SIEM and Security Frameworks

MITRE ATT&CK framework overview

Learning Outcome

4

Map attacks using the ATT&CK Matrix.

3

Describe ATT&CK tactics and attack stages.

2

Differentiate Tactics, Techniques, and Sub-Techniques.

1

Explain MITRE ATT&CK’s purpose.

5

Explain ATT&CK use in SOC operations.

Before an important football match, a team studies its opponent’s playbook to understand the different moves they may use.

Playbook = MITRE ATT&CK Framework

The team learns that the opponent may use different strategies to attack, such as passing, dribbling, or making quick runs.

Attack strategies = Tactics;
Specific attack methods = Techniques

During the match, players recognize a familiar attacking move because they studied the playbook earlier.

They quickly prepare the right defense.

Recognizing attacker behavior = Threat Detection

The defenders use the right defensive move and stop the opponent from reaching the goal.

Stopping the attack = Defense and Incident Response

In cybersecurity, MITRE ATT&CK works like this football playbook. It documents common tactics and techniques used by attackers. Security teams study them to recognize attacks, detect suspicious behavior, investigate threats, and improve defenses.

What is MITRE ATT&CK?

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally recognized cybersecurity framework that documents how real-world attackers operate.

 

It organizes attacker behavior into tactics, techniques, and procedures (TTPs) to help security teams understand, detect, and respond to threats.

 

 

 

 

 

 

 

 

It is widely used by SOC analysts, threat hunters, incident responders, and security teams.

History of MITRE ATT&CK

Developed by MITRE in 2013 based on real-world cyberattack research.

 

Initially focused on attacker techniques against enterprise environments.

 

Expanded to cover cloud, mobile, and industrial control systems.

 

Regularly updated to reflect emerging threats and techniques.

Importance in Cybersecurity

Provides a common language for describing attacker behavior.

 

Helps improve detection, investigation, and response.

 

Helps identify security gaps and strengthen defenses.

Purpose of the Framework

ATT&CK documents how attackers operate and provides a structured approach for:

Understanding attack techniques

Improving threat detection

Developing defensive strategies

Supporting proactive threat hunting

ATT&CK Knowledge Base

ATT&CK contains information about real-world attacker behavior. Each technique includes:

Attack method description

Detection recommendations

Mitigation strategies

Real-world examples

Real-World Adversary Behavior

ATT&CK is based on observed attacker behavior, rather than only theoretical models. It helps security teams understand how attackers gain access, move through networks, steal data, and achieve objectives.

Key Concepts of MITRE ATT&CK

Tactics

Tactics represent what an attacker wants to achieve.

Examples:

Initial Access

 

Credential Access

 

Exfiltration

Techniques

Techniques describe how attackers achieve their objectives.

Examples:

Tactic: Initial Access

 

Technique: Phishing

Sub-Techniques

Sub-techniques provide more specific details about a technique.

Benefits:

Better detection accuracy

 

Detailed threat analysis

 

Improved investigations

ATT&CK Tactics Overview

Tactic

Purpose

Reconnaissance

Resource Development

Initial Access

Gather information about the target.

Create or obtain resources for an attack.

Gain entry into the target environment.

Execution

Persistence

Privilege Escalation

Run malicious code or commands.

Maintain access to compromised systems.

Gain higher levels of access.

Defense Evasion

Credential Access

Discovery

Avoid detection by security tools.

Obtain passwords and authentication information.

Gather information about systems, usersnetworks.

Lateral Movement

Collection

Move between systems within the environment.

Gather data of interest.

Command and Control

Exfiltration

Impact

Communicate with and control compromised systems.

Transfer stolen data outside the environment.

Disrupt operations or damage systems/data.

What is the ATT&CK Matrix?

The ATT&CK Matrix is a visual representation of tactics and techniques that helps security teams understand attacker behavior.

Structure

Tactics

Columns

Helps analysts understand attack progression and map attacker activities.

Techniques

Listed under the relevant tactics

ATT&CK Data Sources

Organizations use different data sources to detect ATT&CK techniques:

Authentication Logs:

Login and account activities.

Network Traffic:

Communication between systems.

Endpoint Telemetry:

Process Logs:

Programs and commands executed.

Cloud Logs:

Activities in cloud environments.

Activities on endpoints.

MITRE ATT&CK and SOC Operations

Threat Detection

Identify attacker techniques and improve detection.

1

Alert Investigation

Understand attacker behavior and investigate alerts.

2

Incident Response

Identify attacker actions and affected systems.

3

Threat Hunting

Proactively search for hidden threats.

4

Security Monitoring

Ensure visibility across attack stages.

5

What is ATT&CK Mapping?

ATT&CK Mapping is the process of associating observed attacker activities with ATT&CK tactics and techniques.

Mapping Incidents

Security teams analyze alerts, logs, and evidence to identify techniques used during an attack.

Benefits

Standardized incident analysis

Better threat visibility

Improved detection coverage

Enhanced reporting

More effective incident response

Activity

ATT&CK Tactic

Phishing Email

PowerShell Execution

Credential Dumping

Initial Access

Execution

Credential Access

Example

ATT&CK Use Cases

Threat Detection

Create detection rules for attacker techniques.

Smart Layouts

AI arranges content beautifully for better flow and impact

Security Assessment

Identify gaps in security controls.

Incident Investigation

Understand attacker actions and timelines.

Threat Hunting

Proactively search for attacker activity.

Benefits of MITRE ATT&CK

Standardized Security Framework: Common language for attacker behavior.

 

 

Better Threat Visibility: Improves understanding of attacks.

 

 

Improved Detection Coverage: Supports effective detection rules.

 

 

Enhanced Incident Response: Provides investigation context.

 

 

Threat Hunting Support: Helps proactively identify threats.

Challenges of Using MITRE ATT&CK

Large Number of Techniques:

Can be difficult to learn and manage.

Continuous Updates: 

Requires keeping up with framework changes.

Complexity for Beginners: 

Its size can be overwhelming.

Resource Requirements: 

Requires skilled people, tools, and maintenance.

MITRE ATT&CK vs Cyber Kill Chain

Understand attacker behavior

Improve security defenses

Similarities

Both frameworks help organizations:

Support detection, threat hunting, and incident response

Differences

Focuses on tactics and techniques

Provides detailed attack methods

Supports threat hunting and detection engineering

Contains many techniques

Focuses on attack stages

Provides high-level attack progression

Supports attack lifecycle analysis

Contains a limited number of phases

MITRE ATT&CK

Cyber Kill Chain

When to Use Each

Organizations can use both frameworks together:

Cyber Kill Chain →

Understands the overall attack progression.

 

 


MITRE ATT&CK →

Provides detailed visibility into the techniques used at each stage.

Summary

5

Helps SOC teams analyze and respond to threats.

4

The Matrix maps attacker tactics and techniques.

3

Supports detection, threat hunting, and incident response.

2

It organizes attacks into tactics, techniques, and sub-techniques.

1

ATT&CK documents real-world attacker behavior.

Quiz

Which ATT&CK concept represents the specific method an attacker uses to achieve an objective?

 

B. Matrix

C. Tactic

D. Technique

A. Procedure

Quiz-Answer

Which ATT&CK concept represents the specific method an attacker uses to achieve an objective?

 

A. Procedure

B. Matrix

C. Tactic

D. Technique

MITRE ATT&CK framework overview

By Content ITV

MITRE ATT&CK framework overview

  • 150