Chapter 6: Understanding the Cyber Kill Chain and the MITRE ATT&CK Framework
Cyber-attacks are constantly evolving and becoming more sophisticated due to several reasons, particularly because knowledge is more widely obtainable. There is an entire arsenal of offensive tools available on the internet; these factors significantly reduce the cost of launching a cyberattack.
An incident response professional needs to understand the possible paths an attacker can follow and the tools they could use in a cyberattack. Fortunately, there are handy reference frameworks that detail the actions of adversaries and their tools.
In this chapter, you will learn about some frameworks to analyze attackers' behaviors and the best way to use them when responding to a cybersecurity incident, covering the following topics:
- Introducing the Cyber Kill Chain framework
- Understanding MITRE ATT&CK
- Discovering and containing malicious behaviors