Summary
In this chapter, we learned about two frameworks that we can use to respond to cybersecurity incidents and how to apply them.
The Cyber Kill Chain focuses on describing the different phases in which an attack occurs to identify and prevent security breaches.
On the other hand, MITRE ATT&CK helps us identify different tactics, techniques, and tools that an attacker could use in an attack. Thus, the ATT&CK Matrix gives us the advantage of visualizing in a much broader way the possible previous or subsequent actions of an attacker to contain or investigate the details of an attack.
In the next chapter, you will perform several hands-on exercises where you can apply what you learned in the modules of this section.
Through a practical scenario, you will model a potential threat for your organization. Finally, you will identify the IoCs and IoAs in a cybersecurity incident to contain the attack using the CTI provided and create the matrices in the ATT&CK...