The Art of Threat-Informed Sharing: Real-life Use Cases from NSA
RSA Conference 2024 · Track Session
Overview
In an era of escalating nation-state cyber threats, the National Security Agency (NSA) has undergone a significant transformation in its approach to cybersecurity, moving from traditional intelligence reporting to agile, operational collaboration. This talk, presented by Morgan Adamski and Josh Zaritsky from the NSA's Cybersecurity Collaboration Center (CCC), details the evolution of the agency's information sharing mechanisms over the past four years. It highlights the critical shift towards providing timely, actionable intelligence directly to network defenders in the Defense Industrial Base (DIB) and critical infrastructure sectors.

Key moments
- 0:00 Speakers' introduction and talk overview
- 2:15 Elevating NSA's cybersecurity mission and forming the Directorate
- 3:45 Vision and creation of the Cybersecurity Collaboration Center
- 4:55 Agility, creativity, trust: keys to NSA's sharing success
- 6:00 Impressive growth of NSA's collaboration and information sharing
- 7:00 First use case: defending critical infrastructure from foreign actors
The Art of Threat-Informed Sharing: Real-life Use Cases from NSA
Speakers: Morgan Adamski, Director, Cybersecurity Collaboration Center, NSA; Josh Zaritsky, Chief Operations Officer, Cybersecurity Collaboration Center, NSA
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=ZQVHA_n3N_g
Overview
In an era of escalating nation-state cyber threats, the National Security Agency (NSA) has undergone a significant transformation in its approach to cybersecurity, moving from traditional intelligence reporting to agile, operational collaboration. This talk, presented by Morgan Adamski and Josh Zaritsky from the NSA's Cybersecurity Collaboration Center (CCC), details the evolution of the agency's information sharing mechanisms over the past four years. It highlights the critical shift towards providing timely, actionable intelligence directly to network defenders in the Defense Industrial Base (DIB) and critical infrastructure sectors.
The presentation provides an in-depth look at how the NSA, through its Cybersecurity Directorate and the CCC, actively partners with private industry, vendors, and other government agencies to counter sophisticated cyber adversaries. Adamski and Zaritsky share compelling real-life use cases, demonstrating the power of threat-informed sharing built on principles of agility, creativity, and, most importantly, trust. These examples illustrate how early engagement, multi-party conversations, and innovative service offerings are crucial in preventing and mitigating high-impact cyber intrusions.
The session underscores the NSA's commitment to a collective defense strategy, where intelligence is not merely disseminated but actively operationalized through dynamic partnerships. By showcasing specific scenarios involving zero-day vulnerability disclosure, rapid mitigation guidance, and scalable cybersecurity services for small to medium-sized businesses, the speakers articulate a vision for a more resilient national cyber ecosystem. This talk is essential for cybersecurity professionals, government partners, and DIB organizations seeking to understand and engage with the NSA's evolving role in global cyber defense.
Background
▶ Watch: Speakers' introduction and talk overview (0:00)
The genesis of the NSA's modern cybersecurity mission, and specifically the Cybersecurity Collaboration Center, can be traced back to a pivotal decision by former NSA Director General Nakasone in October 2019. Recognizing the agency's unparalleled "exquisite intelligence" regarding nation-state cyber actors' plans and intentions, there was a strategic imperative to elevate and rebuild the cybersecurity mission. The core challenge was to ensure that this unique, timely, and actionable intelligence reached the hands of those who could actively defend against it – not just within the U.S. government, but critically, within the Defense Industrial Base (DIB) and broader cybersecurity community.
This led to the birth of the Cybersecurity Directorate, which consolidated threat analysts, platform protection specialists, and intelligence professionals. Simultaneously, the Cybersecurity Collaboration Center (CCC) was created with a clear vision: to share intelligence at scale in a way that had never been done before, enabling operationalization by external partners. Historically, NSA intelligence might take months to be compiled into reports, often rendering it less actionable by the time it reached defenders. The new approach demanded agility, creativity, and trust as foundational pillars.
Agility meant establishing programs with the latitude to make quick decisions, moving away from slow, bureaucratic processes. Creativity involved leveraging commercial solutions and collaboration platforms, integrating them with government security requirements, and developing automated capabilities for efficient information sharing. Above all, trust was identified as the bedrock of these partnerships. The CCC emphasizes protecting partner information while using aggregated insights to achieve cybersecurity outcomes at scale. Over the past four years, this model has grown exponentially, from zero to over 800 collaboration channels with 1,000 partners, facilitating 35,000 analytical exchanges annually. This demonstrates a profound shift from a siloed intelligence agency to a proactive, collaborative defense entity.
Key Findings
▶ Watch: Vision and creation of the Cybersecurity Collaboration Center (3:45)
The NSA's Cybersecurity Collaboration Center has made significant strides in operationalizing intelligence and fostering collective defense. The key findings from their four years of operation revolve around the transformative power of proactive, trust-based collaboration.
Firstly, the CCC has proven the effectiveness of rapidly disclosing and mitigating zero-day vulnerabilities through multi-party engagement. By acting as an intermediary and facilitating direct communication between affected DIB companies, vendors, and other security partners, the NSA has successfully contained and patched critical vulnerabilities before widespread exploitation. This agile response minimizes the window of opportunity for sophisticated nation-state actors.
Secondly, the talk highlighted the critical importance of a conversational approach over transactional information sharing. While automation and indicator sharing are valuable, the deepest insights and most impactful mitigations emerge from direct analyst-to-analyst discussions. These conversations allow for a comprehensive understanding of threats, the identification of additional equities, and the development of robust, tailored defensive strategies. This human element is essential for "pulling the thread" on initial breadcrumbs to uncover larger campaigns.
Thirdly, the NSA has successfully developed and deployed scalable cybersecurity services specifically tailored for small to medium-sized businesses (SMBs) within the Defense Industrial Base. These services, including Protective DNS, Attack Surface Management, and Cyber Threat Intelligence, leverage NSA's unique insights to provide baseline protection and prioritized mitigation guidance, effectively leveling the playing field for organizations with limited resources. The success of these services in blocking millions of malicious attempts underscores their practical impact.
Finally, the CCC's experience reinforces that mutual trust and a willingness to share are paramount. DIB companies, often vulnerable to sophisticated attacks, are increasingly coming forward to share their experiences and technical artifacts, understanding that their individual incidents contribute to a collective defense picture. This "you're never alone" philosophy fosters a stronger, more resilient community capable of detecting and remediating threats more effectively across the entire DIB.
Technical Deep Dive
▶ Watch: Agility, creativity, trust: keys to NSA's sharing success (4:55)
The operational collaboration model championed by the NSA's Cybersecurity Collaboration Center is best illustrated through two detailed real-life use cases, alongside its structured cybersecurity services. These examples demonstrate the technical intricacies of threat-informed sharing and the impact of multi-stakeholder engagement.
Critical Infrastructure PLC Vulnerability
About a year prior to the talk, the NSA became aware of a foreign malicious cyber actor possessing a non-public zero-day vulnerability in a specific Programmable Logic Controller (PLC), an Industrial Control System (ICS) device commonly used in critical infrastructure and manufacturing. The concern was immediate and high-priority, as capabilities targeting such devices are typically indicative of destructive intent.
The CCC initiated a four-month collaborative effort. First, they confidentially disclosed the vulnerability to the affected vendor. This involved unclassified and classified discussions, ensuring the vendor's senior leadership understood the gravity of the threat and prioritized resources. The vendor provided hardware to NSA engineers, allowing for a collective, deeper understanding of the exploit and its potential impact across the product portfolio. Recognizing the difficulty of taking critical infrastructure devices offline for patching, the collaboration extended beyond the vendor. The NSA leveraged its relationships with other Operational Technology (OT) security partners to bring them into the discussion. These partners were provided with example network traffic sessions to develop network signatures and mitigations for their products.
The outcome was a synchronized defense: when the vendor publicly disclosed the vulnerability and released patches, a variety of OT security tools already had detection signatures ready for deployment. This proactive, multi-faceted approach significantly curtailed the adversary's ability to freely leverage their capabilities against potential targets, transforming intelligence into tangible, widespread protection. This case highlights the agility and creativity in bringing diverse technical expertise to bear on a complex industrial control system threat.
Citrix ADC Zero-Day Exploitation in DIB
The second vignette involved PRC malicious cyber actors targeting the U.S. Defense Industrial Base (DIB). This activity was first identified through routine collaboration between the NSA and its industry partners in the threat intelligence and endpoint network security space. Anomalous activity was observed targeting a Citrix Application Delivery Controller (ADC) at the edge of a DIB organization's network.
Within hours, the NSA notified the DIB company, which quickly identified a web shell and other suspicious activity. Crucially, the NSA acted as an intermediary, facilitating information exchange between the DIB company and Citrix, the vendor, while protecting the DIB company's identity. Citrix's analysis of logs revealed exploitation of a previously unknown zero-day vulnerability within their platform.
The actor's post-exploitation activity involved attempting to install a backdoor that bypassed authentication. Intriguingly, this was done via an in-memory patch of the primary ADC binary. However, the actor failed to account for the device's memory mapping to disk, which caused the modification to persist, creating a discoverable artifact. Citrix rapidly developed detection and mitigation guidance. This guidance, combined with NSA's insights, was shared broadly across the DIB community. This led to the discovery of the exact same exploitation affecting additional DIB companies.
On December 13, 2022, Citrix released its technical advisory and patches, simultaneously with the NSA publicly releasing a version of its comprehensive mitigation and detection guidance. This coordinated public disclosure ensured that not only DIB companies but the broader technical community could protect their networks, especially if the actor expanded targets or if other adversaries tried to repurpose the vulnerability. This case exemplifies the critical role of trust, rapid information exchange, and detailed technical analysis in countering sophisticated nation-state threats.
Cybersecurity Services for DIB SMBs
To scale protection across the DIB, particularly for resource-constrained small to medium-sized businesses (SMBs), the CCC offers three core cybersecurity services:
- Protective DNS: This service, funded by the DoD and executed commercially, integrates NSA's unique insights into weekly block lists. These lists contain malicious IPs and domains identified by NSA and DODIN. Over three years, this program has resulted in approximately 70 million blocks. These block lists are shared not only with the contracted vendor but also with multiple other Protective DNS vendors, as well as Five Eyes and CISA networks, maximizing their defensive impact.
- Attack Surface Management (ASM): This service provides vulnerability scanning and analysis of DIB partners' internet-facing footprints. Crucially, the NSA overlays its nation-state threat intelligence onto these scans to prioritize patching. For instance, in the context of Volt Typhoon activity, which is known to exploit edge devices, the ASM program can alert partners when specific vulnerabilities on their networks are actively being targeted, urging immediate remediation. The service also aids in asset discovery, helping companies uncover overlooked or misconfigured internet-facing assets, especially common after mergers and acquisitions (M&A) where technical debt is inherited.
- Cyber Threat Intelligence: For DIB partners lacking extensive cybersecurity teams, this service provides actionable threat intelligence directly, enabling them to leverage NSA's insights to protect their networks without requiring deep analytical collaboration. This was notably used to share extensive information regarding Volt Typhoon activities.
These services demonstrate how the NSA translates its intelligence into practical, scalable defensive measures, directly addressing known nation-state attack vectors and helping the DIB proactively manage its cyber risks.
Demo / Proof of Concept
▶ Watch: Impressive growth of NSA's collaboration and information sharing (6:00)
While this conference talk did not feature a live software demonstration, the speakers effectively presented two compelling real-life "vignettes" or use cases that serve as robust proofs of concept for the Cybersecurity Collaboration Center's operational collaboration model. These detailed scenarios illustrate how the CCC's principles of agility, creativity, and trust are applied in practice to achieve significant cybersecurity outcomes.
The first vignette, concerning the Programmable Logic Controller (PLC) zero-day vulnerability, demonstrated the CCC's ability to orchestrate a multi-party response to a critical threat in industrial control systems. It showcased the entire lifecycle of collaboration: from initial intelligence discovery by the NSA, to confidential vendor disclosure, joint technical analysis, and the simultaneous development of patches and network-based mitigations by a broader ecosystem of OT security partners. This proved that early, trust-based engagement can lead to a coordinated defense that prevents sophisticated adversaries from freely exploiting vulnerabilities against critical infrastructure.
The second vignette, detailing the Citrix ADC zero-day exploitation by PRC actors against the DIB, provided a concrete demonstration of rapid threat notification, the NSA's intermediary role in protecting partner identities, and the power of collective analysis. It highlighted how an initial "breadcrumb" of suspicious activity, when shared and analyzed collaboratively with the vendor, led to the discovery of a previously unknown zero-day. The subsequent coordinated public advisory and patch release on December 13, 2022, served as a clear demonstration of how timely intelligence, combined with vendor expertise and community sharing, can rapidly contain and neutralize a nation-state attack campaign.
These "demos" of collaboration in action underscore the talk's central message: that effective cybersecurity against advanced persistent threats is not a solitary endeavor but a collective responsibility, best addressed through integrated, threat-informed partnerships.
Defensive Implications
▶ Watch: First use case: defending critical infrastructure from foreign actors (7:00)
The insights shared by the NSA's Cybersecurity Collaboration Center offer crucial defensive implications for organizations, particularly those within the Defense Industrial Base and critical infrastructure sectors.
- Prioritize Proactive Collaboration: Defenders should actively seek to establish and nurture relationships with government agencies like the NSA, CISA, and FBI, as well as key vendors and other industry partners. The talk emphasizes that conversation, not just transactional sharing, is where true value lies in understanding and mitigating complex threats. Organizations should be prepared to share technical artifacts and insights, as their unique "spark" might uncover a broader campaign affecting others.
- Leverage Threat-Informed Services: Organizations, especially SMBs in the DIB, should explore and adopt cybersecurity services that integrate nation-state threat intelligence. Services like Protective DNS and Attack Surface Management can provide baseline protection and critically prioritize patching efforts based on known adversary targeting. This means understanding which vulnerabilities are being actively exploited by specific nation-state actors and addressing those first, rather than relying solely on generic vulnerability scores.
- Embrace Agility in Patching and Mitigation: The examples demonstrate that nation-state actors frequently exploit both new zero-days and older, unpatched vulnerabilities. Defenders must cultivate an agile patching strategy, particularly for internet-facing devices and those known to be targeted by sophisticated adversaries (e.g., edge devices targeted by Volt Typhoon). Continuous asset discovery is vital to ensure that no forgotten or misconfigured asset remains exposed.
- Cultivate an "Always On" Intelligence Mindset: Defenders should recognize that they are "never alone" in facing intrusions. Sharing incident details and technical indicators with trusted partners can lead to broader detection and remediation efforts, benefiting the entire community. This requires a cultural shift towards transparency and collective defense, even when it involves sensitive internal information.
- Consider the Human Element of Adversaries: While technical mitigations are crucial, the talk also touched upon the importance of understanding the human behind the attack. Defenders should consider not just the technical aspects of an intrusion but also the adversary's decision-making, campaigns, and potential for influence or disruption. This broader perspective can inform more strategic defensive postures and counter-operations.
- Trust as a Foundational Control: Building and maintaining trust with partners, even when acting as an intermediary to protect identities, is essential for effective information flow. Organizations should evaluate their own trust frameworks for sharing sensitive threat intelligence, recognizing that mutual trust enables faster, more comprehensive responses to shared threats.
By adopting these principles, defenders can move beyond reactive measures to a more proactive, collaborative, and ultimately more resilient cybersecurity posture against the most advanced cyber adversaries.
Key Takeaways
- Collaboration and Trust are Paramount: Effective defense against nation-state actors hinges on deep, trust-based relationships between government, industry, and vendors, facilitating open conversation over mere transactional sharing.
- Agile, Threat-Informed Intelligence: The NSA has transformed its intelligence sharing to be agile, timely, and directly actionable, providing unique insights to network defenders to counter specific nation-state threats like Volt Typhoon.
- Human-Centric Operationalization: While automation is valuable, analyst-to-analyst conversations are critical for "pulling the thread" on initial indicators, uncovering complex campaigns, and developing comprehensive mitigations.
- Scalable Services for DIB Resilience: Programs like Protective DNS (70 million blocks) and Attack Surface Management enable SMBs in the DIB to gain essential protection and prioritize patching based on NSA's threat intelligence.
- Proactive Zero-Day Mitigation: Coordinated disclosure and rapid, multi-party collaboration can effectively contain and patch zero-day vulnerabilities in critical infrastructure and the DIB before widespread exploitation.
- Collective Defense Mindset: Organizations are encouraged to share their incident experiences and technical artifacts, understanding that their contributions strengthen the collective defense posture for the entire community.
About the Speaker(s)
Morgan Adamski is the Director of the Cybersecurity Collaboration Center at the National Security Agency (NSA). With approximately 16 years of experience in cybersecurity within the U.S. government, primarily at NSA, she has focused on cyber defense against nation-state actors. Her background also includes policy work at the Pentagon, where she contributed to writing the 2018 DoD cyber strategy. Adamski played a key role in the standup of the Cybersecurity Directorate before transitioning to lead the CCC, demonstrating a strong commitment to evolving NSA's information sharing capabilities.
Josh Zaritsky serves as the Chief Operations Officer (COO) in the Cybersecurity Collaboration Center. He brings about 20 years of experience at the NSA, working on both sides of the agency's mission. Zaritsky has also spent time in the private industry, which provides him with a unique perspective on the challenges and opportunities for public-private partnerships in cybersecurity. His operational leadership at the CCC is instrumental in executing the center's mission of collaborative threat-informed defense.