A Survey of Attack Techniques Based on MITRE ATT&CK Enterprise Matrix
摘要
MITRE ATT&CK is a well-known knowledge base of adversary tactics and techniques built by MITRE, which is a non-profit organization funded by Federal government of the United States. MITRE collects real-world attack events, and builds knowledge base from these events. Enterprise Matrix is the part related to enterprise attack events among the knowledge base. ATT&CK Enterprise Matrix has been used in many aspects, for instance, threat modeling [1], risk assessment [2]. Most of the works based on ATT&CK matrices concentrate on building relationship between self-defined model and ATT&CK matrices. While in this work, we discuss whether there is attack traffic generated when implement each tactic, further if it is possible to record the attack traffic. And some typical tools are introduced for achieving each tactic.