The near-total internet shutdown imposed by the Iranian government since January 8, reportedly due to a crackdown on protesters, may provide a rare opportunity for Security Operations Centers (SOCs) and other cybersecurity analysts, briefly allowing the identification and digital identification of all sources of government traffic, which is a huge help in monitoring Iranian state actors.
See also: Zero-day vulnerabilities: Why they're on the rise and who pays the price

Among global rogue state actors, Iran ranks near the top, behind China, Russia and North Korea, suggesting that this kind of information about Iranian systems could prove useful. One cybersecurity company CEO says it is a potential goldmine of threat intelligence.
In a near-total internet outage, “the attack surface available to government hackers is reduced. They can no longer hide in the noise of millions of home IPs. They are forced to direct their attacks through the few remaining paths, which are just those boring government agencies like Agriculture, Energy, Universities,” said Kaveh Ranjbar, CEO of Whisper Security. “Advanced Persistent Threat Groups (APTs) typically exploit innocent government infrastructure to launch attacks because they look clean. When the rest of the country is dark, those boring servers become the only available launchers. A connection from the Department of Agriculture might not be a farmer. It could be a tunnel for a government agent who needs an exit node.”
See also: Prepare a tech emergency kit before the next blackout

Ranjbar said that removing traffic from millions of Iranian business and home user routines allows for robust visibility into Iranian government traffic patterns, thus allowing SOCs to pinpoint these sources.
If a server is allowed to communicate with the outside world while 80 million citizens are silent, that server is, by definition, a state asset. In a zero-trust environment, this makes it a high-confidence indicator of a breach (IoC). Analysts and consultants, however, were skeptical about the approach, but pointed out that, on a return on investment (ROI) basis, it typically requires minimal effort to collect this data during an outage.
State actors for these four countries are among the most sophisticated, experienced, and well-funded attackers anywhere. One of their top skills is not only knowing how to cover their tracks, but also how to create fake logs and other deceptions to make an attack appear to be coming from anywhere other than its actual source. In short, if the logs show that the attack is coming from China, a CISO knows that the attack almost certainly didn’t come from there.
Sanchit Vir Gogia, principal analyst at Greyhound Research, said he sees some potential value, but added that it is limited.
See also: Creating a functional playbook for dealing with ransomware attacks

State actors tend to reuse infrastructure, routes, and operational models. Performance is risky based on fragmented technical data. Security professionals must always be alert and respond to any incident promptly and accurately.
