The MITRE ATT&CK Framework in CTI
摘要
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework has become one of the most widely adopted tools in the field of Cyber Threat Intelligence (CTI). Originally developed by the MITRE Corporation to catalogue the observed behaviors of adversaries in post-compromise environments, ATT&CK provides a comprehensive, structured repository of tactics, techniques, and procedures (TTPs) based on real-world incidents. It was not initially designed for threat hunting or detection alone—it was a reference model to capture how adversaries operate, particularly how they persist and move laterally once inside a network.