MITRE ATT&CK Framework for Threat Hunting

No ratings

Presented at BSidesBristol 2019 by

Cyber Operations needs to be continually improving to stop attackers. The attackers are developing new tools, techniques and processes (TTPS) all the time to circumvent our defences. Threat Intelligence led security is the first stage of delivering a proactive and mature service. It enables us to look for known malicious TTPs in our environment. Threat Hunting is looking for the unknown, something you have not seen before. It is difficult to do as it requires; research, writing detections, data capture and lots of trawling through false positives. In most companies this is done by analysts on top of their day job. The Mitre ATT&CK framework provides 220+ of the most common techniques used to compromise environments. Each Technique contains information on how to detect and mitigate them and provides real world examples on how known actors are using them. This decreases the effort and experience the analyst needs to perform a threat hunting investigation. We will cover in our talk; An overview of the Mitre ATT&CK framework, how to use it for Threat hunting, what hurdles you need to jump, what tooling you need to build and what benefits you get from it.