Operationalizing
ATT&CK
Bryson Bort
SCYTHE Founder & CEO
ICS Village Co-Founder
SESSION ID:
2
PERIODICTABLE
POTENTIAL
ATTACKSPACE
3
Communications
Behaviors
POTENTIAL
ATTACKSPACE
4
C2,Lateral,Exfil
Persistence, Privileges,
Credentials, Collection,
Discovery
SESSION ID:
5
GENERIC vsBRAND NAME
• No CTI available
• Behavior versus Technical
Binary Padding
BRONZE BUTLER 0’s appended to inflate file size
LEVIATHAN Garbage/randomized characters

MITRE ATT&CKcon 2018: Operationalizing ATT&CK, Bryson Bort, SCYTHE