Traditional Defenders
Defend a list of assets
Manage incidents
Minimize risks by keeping incidents secret
View pentest results as a report card
Think about stopping attacks
Modern Defenders
Defend a graph of assets
Manage adversaries
Maximize learning by sharing incidents with
trusted outside peers
View pentest results as an input
They think about increasing attacker
requirements
Promoting
Community
Organized
Knowledge
Executable
Know-how
Repeatable
Analysis
Li
lithium
Na
sodium
K
potassium
Rb
rubidium
Cs
caesium
Fr
francium
Be
beryllium
Mg
magnesium
Ca
calcium
Sr
strontium
Ba
barium
Ra
radium
Sc
scandium
Y
yttrium
Ti
titanium
Zr
zirconium
Hf
hafnium
V
vanadium
Nb
niobium
Cr
chromium
Mo
molybdenum
Mn
manganese
Tc
technetium
Fe
iron
Ru
ruthenium
Co
cobalt
Rh
rhodium
Ni
nickel
Pd
palladium
Cu
copper
Ag
silver
Zn
zinc
Cd
cadminium
Ta
tantalum
W
tungsten
Re
rhenium
Os
osminium
Ir
iridium
Pt
platinum
Au
gold
Hg
mercury
B
boron
Si
silicon
Ge
geramanium
As
arsenic
Sb
antimoney
Te
tellurium
Po
polonium
H
hydrogen
C
carbon
P
phosphorous
N
nitrogen
O
oxygen
S
sulphur
Se
selenium
Al
aluminium
Ga
galium
In
indium
Tl
thallium
Sn
tin
Pb
lead
Bi
bismuth
F
fluorine
Cl
chlorine
Br
bromine
I
iodine
At
astatine
He
helium
Ne
neon
Ar
argon
Kr
krypton
Xe
xenon
Rn
radon
1 2
3
11
19
37
55
La
lanthanum
Ce
cerium
Pr
praseodymium
Pm
promethium
Sm
samarium
Eu
europium
Gd
gadolinium
Tb
terbium
Dy
dysprosium
Ho
holmium
Er
erbium
Tm
thulium
Yb
ytterbium
Lu
lutetium
Nd
neodymium
Ac
actinium
Pa
protactinium
U
uranium
Np
neptunium
Pu
plutonium
Am
americium
Cm
curium
Bk
berkelium
Cf
californium
Es
einsteinium
Fm
fermium
Md
mendelevium
Th
thorium
No
nobelium
Lr
lawrencium
87
4
12
20
38
56
88
39
2221
40
72
23
41
73
24
42
74
25
43
74
26
44
76
27
45
77
28
46
78
29
47
79
30
48
80
31
49
81
5
13
32
50
82
6
14
33
51
83
7
15
34
52
84
8
16
35
53
85
9
17
36
54
86
10
18
57 58 59 60 61 62 63 64 65 66 67 68 69 70 71
89 90 91 92 93 94 95 96 97 98 99 100 101 102 103
Fr
francium
Ra
radium
Mt
meitnerium
Ds
darmstadtium
Rg
goentgenium
Cn
copernicium
Lv
livermorium
Nh
nihonium
Fl
flerovium
Mc
moscovium
Ts
tennessine
Og
oganesson
Rf
rutherfordium
Db
dubnium
Sg
seaborgium
Bh
bohrium
Hs
hassium
104 105 106 107 108 109 110 111 113 114 115 116 117 118112
Over 110 groups known to us
Over 70 full-fledged Activity
Groups
Activity Groups
https://cyberwardog.blogspot.com/2017/07/how-hot-is-your-hunt-team.html.
https://github.com/redcanaryco/atomic-red-team
“Githubification” of Infosec
Analysis
Threat Group
Technique Database
Detection Definitions
Detection Product
@JohnLaTwC
MITRE ATT&CKcon 2018 Keynote: Advancing Infosec, John Lambert, Microsoft

MITRE ATT&CKcon 2018 Keynote: Advancing Infosec, John Lambert, Microsoft