MITRE ATT&CK
MITRE ATT&CK is a globally established framework for describing the attack tactics, techniques and procedures of real threat actors. It helps security teams to understand attacks systematically and to assess protective measures better. The framework is particularly valuable because it creates a common language for vendors, analysts, incident response teams and decision-makers. Organizations use MITRE ATT&CK for detection engineering, gap analyses, purple teaming and the evaluation of security solutions, among other things.
Instead of looking at isolated events, it becomes visible at which point of an attack chain an attacker is moving. This facilitates both prioritization and communication. Since the framework is continuously developed, it remains closely oriented to real attacker techniques; the broader context of the knowledge base is described in the entry MITRE Framework.
In addition, MITRE ATT&CK is also used as the basis for independent tests and evaluations of security solutions, for example in the so-called MITRE ATT&CK Evaluations. These practical tests simulate real attack scenarios and examine how well different security tools detect and present attacks. Such results help organizations to compare the effectiveness of security technologies more objectively and to make well-founded investment decisions. Operationally, automated attack detection helps to separate relevant signals from less critical events more quickly.
See also: Threat Intelligence and Threat Hunting.