Resources for SOC operations
The following study resources are available for improving SOC capabilities, such as advanced threat-hunting procedures, incident response tactics, and adopting a strategic zero-trust approach to implementing technology.
MITRE ATT&CK® framework
The MITRE ATT&CK framework stands for Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK). The MITRE ATT&CK framework was developed to ensure documentation of these behaviors and that they are applicable to real environments. The framework provides a common taxonomy to promote comparison across different types of adversary groups using the same terminology.
The MITRE ATT&CK® framework contains four common use cases:
- Detection and Analytics
- Threat Intelligence
- Adversary Emulation and Red Teaming
- Assessment and Engineering
This framework has been embedded across Microsoft Sentinel to ensure ease of reference. To learn more about this framework...