threat actor profiling, and campaign intelligence to the incident response team.
- 🕵️ **Attribution Analysis**: Support attribution analysis (identifying threat actor groups, TTPs, ransomware variants, e.g. Ryuk/LockBit).
- 🌐 **Track Industry Threats**: Continuously track industry-wide threats, emerging vulnerabilities, and active campaigns targeting financial sector assets.
- 🔬 **Threat Intelligence Correlation**: Assist L2/L3 analysts with threat intelligence correlation during active incident investigations.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Enrich file hash `e3b0c44...` and C2 IP `185.123.45.6` against global threat intelligence platforms.
- Identify ransomware family, decryption viability, and known exfiltration methods.
- Provide intelligence briefing on potential data leak site publications by the threat group.

---

## 📝 Action Checklist
- [ ] Receive extracted IOCs from L2/L3.
- [ ] Perform threat intelligence enrichment and sandbox correlation.
- [ ] Determine threat actor attribution and campaign pattern.
- [ ] Assess exfiltration capabilities and dark web leak risks.
- [ ] Provide CTI briefing to Incident Commander and Executive Leadership.
