MITRE ATT&CK: Difference between revisions
No edit summary |
No edit summary |
||
| Line 13: | Line 13: | ||
==MITRE ATT&CK Matrix for Enterprise== | ==MITRE ATT&CK Matrix for Enterprise== | ||
===Reconnaissance=== | ===Reconnaissance=== | ||
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. <ref name=”RE1”>"Reconnaissance" - Abrufbar unter: https://attack.mitre.org/tactics/TA0043/</ref> | |||
===Ressource Development=== | ===Ressource Development=== | ||
Revision as of 07:50, 3 January 2024
Introduction
Developed by MITRE, ATT&CK is a globally accessible knowledge base focused on adversary behaviour. Cyber adversaries are notorious for their intelligence, adaptability, and persistence, learning from each attack, whether successful or unsuccessful. Their capabilities range from stealing personal information to disrupting critical infrastructure and damaging business operations. The MITRE ATT&CK knowledge-base is freely available to everyone. THE MITRE ATT&CK knowledge base documents the common tactics, techniques and procedures used by cyber adversaries. It can serve as a valuable resource for the development of specific threat models and methodologies. [1]
MITRE ATT&CK Groups
MITRE ATT&CK Software
MITRE ATT&CK Tactics
MITRE ATT&CK Techniques
MITRE ATT&CK Matrix for Enterprise
Reconnaissance
Reconnaissance involves adversaries actively or passively collecting information to support their targeting efforts an reach their target, which consist in an successfull attack. This gathered informations may include details about the victim organization, its infrastructure, used software or hardware or personnel. Threat actors can utilize this information across different phases of the mentioned process (MITRE ATT&CK Matrix), using it for tasks like planning and executing Initial Access, determining post-compromise objectives, or guiding subsequent Reconnaissance efforts. [1]
Ressource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Controll
Exfiltration
Impact
References
- ↑ 1.0 1.1 "MITRE ATT&CK" - Abrufbar unter: https://www.mitre.org/focus-areas/cybersecurity/mitre-attack Cite error: Invalid
<ref>tag; name "”RE1”" defined multiple times with different content