Contact Sales
Contact Sales

Using MITRE ATT&CK® as an Operational Framework: Prioritizing, Testing, and Sustaining Defense

Using MITRE ATT&CK® as an Operational Framework: Prioritizing, Testing, and Sustaining Defense (PDF, 1.87MB)Published: 18 Mar, 2026
Created by:
Christopher Crowley
Christopher Crowley

Thank You To Our Sponsor

Cybersecurity practitioners today operate in an environment defined by constant change, incomplete information, and real operational consequences. New adversary techniques emerge faster than controls can be deployed, tools are added faster than they can be fully understood, and defenders are expected to explain why certain gaps existed and why specific tradeoffs were made.

Using MITRE ATT&CK as an Operational Framework: Prioritizing, Testing, and Sustaining Defense

Related Webcast

Join SANS Instructor Chris Crowley and Tidal Cyber Co-Founder and Chief Innovation Officer Frank Duff to explore how to move beyond theory and operationalize MITRE ATT&CK across your environment.

Man with Headphones Looking at Laptop

Meet Your Author

Christopher Crowley
Christopher Crowley

Christopher Crowley

Senior Instructor

Christopher Crowley, a SANS Senior Instructor, has 25 years of industry experience managing and securing networks. He has authored numerous courses and is considered a leading expert in building an effective SOC.

Read more about Christopher Crowley