Group Purchasing
Group Purchasing

Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework

Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework (PDF, 3.99MB)Published: 17 Jul, 2020
Created by:

The Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework white paper, published by SANS Institute in July 2020, examines how security operations teams can use the MITRE ATT&CK knowledge base to build, measure, and continuously improve a threat-informed defense strategy. Written by SANS certified instructor John Hubbard, the paper covers the structure of the ATT&CK matrices, methods for threat intelligence mapping, data source gap analysis, and analytic testing approaches for security operations centers (SOCs).

Key concepts:

  • MITRE ATT&CK began in 2015 as a globally accessible knowledge base of adversary tactics and techniques drawn from real-world observations
  • ATT&CK is organized into four matrices: Enterprise, Mobile, ICS, and PRE-ATT&CK, each covering a different attack surface or intrusion stage
  • The Enterprise matrix covers post-exploitation techniques across Windows, macOS, and Linux, as well as cloud platforms like AWS, Azure, and Google Cloud
  • Each technique carries a unique four-digit identifier (T####) along with associated tactics, platforms, permissions, data sources, and mitigations
  • A 2020 restructuring introduced sub-techniques, splitting parent techniques into more granular child techniques for more precise detection mapping
  • MITRE's Cyber Analytics Repository (CAR) and the open source BZAR project provide prewritten detection logic for many ATT&CK techniques
  • ATT&CK Navigator lets teams visualize technique coverage using colored, scored layers, and combine multiple layers to find overlapping techniques used by different threat groups
  • MITRE's TRAM tool applies natural language processing to automatically flag ATT&CK technique references in threat intelligence reports
  • A simple four-level coverage scale (None, Partial, Most, Complete) helps teams track detection maturity without over-engineering the measurement system
  • Testing capability should progress through atomic testing, purple teaming, red teaming, and adversary emulation, roughly in order of increasing realism
  • Organizations are advised to schedule purple and red team assessments quarterly or semi-annually to validate detection capability over time
  • Network-based data sources (NetFlow, packet capture) and host-based data sources (EDR, process logs) are complementary, each covering blind spots the other misses

The paper's throughline is that ATT&CK's value comes from pairing outward-facing threat intelligence with an inward-facing assessment of detection gaps, then closing the loop through repeated, increasingly realistic testing. Teams that treat ATT&CK as a static checklist tend to stall; teams that track their technique coverage over time and retest continuously are better positioned to demonstrate measurable improvement in defensive capability to stakeholders. This is a practitioner-focused framework paper rather than an empirical survey, authored by SANS instructor John Hubbard and sponsored by Anomali, AttackIQ, Corelight, CyberProof, ExtraHop, Infoblox, LogRhythm, RSA, and ThreatQuotient.

FAQ

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observed attacks, started by MITRE in 2015 to help security teams build a threat-informed defense.

ATT&CK is split into Enterprise (post-exploitation techniques across operating systems and cloud platforms), Mobile (Android and iOS), ICS (industrial control systems), and PRE-ATT&CK (pre-exploitation reconnaissance and planning stages).

ATT&CK Navigator is a web-based tool that lets security teams visualize technique coverage using colored, scored layers, and combine layers to see overlapping techniques used across multiple threat groups.

The paper recommends scheduling purple team and red team assessments quarterly or every six months, while atomic testing of individual analytics should happen continuously as the environment changes.

TRAM (Threat Report ATT&CK Mapping) is a still-in-development MITRE tool that uses natural language processing to automatically identify and flag references to ATT&CK techniques within threat intelligence reports, speeding up manual analysis.

Meet the expert

John Hubbard
John Hubbard

John Hubbard

Senior Instructor

John is a Senior SANS Instructor and SOC consultant, author of SEC450 and LDR551. With deep SOC leadership experience, GIAC certifications, and hands-on labs, he equips cyber defenders with the skills to hunt, detect, and lead resilient operations.

Read more about John Hubbard