Understanding the MITRE ATT&CK framework
Depending on the scope, pentesting can become a large and cumbersome engagement that may have a severe impact on the quality of the pentest. When pentesting, we want to be able to provide both creative and real-world scenarios that we can use to engage our clients and customer networks and systems. During the pentest, we call our actions and methods TTPs – which stands for the following:
- Tactics
- Techniques
- Procedures
These three words make up a large portion of how we pentest; however, if we don't really understand what they stand for, then we really cannot make use of them. To better understand them, we can apply them to an open knowledge base, known as the MITRE ATT&CK framework, and discuss these terms by applying them to real-world scenarios.
The MITRE ATT&CK framework allows us to develop our own methods and actions in the form of TTPs and fulfill the promise of quality engagement to...