Skip to content

JArmandoG/MITRE_General

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 

Repository files navigation

MITRE

MITRE ATT&CK DEFENDER (MAD): https://mitre-engenuity.org/mad/ (Link: "Get training" → Cybrary → Free when training from MAD) https://mitre-engenuity.org/blog/2021/03/25/mad-press-release/https://www.cybrary.it/catalog/refined/?q=mit Getting Started ATT&CK: https://attack.mitre.org/resources/getting-started/

CAR - CYBER ANALYTICS REPOSITORY


Analytics

Sysmon, Osquery → Splunk, etc. Tactics/Techniques detection

MITRE ATT&CK


An exercise

General Info:

Tactic vs. Technique vs. Procedure:

Untitled

Tactics: Adversary's Technical Goals

Techniques: How those Goals are achieved.

Procedures: Specific implementations of techniques.

"Atomic Indicator": IP address, File Hash, etc. (Indicadores mínimos de presencia de un adversario)

Usage: Incident Report / Observable Behavior → Mapping to MITRE ATT&CK

Recommendations:

  • UNDERSTAND ATT&CK
  • FIND BEHAVIOR
  • RESEARCH BEHAVIOR
  • TRANSLATE THE BEHAVIOR → TACTIC
  • WHICH TECHNIQUES APPLIES TO THE BEHAVIOR
  • COMPARE RESULTS

General resources

Pdf: Getting started with ATT&CK (GOOD)

PDF: Foundations of Operationalizing MITRE ATT&CK

MITRE ATT&CK FOR DUMMIES PDF

MITRE ATT&CK GROUPS

Groups

CISA_Best_Practices_for_MITRE_ATTCK_Mapping_.pdf

MATRIX - USAGE


MATRIX & GROUPS -

Enterprise Matrix

Groups

BY INDUSTRY -

Example: Searching for ecommerce industry:

Untitled

NAVIGATOR

ATT&CK® Navigator

Use the Navigator directly for a custom Matrix or select it from APT Group, technique, or even Software (i.e. Mimikatz) and see the Matrix already highlighted for the tactic, technique, group or swoftware:

Example usage

Directly into a Navigator highlighting this group's tactics & techniques

Directly into a Navigator highlighting this group's tactics & techniques

Ejemplo: Conti (Software)

Untitled

Red Team Simulators:

Untitled

Breach and Attack Simulations (BAS) Technologies

MITRE CAR (Cyber Analytics Repository)

Analytics

attack-scripts/scripts at master · mitre-attack/attack-scripts

Attack scripts

Usage (Extract logs → Integrate a SIEM → Use Datasets for testing → Analyze with MITRE CAR)

  • Use SIGMA for translating CAR analytics into other languages

Untitled

MITRE D3FENSE

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published