MITRE framework
The MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework is a comprehensive knowledge base that
-
provides insights into the tactics, techniques, and procedures (TTPs) distributed by threat actors aiming to harm systems,
-
incorporates groups to refer to threat groups, activity groups, or threat actors based on the set of tactics and techniques they employ, and
-
is compiled as matrices, with each matrix representing an operating system or a particular platform.
Each technique includes information about execution, procedures, defenses, detections, and real-world examples.
Note | See https://attack.MITRE.org for additional information about MITRE ATT&CK. |
The management center uses the MITRE ATT&CK Framework to enhance threat detection and response, incorporating these capabilities:
-
Intrusion events include TTPs, allowing administrators to manage traffic with greater granularity by grouping rules according to vulnerability type, target system, or threat category.
-
Select malware events use TTPs, enhancing the ability to detect and respond to threats.