Talk With an Expert

Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework

Measuring and Improving Cyber Defense Using the MITRE ATT&CK Framework (PDF, 3.99MB)Published: 17 Jul, 2020
Created by:
John Hubbard
John Hubbard

Through the ATT&CK framework, MITRE has generated a gold mine of information about the most important tactics and techniques used by attackers and how the blue team can detect and prevent these actions. Blocking atomic attack indicators such as domain names and IP addresses might work in the short term, but understanding the higher-level tactics in ATT&CK helps the blue team identify and anticipate attacker activity at a higher level of abstraction. In this white paper, SANS author and dedicated blue team member John Hubbard explores how ATT&CK slows attackers down and gives defenders a fighting chance.

Meet the expert

John Hubbard
John Hubbard

John Hubbard

Senior Instructor

John is a Senior SANS Instructor and SOC consultant, author of SEC450 and LDR551. With deep SOC leadership experience, GIAC certifications, and hands-on labs, he equips cyber defenders with the skills to hunt, detect, and lead resilient operations.

Read more about John Hubbard