Talk With an Expert

Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework

Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework (PDF, 3.99MB)Published: 17 Jul, 2020
Created by
John Hubbard
John Hubbard

Through the ATT&CK framework, MITRE has generated a gold mine of information about the most important tactics and techniques used by attackers and how the blue team can detect and prevent these actions. Blocking atomic attack indicators such as domain names and IP addresses might work in the short term, but understanding the higher-level tactics in ATT&CK helps the blue team identify and anticipate attacker activity at a higher level of abstraction. In this white paper, SANS author and dedicated blue team member John Hubbard explores how ATT&CK slows attackers down and gives defenders a fighting chance.

Meet the expert

John Hubbard
John Hubbard

John Hubbard

Senior Instructor

John redefined modern SOC operations by engineering globally adopted blue team strategies and co-creating the GSOC cert. Through the Blueprint podcast and SANS leadership, he’s unified thousands of defenders around real-world detection tactics.

Read more about John Hubbard