What is MITRE ATT&CK?
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a knowledge base that describes how cyber adversaries operate during attacks. It is based on observed adversary behavior and organizes that behavior into a structure that security teams can use to understand, detect, and defend against different attack methods.
ATT&CK distinguishes between concepts including tactics and techniques. Tactics describe what an adversary is trying to achieve, while techniques describe how the adversary attempts to achieve that objective. Techniques can be divided into more detailed sub-techniques, while procedures describe how specific adversaries have implemented techniques in practice.
Examples of tactics include gaining initial access, obtaining higher privileges, accessing credentials, collecting information, and communicating with compromised systems. By mapping observed activity to ATT&CK, security teams gain a common language for describing how an attack develops.
MITRE ATT&CK covers three technology domains: Enterprise for enterprise networks, cloud services, and other IT environments, Mobile for mobile devices, and ICS for industrial control systems.
A useful analogy is a catalog of burglary techniques. Rather than simply recording that someone broke into a building, the catalog describes the objectives a burglar may have along the way, the methods they may use, and the traces those methods can leave behind.
Sicra and MITRE ATT&CK
Detecting and responding to cyberattacks requires an understanding of how adversaries actually operate. MITRE ATT&CK provides a structure for describing known attack methods and assessing how effectively an organization’s security controls and detection capabilities cover them.
ATT&CK can be used in security monitoring, threat-informed assessments, penetration testing, and security maturity assessments. Mapping observed events and security data to known techniques can make it easier to understand what an adversary is attempting to do and where an organization has strong or insufficient coverage.
Sicra helps organizations with continuous security monitoring, network security assessments, and security maturity assessments. MITRE ATT&CK can be used as a professional framework for understanding threats, analyzing detection capabilities, and prioritizing security improvements.
Services
Sicra SOC - Security Operation Center
Network security assessment
Security maturity assessment
Sicra security analysis
Related terms: Cyber Kill Chain, MITRE D3FEND, Threat intelligence, Blue team, Red team, Purple team, SOC (Security Operations Center), SIEM (Security Information and Event Management), EDR (Endpoint Detection and Response), XDR (Extended Detection and Response), Pentesting