Further reading
If you want to learn more about the MITRE ATT&CK data sources outside of what we briefly mentioned in the first section of this chapter, there are several blog posts by MITRE themself that specify the goals of the project and how the schema for data sources was created. Check them out here:
- https://medium.com/mitre-attack/defining-attack-data-sources-part-i-4c39e581454f
- https://medium.com/mitre-attack/defining-attack-data-sources-part-ii-1fc98738ba5b
- https://medium.com/mitre-attack/dissecting-a-detection-part-1-19fd8f00266c
- https://medium.com/mitre-engenuity/researching-data-sources-to-build-a-foundation-for-detections-e9369a8dbb23
We also recommend diving into the MITRE ATT&CK data sources knowledge base to explore different data sources available for investigating certain techniques.