Cyber Security Research Hub

MITRE ATT&CK: The Threat Hunting

Nowadays, people are becoming more and more dependent on the digital world.
And with this process, people are becoming more vulnerable to cyber criminals.
In August of 2016, Cybersecurity Ventures predicted that cybercrime would cost
the world $6 trillion annually by 2021, up from $3 trillion in 2015. So, to protect
our data from the cyber world, cyber security is important and MITRE ATT&CK
plays a key role here.

Let’s talk about MITRE first. MITRE is a government funded non-profit research
organization based in Bedford, Massachusetts and McLean, Virginia. It has been
involved in a range of commercial and top-secret projects for a range of agencies.
MITRE has a substantial cyber security practice funded by The National Institute
of Standards and Technology (NIST).

With the advancement of cyber risk, people just can’t rely on the traditional
antivirus softwires and firewalls. Keeping an accurate and complete record of the
threats, vulnerabilities, and attack methods that apply to enterprise application,
computing, and networking infrastructures is one of the most useful methods in
current cybersecurity risk management. Hence, in 2013, MITRE came up with
MITRE ATT&CK Framework where researchers emulated both adversary and
defender behavior in an effort to improve post-compromise detection of threats
through telemetry sensing and behavioral analysis. However, this framework was
released to the public for free in 2015.

ATT&CK is an acronym for Adversarial Tactics, Techniques, and Common
Knowledge. The framework consists of 14 tactics categories consisting of
“technical objectives” of an adversary.

MITRE ATT&CK now has three iterations:

Figure 02: Iterations of ATT&CK

ATT&CK for Enterprise focuses on adversarial behavior in windows, mac, linux
and cloud environment. While ATT&CK for mobile focuses on adversarial
behavior on iOS and android and ATT&CK for ICS describes the actions of
adversary may take while operating within an ICS network.

3

ATT&CK provides the framework for describing opponent TTPs and behavior.
This framework enables us to compare enemy groups to themselves, other groups,
and defenders in a way that overcomes some of the attacks. Analysts and
defenders can both use ATT&CK to organize their data. Analysts can organize
intelligence about enemy activity, while defenders may organize data about what
behavior they can detect and mitigate. They can develop threat-based awareness
by superimposing information from two or more groups. Let us visualize this
using the ATT&CK Navigator for Enterprise.

Figure 03: APT3 VS APT29

Here in figure 03, in the header row, we have the 14 different tactics mentioned
earlier.
• Reconnaissance
• Resource Development
• Initial Access
• Execution
• Persistence
• Privilege Escalation
• Defense Evasion
• Credential Access
• Discovery
• Lateral Movement
• Collection
• Command and Control
• Exfiltration
• Impact

And under these tactics, we have different techniques and sub-techniques. The
techniques used only by APT3 are marked in red, the techniques used only by
APT29 are marked in yellow and the techniques used only by both are marked in
green.

There is a saying, prevention is better than cure. Structuring TTPs gives us a
way to count them, which helps make adversaries and defenses measurable.
And MITRE ATT&CK is helping us beautifully to do so. So why not stay a step
ahead from the attack.

Leave a Reply

Your email address will not be published. Required fields are marked *