Introduction to the MITRE ATT&CK Framework
51mIntermediate2023-09-01
Authors

Prashant Pandey
Penetration Tester at Birlasoft
Course details
With the meteoric rise in cyberattacks, CISOs and company work to fend off these attacks from a variety of sources. Modern cyber attacks are very coordinated and complex in their execution strategies. MITRE ATT&CK framework was created as a tool to understand the anatomy of modern cyber attacks and map out the thought process of hackers. In this course, CISSP certified penetration tester Prashant Pandey provides you with a solid understanding of what this framework is all about and how to add it to your daily activities. After a thorough overview of the MITRE ATT&CK framework, explore the many phases of a cyberattack. Learn how to incorporate MITRE ATT&CK into your security program, threat intelligence program, and security tools. Go over best practices for using the framework, and then dive into a series of case studies to help you understand ways to leverage what you’ve learned.
Skills covered
Introduction toIncident ResponseCybersecurity
Concepts
Introduction
- Course introduction
- What you should know
Introduction to MITRE ATT&CK
- What is MITRE ATT&CK
- Why MITRE ATT&CK
- Overview of the framework - Part 1
- Overview of the framework - Part 2
Understanding the Phases of Attack
- Reconnaissance
- Resource development
- Initial access
- Execution
- Persistence
- Privilege escalation
- Defense evasion
- Lateral movement
Implementing MITRE ATT&CK in Practice
- Incorporating MITRE ATT&CK into your security program
- Using Att&ck to equip threat intelligence
- Integrating MITRE ATT&CK with security tools
- Best practices for using the framework
Case Studies
- ATT&CK Navigator
- Case study 1
- Case study 2
- Case study 3
Conclusion
- Next steps for continuing your education