MITRE ATT&CK is today an important reference for structuring detection capabilities.
The framework describes the techniques and behaviors used by adversaries.
An organization can therefore build SIEM use cases around specific techniques.
Examples:
- account discovery;
- network discovery;
- escalation of privileges;
- lateral movement;
- script execution;
- theft of credentials;
- persistence;
- exfiltration;
- manipulation of defense mechanisms.
MITRE also provides resources to help defenders build ATT&CK-based detection mechanisms. [4]
The goal is then to move from a logic of:
“We have installed a SIEM.”
has :
“We know which attack techniques our SIEM is capable of detecting.”
This difference is considerable.