MITRE ATT&CK® is a knowledge base of adversary tactics and techniques based on real world observations published by MITRE. This knowledge base can be used as the foundation for understanding the Cyber Attack patterns.
The MITRE Attack Matrices covers the following categories
- Enterprise
- PRE
- Windows
- MacOS
- Linux
- Cloud
- Containers
- ESXi
- Mobile
- ICS (Industrial Control Systems)
The MITRE Attack chain has 14 Tactics that will be executed in order by an attacker. Each Tactics has different techniques depending on the motive of the attack. By analyzing events, alerts, logs from various devices in the organization, we can identify the pattern of an attack. If we can detect an attack early in the kill chain like in the reconnaissance or initial access, the attack objective like stealing data or service going down can be prevented completely without any impact to the target.
- Reconnaissance – Gathering information about the target.
- Resource – Developing resources to exploit the target.
- Initial Access – Gaining the initial access of the target.
- Execution – Executing malicious code on the target system.
- Execution Persistence – Maintaining access to the compromised target system.
- Privilege Escalation – Getting higher privilege access on the compromised target system.
- Defense Evasion – Bypassing security controls on the compromised target system.
- Credential Access – Getting credentials of the compromised target system.
- Discovery – Discover information from the compromised target system.
- Lateral Movement – Moving across network and infrastructure from the compromised target system
- Collection – Gathering data from compromised target system.
- Command and Control – Establishing command & and control channel with the compromised target system.
- Exfiltration – Steal data from compromised target system.
- Impact – Perform and complete the attack objective on compromised target system.