The MITRE ATT&CK framework is a globally used knowledge base of the tactics and techniques employed by cybercriminals during attacks. Organisations use the framework to identify threats, assess security measures and reveal gaps in their detection capabilities. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge.
Discussions with existing customers and partners revealed that collecting and analysing data from different sources presents many challenges. How do you find the needle in the haystack? And how can you effectively identify patterns that indicate unusual behaviour? In this article, we explain how SBL Cyber Monitoring uses the MITRE ATT&CK framework.
The MITRE ATT&CK framework is an extensive knowledge base that categorises the behaviour of cyber adversaries into tactics, techniques and sub-techniques. It describes, among other things:
We use this framework in our cybersecurity assessments to:
In our cybersecurity assessments, we use the MITRE ATT&CK framework to map the potential attack path of a cyber adversary. Based on this path, we analyse how resilient a customer is against different attack patterns.
The framework provides insight into the measures that can mitigate attack techniques and the methods that can be used to detect suspicious behaviour. This is particularly valuable when conducting in-depth threat analysis across large volumes of data, also known as threat hunting.
WatchEagle automatically analyses data from IT and OT networks to identify potential cyber threats. It uses the structure and attack techniques defined in the MITRE ATT&CK framework.
This technology enables us to:
Examples include:
MITRE ATT&CK categorises attacker behaviour into recognisable tactics, techniques and sub-techniques. This enables security teams to determine which attack patterns they can already detect and where gaps in their detection capabilities remain.
WatchEagle uses this structure to analyse current and historical network data. When behaviour in the data corresponds to a known attack technique, it can be investigated more quickly. In this way, MITRE ATT&CK supports the targeted development and improvement of detection rules.
By applying the MITRE ATT&CK framework, WatchEagle is becoming increasingly effective at finding the needle in the haystack. We continue to add new attack patterns to WatchEagle and investigate how we can provide immediate, actionable guidance when suspicious activity is detected.
Do you want to do more than identify attack patterns and also test whether your security measures actually detect them? With a breach and attack simulation, SBL safely simulates realistic attack techniques and provides insight into the effectiveness of your security controls.