MITRE ATT&CK
MITRE’s Adversarial Tactics, Techniques and Common Knowledge (ATT&CK™) is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target. ATT&CK is useful for understanding security risk against known adversary behavior, for planning security improvements, and verifying defenses work as expected.
Reference: ATTCK
This part of the OSSEM project focuses on the documentation of ATT&CK data sources suggested or associated with techniques defined in the Enterprise Matrix. In addition, here is where ATT&CK data sources will be mapped with specific sub data sources defined in the Detection Data Model with the main goal of creating a link between ATT&CK data sources and event logs.
Data source (Process Monitoring) mapped to specific event logs example:
Mapping event logs to ATT&CK data sources
The methodology follows the next steps:
- Exploring ATT&CK data sources
- Documenting event logs related to ATT&CK data sources
- Develop a data model
- Map event logs to ATT&CK data sources
Resources:
