MITRE ATT&CK®
ATT&CK is a globally accessible knowledge base of adversary strategies and procedures based on real-world observations, developed and maintained by the MITRE Corporation with the help of the global cybersecurity community.
We have already used this framework throughout this book, but I still recommend reading the following white paper, MITRE ATT&CK®: Design and Philosophy (https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf).
There are 14 adversary tactics described in MITRE ATT&CK®:
- Reconnaissance
- Resource development
- Initial access
- Execution
- Persistence
- Privilege escalation
- Defense evasion
- Credential access
- Discovery
- Lateral movement
- Collection
- Command and control
- Exfiltration
- Impact
Let's look at each tactic separately.
Reconnaissance
The adversary collects information about the target. As discussed previously, threat actors may use...