Plotting a Winning Threat Detection Strategy: A Visual Model | by VanVleet | Medium
This article is part of a series on Threat Detection. In this article, I’m going to set up a model for thinking about threat detection and then use it to answer two fundamental questions: First we’ll build a visual model. we’ll start with Mitre’s ATT&CK framework for Windows. We’re going to represent each technique as a single dot. Then, if we’ve done a good job defining our attack techniques, an attacker’s path through the network from initial access to objective could be represented as a path between dots. Obviously, an attacker doesn’t have to use a technique from EVERY tactic, but they do have to use SOME. Using this model, the goal of threat detection is to build mechanisms to prevent and/or detect as many techniques as possible, so an attacker can’t get from initial access to objective without triggering alarms. At this point, it becomes a game of probability: how probable is it that an attacker will take a path through that doesn’t alert you to their presence? Let’s make this si
This article is part of a series on Threat Detection. In this article, I’m going to set up a model for thinking about threat detection and then use it to answer two fundamental questions: First we’ll build a visual model. we’ll start with Mitre’s ATT&CK framework for Windows. We’re going to represent each technique as a single dot. Then, if we’ve done a good job defining our attack techniques, an attacker’s path through the network from initial access to objective could be represented as a path between dots. Obviously, an attacker doesn’t have to use a technique from EVERY tactic, but they do
Explore this link on the map →