Practical Threat Modeling with MITRE ATT&CK Analytics - SANS@Mic Tokyo

  • Wednesday, 04 Nov 2020 9:00PM EST (05 Nov 2020 02:00 UTC)
  • Speaker: Ismael Valenzuela

Unless you've been living under a rock over the last 3 years (everything is possible right...?) I'm pretty sure you know what MITRE ATT&CK is: a framework, a reference model, and even a language, to understand how attackers behave through the study of their tactics, techniques, and procedures. However studying the adversary is of no use if we're not able to leverage that intelligence to drive our defensive strategy, as security architects and engineers. '

In this webinar, I'll show you how to systematically analyze your defensive posture doing practical threat modeling to architect for visibility and detection using MITRE ATT&CK. Through community tools and open source projects that you can easily run on your own system with docker containers, I'll demonstrate how you can run analytics and generate visualizations that can help you to identify your weakest points and prioritize your cyber defense strategy.