Overview of the various ATT&CK models
As mentioned, the MITRE ATT&CK Framework has evolved to include multiple different models based on operating systems and environments. Currently, these are the following models:
- Windows
- macOS
- Linux
- Network
- Containers
- Office 365
- Azure AD
- Google Workspaces
- Software as a Service (SaaS)
- Infrastructure as a Service (IaaS)
- Android
- iOS
- Industrial Control System (ICS)
These models are meant to be used in a pick-and-choose manner so that, as an end user, you are able to select the techniques and matrices that apply to your environment and mix and match options as needed. We’ll take a deep-dive into quite a few of the different models by looking at the types of techniques and comparison of the different models through future chapters. However, from a basic point of view, they are all initially based on a version of the Cyber Kill Chain framework. The Cyber Kill Chain framework...