MITRE ATT&CK is today an important reference for structuring detection capabilities.

The framework describes the techniques and behaviors used by adversaries.

An organization can therefore build SIEM use cases around specific techniques.

Examples:

  • account discovery;
  • network discovery;
  • escalation of privileges;
  • lateral movement;
  • script execution;
  • theft of credentials;
  • persistence;
  • exfiltration;
  • manipulation of defense mechanisms.

MITRE also provides resources to help defenders build ATT&CK-based detection mechanisms. [4]

The goal is then to move from a logic of:

“We have installed a SIEM.”

has :

“We know which attack techniques our SIEM is capable of detecting.”

This difference is considerable.

Categories: