Working with the MITRE ATT&CK framework
Maybe it's not a completely fair statement, but we will post it here regardless: MITRE ATT&CK lets you think from the attacker's perspective when it comes to security. The strength of this framework is that anyone can contribute to it. It doesn't really describe the actual vulnerabilities in systems, but more the techniques attackers could use to exploit these vulnerabilities. MITRE ATT&CK uses a matrix with 14 attack tactics. Next, it divides these tactics across major platforms or technologies, including cloud and containers. In the cloud, there's a subdivision for Azure, AWS, and GCP.
Tip
The full MITRE ATT&CK framework can be found at https://attack.mitre.org/. However, it is recommended to follow MITRE on Twitter as well at @MITREattack
. The matrix is open source, so a lively community is contributing to the tactics and techniques that are collected in the framework. MITRE invites people to join...