MITRE ATT&CK mapping
We cannot begin threat hunting by assuming everyone in the world is after us. We need a targeted threat actor or threat campaign-based approach. This is where both Wazuh and MITRE ATT&CK become helpful. Wazuh can collect and trigger any alerts, but for threat hunting, we need to focus on relevant and high-priority threats to our business and need to map this to our Wazuh rules. The MITRE ATT&CK framework helps threat hunters to focus on these kinds of threats and Wazuh allows us to map each of the techniques of those threat actors to Wazuh rules. As a result, threat hunters can hone their focus and save tremendous amounts of time. In this section, we will cover the following topics:
- What is MITRE ATT&CK?
- The ATT&CK framework
- Prioritizing the adversary’s techniques
- MITRE ATT&CK mapping
What is MITRE ATT&CK?
The MITRE ATT&CK framework was developed by the MITRE Corporation to provide a uniform taxonomy...