<img alt="" src="https://secure.hiss3lark.com/173130.png" style="display:none;">

Datashield's Resource Library

Read all of our news, articles, reviews, and more in our company blog

All Posts

What is the MITRE ATT&CK Framework?

What is the MITRE ATT&CK Framework_

Learn about the MITRE ATT&CK® Framework and how cybersecurity teams leverage its matrix of tactics and techniques to assess risk and vulnerabilities within an organization.

Definition 

The MITRE ATT&CK Framework is a knowledge base of tactics and techniques that can be used as a foundation for classifying adversary behaviors and assessing an organization’s vulnerabilities. 

Created in 2013 by the MITRE Corporation, a non-profit supporting U.S. government agencies, it is one of the most comprehensive sources for classifying threats and developing models. 

The ATT&CK portion of the name stands for Adversarial Tactics, Techniques, and Common Knowledge. 

Simply put, you can imagine the MITRE ATT&CK knowledge base a “Wikipedia” of cyber threats and tactics. 

Who is MITRE? 

MITRE is a government-funded research organization. The company was born out of MIT in 1958MITRE started ATT&CK in 2013 to document common tactics, techniques, and procedures (TTPs) that advanced persistent threats use against Windows enterprise networks. It was created out of a need to document adversary behaviors for use within a MITRE research project. 

Upgrade your cybersecurity strategy click here

MITRE ATT&CK Matrices 

The MITRE ATT&CK Matrices are tactics and techniques laid out in a “periodic table” of tactics and techniques used by threat hunters, defenders, and other cybersecurity professionals to classify attacks and assess an organization’s risk. 

The most popular framework used is the MITRE ATT&CK® Matrix for Enterprise. 

The matrix contains information for the following platforms: Windows, macOS, Linux, PRE, AWS, GCP, Azure, Azure AD, Office 365, SaaS, Network.

mitre att&ck framework matrix enterprise

Tactics 

The MITRE ATT&CK Tactics represent the “why” of a technique. What is the adversary’s objective when performing an action? Tactics give important context to the offensive action. 

Techniques 

Techniques are the “how” component of the action, how an adversary achieves the tactic. They may also represent the “what” an adversary gains by performing an action.  

Use Cases 

There are a number of ways an organization can utilize the MITRE ATT&CK framework, here are just a few: 

  • Adversary Emulation: Organizations can use the framework to emulate scenarios and verify their defenses 
  • Red TeamingPlan and organize red team operations to avoid certain defensive measures within a network 
  • Behavioral Analytics Development: Construct and test behavioral analytics to detect adversarial behavior within an environment 
  • Defensive Gap AssessmentAssess tools, monitoring, and mitigations of existing defenses to find gaps 
  • SOC Maturity Assessment: The matrix can be used as one measure of a SOC’s effectiveness and can signal its maturity in detecting and responding to intrusions 
  • Cyber Threat Intelligence: Use the MITRE ATT&CK framework to better understand adversary group profiles and popular threat actors 

How Datashield Utilizes the MITRE ATT&CK Framework 

When choosing a Managed Security Service Provider (MSSP) for outsourced threat detection and response services, the MITRE ATT&CK Framework proves its value in a Security Operations Center (SOC). 

Datashield uses the MITRE ATT&CK framework in several ways. 

First, our content team maps each of our alerts to a technique, which allows us to see where our detections are heaviest and where we need to expand our ruleset. 

When our analysts are threat hunting, they use MITRE techniques as guides for Tools, Techniques, and Procedures (TTPs) that they should be on the lookout for. Doing so allows us to find gaps in customer visibility. 

One use case is if a customer gets all their alerts in the Reconnaissance phase, but not much else, we can assume they are not receiving all relevant data. This would start a process where we take another look at their environment and see if their critical logging source has changed their logging format. 

Another added benefit is trend data. Datashield receives alerts across our clients’ environments collectively, where they can be categorized using the MITRE framework. For example, if there is a spike in Initial Access through phishing, like the initial onset of COVID-19, or an influx in Supply Chain attacks in the SolarWinds fiasco. 

Our customers receive more information so they can become more granular with their defense strategies and focus on weak areas. For example, if we see a customer with a large amount of phishing emails, they may need to step up their email filtering. Or if we see an increase in privilege escalation, defense evasion, or credential access, we should figure out the origin of these attacks and ensure the customer has a solid Endpoint Detection and Response platform. 

MITRE allows Datashield to identify gaps in security and give a broad picture of where our SOC should focus and how to better assist our clients. 

Every level of our security operations team uses the MITRE ATT&CK framework, from reporting to tasking the threat content team to see if customers need specialized assistance or guidance. 

SHIELDVision 

Datashield’s proprietary orchestration tool, SHIELDVision, utilizes the MITRE ATT&CK framework in order to provide concise identification and feedback. 

We utilize the framework in our automated scans, hunting scans, and investigations. Analysts make sure to list the Access and Technique according to the framework. 

Customers can rest easier knowing we are mapping their networks to the MITRE framework and receive additional insight in their quarterly calls with our engagement team. 

Conclusion 

The MITRE ATT&CK Framework is an important tool for red and blue teams alike. Whether it’s emulating an attack or using the framework to inform security decisions, the MITRE ATT&CK framework is a useful piece of the cybersecurity landscape. 

Leading MSSPs utilize the framework in order to provide in-depth investigations, threat hunt, and create clear communication with their customers. 

To learn more about how Datashield uses the MITRE ATT&CK Framework and how we can protect your network, contact us today. 

Read more blogs from Datashield

Topics from this Article

Managed Detection and Response, Endpoint Detection and Response, Managed Security Service Providers, Blue Team, MITRE ATT&CK, SOC

Cassidy Trowbridge
Cassidy Trowbridge
Cassidy is a marketing specialist at Datashield. She manages Datashield's content and social marketing strategies.

Related Posts

Strong Showing For Datashield Partners In 2021 Gartner Magic Quadrant

With a clear separation in the market among the considered vendors, the newest Gartner Magic Quadrant for EPP, showcases 4 Datashield partners who are leading in this space.

How Datashield and ExtraHop Work Together

Learn how Datashield partners with ExtraHop, our premier Network Detection and Response (NDR) partner, from our Director of Product Management Mike Heller. I first met the ExtraHop team at RSA Conference 2020, just weeks before the world changed from COVID-19. After the initial meet and greets, we decided to schedule a time to do a deep dive post-conference. Datashield saw an immediate value-add that our service would bring from a technology perspective.

What is Cyber Insurance?

Statistics show that the fallout from successful cybersecurity incidents has both financial and business-related consequences. A data breach costs the average enterprises approximately $60,000, and in extreme situations, small and medium-sized businesses may go out of business within 6 months from the date the incident occurred. Thus, to determine whether the financial cost of successful hacking attempts, businesses have turned to insurance to deal with extensive losses.