MITRE framework

The MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework is a comprehensive knowledge base that

  • provides insights into the tactics, techniques, and procedures (TTPs) distributed by threat actors aiming to harm systems,

  • incorporates groups to refer to threat groups, activity groups, or threat actors based on the set of tactics and techniques they employ, and

  • is compiled as matrices, with each matrix representing an operating system or a particular platform.

Each technique includes information about execution, procedures, defenses, detections, and real-world examples.

Note

See https://attack.MITRE.org for additional information about MITRE ATT&CK.

The management center uses the MITRE ATT&CK Framework to enhance threat detection and response, incorporating these capabilities:

  • Intrusion events include TTPs, allowing administrators to manage traffic with greater granularity by grouping rules according to vulnerability type, target system, or threat category.

  • Select malware events use TTPs, enhancing the ability to detect and respond to threats.