
MITRE ATT&CK
https://medium.com/@sroberts/incident-response-hunting-tools-a40331257a46MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target. ATT&CK is useful for understanding security risk against known adversary behavior, for planning security improvements, and verifying defenses work as expected.
Recon->Weaponizes->Deliver->Exploit->Control->Execute->-Maintain
Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Execution, Collection and Exfiltration, Command and Control.
- Lockheed Martin Kill Chain – https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Intel-Driven-Defense.pdf
- Diamond Model For Intrusion Analysis – http://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf
- MITRE EDR Test Scripts – https://github.com/op7ic/EDR-Testing-Script
- Privileged Escalation – kheirkhabarov_offzone_2018_final
MITRE ATT&KCon 2018
[youtube=https://www.youtube.com/playlist?list=PLkTApXQou_8JrhtrFDfAskvMqk97Yu2S2&app=desktop]
Getting started with ATT&CK
- Mitre attacked visualisation – eBook – mitre-getting-started-with-attack-october-2019
- Getting Started with ATT&CK: Assessments and Engineering https://medium.com/mitre-attack/getting-started-with-attack-assessment-cc0b01769cb4
- Getting Started with ATT&CK: Threat Intelligence by Katie Nickels https://lnkd.in/ggzkg_R
- Getting Started with ATT&CK: Detection and Analytics by John Wunder https://lnkd.in/gJy6ym7
- Getting Started with ATT&CK: Adversary Emulation and Red Teaming by Blake Strom, Timothy Schulz, and Katie Nickels https://lnkd.in/gmq5rRY
- DeTT@CT – https://github.com/rabobank-cdc/DeTTECT
- Quantifying Vendor Efficacy Using The MITRE ATT&CK Evaluation – https://go.forrester.com/blogs/measuring-vendor-efficacy-using-the-MITRE-attck-evaluation/
- Here’s Why We Can’t Have Nice Things – https://www.endgame.com/blog/executive-blog/heres-why-we-cant-have-nice-things
- BZAR (Bro/Zeek ATT&CK-based Analytics and Reporting)
- EU ATT&CK Community – https://attack-community.org/event/




- Threat_Hunting_For_Dummies_Carbon-Black
- https://attack.mitre.org/wiki/Main_Page
- https://github.com/redcanaryco/atomic-red-team
- https://github.com/redcanaryco/cb-response-surveyor
- https://github.com/mitre
- CbResponsePartner-Guide-RedCanary
- Framework-for-Threat-Hunting-Whitepaper
- https://threathunting.org/
- https://pan-unit42.github.io/playbook_viewer/
- https://github.com/MISP/misp-galaxy
- https://github.com/MISP/MISP
- https://github.com/nshalabi/ATTACK-Tools
- https://www.cybereason.com/blog/mitre-attck-evaluation-results
- https://attackevals.mitre.org/evaluations/cybereason.1.apt3.1.html
- https://attackevals.mitre.org/
- https://atomicredteam.io/testing
- https://github.com/nshalabi/ATTACK-Tools
- ATT&CK – https://attack.mitre.org – github.com/mitre/cti – cti-taxii.mitre.org ▪ ATT&CK Navigator – https://github.com/mitre/attack-navigator – https://mitre.github.io/attack-navigator/enterprise/ ▪ Adversary Emulation Plans – https://attack.mitre.org/wiki/Adversary_Emulation_Plans ▪ CALDERA: Automated Adversary Emulation – https://github.com/mitre/caldera ▪ Cyber Analytic Repository (CAR) – https://car.mitre.org
- us-19-Nickels-MITRE-ATTACK-The-Play-At-Home-Edition
- https://eqllib.readthedocs.io/en/latest/atomicblue.html
- MITRE Visualising
- https://www.youtube.com/watch?v=_kWpekkhomU
- DeTT&CT https://github.com/rabobank-cdc/DeTTECT
- https://github.com/JPMinty/MindMaps/tree/master/MITRE%20ATT%26CK/PNG
- RE&CT – https://github.com/atc-project/atc-react
- AMMIT – https://github.com/misinfosecproject/amitt_framework
- MITRE Cyber Analytics Repository
- Cloud Matrix – https://attack.mitre.org/matrices/enterprise/cloud/
- Attack Community
- Adversary Emulation & Red Teaming
- MITRE Caldera – https://github.com/mitre/caldera
- Atomic Red Team – https://atomicredteam.io/
- Path Finder – https://medium.com/mitre-engenuity/caldera-pathfinder-7564e63f3082
- Medium – https://medium.com/mitre-engenuity
- ATTACKiQ
- MITRE ATT&CK for Dummies.
- On-Demand: Foundations of Operationalizing MITRE ATT&CK
- https://www.mitre.org/capabilities/cybersecurity/threat-based-defense
- https://crits.github.io/
- https://mitre-engenuity.org/ctid/
- Introduction to FIn6 Emulation Plan and MITRE ATT&CK
- Emulations Plans APT3, APT29 and Carbank+Fin7
- Foundations of Breach & Attack Simulation

