Advertisement
Advertisement

More Related Content

Advertisement
Advertisement

State of the ATT&CK May 2023

  1. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. State of the ATT&CK Adam Pennington (@_whatshisface) Charissa Miller
  2. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. CLOUD DEFENSIVE COVERAGE LINUX ICS Assets Mobile Data Sources Ransomware Campaigns ATT&Ckcon 4.0 Structured Detections Cross Domain Mappings 01: ATT&CK Roadmap Overview 02: ATT&CK for Mobile 03: ATT&CK for ICS 04: ATT&CK for Enterprise 05: ATT&CK’s Software Agenda
  3. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK’s Current Three Domains Enterprise It’s just Mobile ICS
  4. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Mobile and ICS need ongoing content adjustments for parity with Enterprise ATT&CK is an intelligence- driven knowledge base Team manages many tools for updating/publishing ATT&CK §Adversaries evolve and use new behaviors §New defender visibility leads to behaviors being reported §New adversaries appear § Us/CTID create the tools to maintain ATT&CK’s STIX format § All open source, and most widely used ATT&CK Maintenance
  5. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. April October ATT&CKcon 4.0: Oct 24-25 We’re Here Release v14 Release v13 ATT&CK 2023 Releases
  6. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK 2023 Roadmap © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION
  7. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Drive-By Compromise Command and Scripting Interpreter Boot or Logon Initialization Scripts Abuse Elevation Control Mechanism Download New Code at Runtime Access Notifications File and Directory Discovery Exploitation of Remote Services Access Notifications Application Layer Protocol Exfiltration Over Alternative Protocol Account Access Removal Lockscreen Bypass Native API Compromise Application Executable Exploitation for Privilege Escalation Execution Guardrails Clipboard Data Location Tracking Replication Through Removable Media Adversary-in-the- Middle Call Control Exfiltration Over C2 Channel Call Control Replication Through Removable Media Scheduled Task/Job Compromise Client Software Binary Process Injection Foreground Persistence Credentials from Password Store Network Service Scanning Archive Collected Data Dynamic Resolution Data Encrypted for Impact Supply Chain Compromise Event Triggered Execution Hide Artifacts Input Capture Process Discovery Audio Capture Encrypted Channel Data Manipulation Foreground Persistence Hooking Steal Application Access Token Software Discovery Call Control Ingress Tool Transfer Endpoint Denial of Service Hijack Execution Flow Impair Defenses System Information Discovery Clipboard Data Non-Standard Port Generate Traffic from Victim Scheduled Task/Job Indicator Removal on Host System Network Configuration Discovery Data from Local System Out of Band Data Input Injection Input Injection System Network Connections Discovery Input Capture Web Service Network Denial of Service Native API Location Tracking SMS Control Obfuscated Files or Information Protected User Data Process Injection Screen Capture Proxy Through Victim Stored Application Data Subvert Trust Controls Video Capture Virtualization/Sandbox Evasion © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION ATT&CK for Mobile Mobile-specific Data Sources Mobile Security Community Collaboration Structured Detections Expanding Sub + Multi-Domain Techniques
  8. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK for ICS Enhancing Cross-domain mappings Addressing Domain Overlaps & Integration Revamping ICS Assets
  9. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK for Enterprise Mac Linux Cloud Containers Windows Network
  10. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Defensive Coverage Detection-related Collection Effort More Directly Usable Guidance for Defenders In-depth look at data collection analyzation, & technique identification Evolving Mitigations Researching & Adding New Preventions Crafting Additional Ways to Prevent Technique Success Overall Goal: Working to enhance offerings for lower-resourced defenders
  11. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Defensive Coverage Example
  12. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Expanding Linux § Adjustments to technique scope + new sub-techniques and updated procedures. § Enhanced account for activity within on-premise Linux servers & broader Linux-based spaces adversaries have been abusing. § Collaboration across Linux security community. Increased Linux Representation within ATT&CK
  13. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Utilizing Cloud & Growing Campaigns © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION 14 Cloud Assessing How Tactics Change For Cloud Environments In-depth look at data collection analyzation, & technique identification Campaigns Significant APT Campaigns Criminal/Ransomware Campaigns
  14. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK’s Software
  15. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK Website Search Optimizations Search on attack.mitre.org State of Search (initial) Load Time © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3.
  16. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK Website Search Optimizations Search on attack.mitre.org State of Search (refactored) Load Time © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3.
  17. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK Navigator SVG Exporter Image orientation and size
  18. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK Navigator SVG Exporter Custom font size Dynamic sizing
  19. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK Navigator SVG Exporter Custom font size Dynamic sizing Consistent sizing
  20. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CK Navigator SVG Exporter (Coming Soon) Custom font size
  21. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Diff STIX Detailed version changelog
  22. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. Diff STIX Machine-readable JSON file
  23. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. MitreAttackData Library CTI Usage Document
  24. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. MitreAttackData Library CTI Usage Document
  25. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. MitreAttackData Library ReadTheDocs: https://mitreattack-python.readthedocs.io/
  26. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. GitHub Links Website: https://github.com/mitre-attack/attack-website Navigator: https://github.com/mitre-attack/attack-navigator mitreattack-python: https://github.com/mitre-attack/mitreattack-python
  27. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. ATT&CKcon 4.0 In-person and virtual October 24-25, 2023 MITRE campus in McLean, VA CFP Open at https://bit.ly/ATTcon © 2023 Watch our Twitter and LinkedIn for additional announcements
  28. © 2023 THE MITRE CORPORATION. ALL RIGHTS RESERVED. APPROVED FOR PUBLIC RELEASE. DISTRIBUTION UNLIMITED 23-00696-3. https://attack.mitre.org attack@mitre.org @mitreattack ATT&CK Slack: https://bit.ly/ATTs Charissa Miller Adam Pennington/@_whatshisface
Advertisement