The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework has become one of the most widely adopted tools in the field of Cyber Threat Intelligence (CTI). Originally developed by the MITRE Corporation to catalogue the observed behaviors of adversaries in post-compromise environments, ATT&CK provides a comprehensive, structured repository of tactics, techniques, and procedures (TTPs) based on real-world incidents. It was not initially designed for threat hunting or detection alone—it was a reference model to capture how adversaries operate, particularly how they persist and move laterally once inside a network.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

The MITRE ATT&CK Framework in CTI

  • Crawford Thomas

摘要

The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework has become one of the most widely adopted tools in the field of Cyber Threat Intelligence (CTI). Originally developed by the MITRE Corporation to catalogue the observed behaviors of adversaries in post-compromise environments, ATT&CK provides a comprehensive, structured repository of tactics, techniques, and procedures (TTPs) based on real-world incidents. It was not initially designed for threat hunting or detection alone—it was a reference model to capture how adversaries operate, particularly how they persist and move laterally once inside a network.