infosec-jobs.com · @infosec_jobs
1453 followers · 14571 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1450 followers · 14564 posts · Server mastodon.social
Ricky · @ricky
11 followers · 16 posts · Server infosec.exchange

@fugueish Yes, but I think your CSIRP and related processes would need to reference MITRE ATT&CK and require it before it would be widely used.
It can get you started on mapping out any possible threat, risk, or attack you can think of and help you come up with mitigations. But if everybody isn't using it, you'll have references and language that only some teams understand.
In real life, it is nice when our security tools link to MITRE ATT&CK because we can quickly understand what a particular alert is about. But we don't put that on a report that goes to anybody else, because, as of right now, they would have no idea what T1548.002 means.

#mitre #mitreattack #mitreattck #csirp #csirt #infosec

Last updated 3 years ago

Melinda Marks · @melindamarks
33 followers · 7 posts · Server infosec.exchange
Melinda Marks · @melindamarks
113 followers · 59 posts · Server infosec.exchange
_Veronica_ · @verovaleros
345 followers · 122 posts · Server infosec.exchange

I like Mitre ATT&CK, but it feels too enterprise centric and often lacking behaviors usually tied to other scenarios such as home infections. These intrusions are not doing internal lateral movement, but scanning/attacking the internet. Somehow “network service discovery “ feels inappropriate for such behavior.

#threatintel #mitreattck

Last updated 3 years ago

cygnetix :unverified:​ · @cygnetix
401 followers · 136 posts · Server infosec.exchange

Attack Flow has come a long way since I last looked at it. I'd love to see Red Teams start including Attack Flow diagrams as part of their report findings.

center-for-threat-informed-def

#mitreattck #redteamtips

Last updated 3 years ago

MJS :trans: · @MJS
40 followers · 62 posts · Server hachyderm.io
· @postmodern
301 followers · 173 posts · Server infosec.exchange

Other than MITRE ATT&CK which is very broad and exhaustive, is there a attribute list for "capabilities" or "functionality" (or whatever you want to call them) that exploits or payloads grant the user? I'm looking for things like command-exec, file-read, file-write, etc.

#infosec #taxonomy #postexploitation #mitreattck

Last updated 3 years ago

Puggmeister · @Puggmeister
11 followers · 5 posts · Server infosec.exchange

Jag har nyligen publicerat två delar av en serie på Medium om Atomic Red Team, Mitre ATT&CK och lite IT-forensiska verktyg. Tanken är att visa både på vilket sätt man kan använda Atomic Red Team, för att skapa en bättre förståelse för vad som händer på en klient vid ett potentiellt intrång, samt hur man med ganska enkla medel kan få fram artefakter och tekniska indikatorer vid en undersökning efter en attack-simulering.
Jag tar gärna emot feedback.
Här är del 1:
medium.com/@mathias_persson/it

Här är del 2:
medium.com/@mathias_persson/it

#dfir #Atomicredteam #mitreattck

Last updated 3 years ago

Taylor Parizo · @taylorparizo
85 followers · 46 posts · Server infosec.exchange

Great way of adding MITRE ATT&Ck analytics to your SIEM for threat hunting. They even added an intelligence component that resembles MITRE's Software/Groups tabs so your references are in one place.

thehackernews.com/2022/11/thre

#threatintel #threathunting #mitreattck

Last updated 3 years ago

infosec-jobs.com · @infosec_jobs
1086 followers · 14485 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1051 followers · 14465 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1045 followers · 14456 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1041 followers · 14444 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1027 followers · 14430 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1023 followers · 14417 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1021 followers · 14404 posts · Server mastodon.social
infosec-jobs.com · @infosec_jobs
1017 followers · 14400 posts · Server mastodon.social