NL

What is the MITRE ATT&CK framework and how does it work?

Date: 01-06-2022

The MITRE ATT&CK framework is a globally used knowledge base of the tactics and techniques employed by cybercriminals during attacks. Organisations use the framework to identify threats, assess security measures and reveal gaps in their detection capabilities. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge.

Discussions with existing customers and partners revealed that collecting and analysing data from different sources presents many challenges. How do you find the needle in the haystack? And how can you effectively identify patterns that indicate unusual behaviour? In this article, we explain how SBL Cyber Monitoring uses the MITRE ATT&CK framework.
 

What is the MITRE ATT&CK framework?

The MITRE ATT&CK framework is an extensive knowledge base that categorises the behaviour of cyber adversaries into tactics, techniques and sub-techniques. It describes, among other things:

  1. How attackers operate
  2. Which attack techniques they use
  3. How attack techniques can be detected and mitigated

We use this framework in our cybersecurity assessments to:

  • Map the potential attack path of a cybercriminal
  • Analyse how resilient our customers are against different attack patterns
  • Recommend effective protection and detection measures
     

How is MITRE ATT&CK used in a cybersecurity assessment?

In our cybersecurity assessments, we use the MITRE ATT&CK framework to map the potential attack path of a cyber adversary. Based on this path, we analyse how resilient a customer is against different attack patterns.

The framework provides insight into the measures that can mitigate attack techniques and the methods that can be used to detect suspicious behaviour. This is particularly valuable when conducting in-depth threat analysis across large volumes of data, also known as threat hunting.
 

Applying MITRE ATT&CK with WatchEagle

WatchEagle automatically analyses data from IT and OT networks to identify potential cyber threats. It uses the structure and attack techniques defined in the MITRE ATT&CK framework.

This technology enables us to:

  1. Analyse real-time data for suspicious patterns
  2. Examine historical data for previously observed attack patterns
  3. Identify specific threats and attack techniques

Examples include:

  • DNS tunneling: a technique used to transfer or exfiltrate data without being detected
  • Lateral movement: techniques used by attackers to move through a network
  • Persistence: techniques used by attackers to maintain long-term access to an environment
     

How does MITRE ATT&CK help detect cyberattacks?

MITRE ATT&CK categorises attacker behaviour into recognisable tactics, techniques and sub-techniques. This enables security teams to determine which attack patterns they can already detect and where gaps in their detection capabilities remain.

WatchEagle uses this structure to analyse current and historical network data. When behaviour in the data corresponds to a known attack technique, it can be investigated more quickly. In this way, MITRE ATT&CK supports the targeted development and improvement of detection rules.
 

Using MITRE ATT&CK for better detection and threat hunting

By applying the MITRE ATT&CK framework, WatchEagle is becoming increasingly effective at finding the needle in the haystack. We continue to add new attack patterns to WatchEagle and investigate how we can provide immediate, actionable guidance when suspicious activity is detected.
 

Testing security with breach and attack simulation

Do you want to do more than identify attack patterns and also test whether your security measures actually detect them? With a breach and attack simulation, SBL safely simulates realistic attack techniques and provides insight into the effectiveness of your security controls.