MITRE-ATT&CK framework overview
Summarize
Summary of MITRE-ATT&CK framework overview
The MITRE-ATT&CK framework is a comprehensive knowledge base of adversarial tactics, techniques, and procedures (TTPs) used in cyberattacks. It helps organizations develop targeted threat models and methodologies by documenting adversary behaviors across different stages of an attack. This framework supports the cyberthreat intelligence community in quickly identifying threats and coordinating effective responses.
Show less
Integration with Security Operations
Within ServiceNow Security Operations, MITRE-ATT&CK data is ingested through a pre-loaded TAXII client and integrated with Security Information and Event Manager (SIEM) systems. This integration enriches security incidents with relevant TTPs and enables automated searches for indicators of compromise (IoCs) linked to incidents. When IoCs are found, Threat Intelligence can send them to third-party tools such as EDR, Sandbox, or TIP for deeper analysis. MITRE-ATT&CK also provides CVE context, allowing teams to assess if critical assets are at risk via Vulnerability Response.
MITRE-ATT&CK Matrices, Tactics, and Techniques
The framework’s core is a matrix that maps adversary tactics and techniques, illustrating the attacker’s objectives and methods at each incident stage. Understanding this sequence helps security teams anticipate attacker moves and disrupt the kill chain. The primary matrices include:
- Enterprise ATT&CK: Covers adversary behaviors in enterprise networks and cloud environments (including the deprecated Pre ATT&CK matrix).
- ICS ATT&CK: Focuses on adversary actions within Industrial Control Systems networks.
- Mobile ATT&CK: Details adversary tactics targeting mobile devices.
Tactics describe the adversary’s objectives (the "why"), while techniques describe how these objectives are achieved. Techniques can relate to multiple tactics, offering a versatile understanding of adversary behavior.
Intent-Based Incident Response
By adopting an intent-based response approach, your security team can use a dynamic kill chain framework to correlate incidents and identify broader attack patterns. This approach enhances prediction of attacker behavior, enabling efficient allocation of security resources. In ServiceNow Security Incident Response, incidents are managed by focusing on IoCs, and integration with MITRE-ATT&CK treats incidents as parts of a larger attack campaign.
Benefits of Using MITRE-ATT&CK in Security Operations
- Empowers security analysts with detailed TTPs for improved incident analysis and response.
- Enables automation of incident workflows using playbooks aligned with the MITRE-ATT&CK framework.
- Helps prioritize IoCs and threat hunting efforts based on MITRE-ATT&CK insights.
- Provides a high-level view of your organization’s security posture through the lens of MITRE-ATT&CK.
Administration and Usage in ServiceNow
You can configure, map data sources, monitor detection coverage, and maintain the MITRE-ATT&CK repository within the ServiceNow AI Platform. Leveraging the framework across Threat Intelligence and Security Incident Response modules enhances your organization’s ability to detect and analyze threats efficiently.
The MITRE-ATT&CK framework is a knowledge base of common tactics, techniques, and procedures (TTP) that your organization can access to develop specific threat models and methodologies against cyberattacks.
Overview
The MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework documents and tracks various adversarial techniques that are used during different stages of a cyberattack.
By using the MITRE-ATT&CK framework's knowledge base, the cyberthreat intelligence community can quickly identify threats and coordinate cyberattack responses.
MITRE-ATT&CK and Security Operations
See the following diagram to learn how the MITRE-ATT&CK information flows with Security Operations applications.
- The pre-loaded TAXII client connects to the TAXII server to ingest the data collections to Threat Intelligence.
- Existing Security Information and Event Manager (SIEM) integrations ingest their threat data (alerts and events), with relevant TTPs and are associated with security incidents.
- When an IoC is associated to a security incident, Threat Intelligence automatically searches threat feeds for relevant information and sends IoCs to third-party sources such as EDR, Sandbox, or TIP for additional analysis.
- If any third-party source contains the MITRE-ATT&CK information, then Threat Intelligence extracts the technique information and enriches the data in the Threat Intelligence repository for correlation and analysis.
- MITRE-ATT&CK also shares CVE context information for each technique. Your security team can review the exploited techniques in Vulnerability Response to determine if your business-critical assets are threatened.
MITRE-ATT&CK matrices, tactics, and techniques
- Enterprise ATT&CK: Describes the behaviors and actions that an adversary takes to
compromise and operate in an enterprise network and cloud.Note:The Pre ATT&CK matrix has been deprecated by MITRE and is merged with the Enterprise matrix.
- ICS ATT&CK: Describes the actions that an adversary takes while operating within an Industrial Control Systems (ICS) network.
- Mobile ATT&CK: Describes the adversary behaviors and actions that focus on mobile devices.
Tactics represent the why of an ATT&CK technique. It is the adversary’s tactical objective for performing an action.
Techniques represent how an adversary achieves a tactical objective by performing an action.
Techniques may be associated with more than one tactic. For example, Access Token Manipulation is used by an adversary to achieve either the tactic of Privilege Escalation or Defense Evasion.
Using an intent-based approach for incident responses
An intent-based response uses a dynamic and contextual kill chain framework that can help your organization to correlate security incidents and to identify a large scope of attacks. Your security team can use an intent-based response to understand how the organization is being attacked and what the attacker might do next. This type of response enables you to predict an attacker's behavior so that you can focus your resources effectively.
Using Security Incident Response, your security team can manage the life cycle of each security incident from analysis to containment by focusing on indicators of compromise (IOCs) like IP addresses, file hashes, and domains.
By integrating Security Incident Response with the MITRE-ATT&CK framework, security incidents are handled as links in a larger enterprise-wide attack.
How your organization can benefit from MITRE-ATT&CK in Security Operations
Using the MITRE-ATT&CK framework can help your organization do the following:
- Equip security analysts with MITRE-ATT&CK tactics, techniques, and procedures (TTPs) to better analyze and respond to security incidents.
- Automate the incident workflows using the playbook for detecting and containing threats in the context of the MITRE-ATT&CK framework.
- Prioritize indicators of compromise and threat hunting with MITRE-ATT&CK information.
- Understand the high-level security posture of your organization in the context of the MITRE-ATT&CK framework.