Resources for SOC operations
The following study resources are available for improving SOC capabilities, such as advanced threat-hunting procedures, incident response tactics, and adopting a strategic Zero Trust approach to implementing technology.
MITRE ATT&CK® framework
ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge. The MITRE ATT&CK® framework was developed to ensure documentation of these behaviors and that they are applicable to real environments. The framework provides a common taxonomy to promote comparison across different types of adversary groups using the same terminology.
The MITRE ATT&CK® framework contains four common use cases:
- Detections and Analytics
- Threat Intelligence
- Adversary Emulation and Red Teaming
- Assessment and Engineering
This framework has been embedded across Azure Sentinel to ensure ease of reference. To learn more about this framework, and to gain access to relevant...