Let’s Be Honest About MITRE ATT&CK® Mappings and the “So What”

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ก.พ. 2024
  • Mapping your intelligence outputs to ATT&CK may be a hot trend, best practice, and potentially an unspoken expectation at this point. But let's be real, what value does this extra effort really add? In this talk, we'll explore how mapping CTI to ATT&CK tactics and (sub-)techniques can enable your audience to better consume, contextualize, and action your findings. But more importantly we'll also discuss how to identify and avoid when the process of creating mappings can be a distraction and have diminishing returns. We'll finish with understanding how to make the most out of presenting ATT&CK mappings in products, and how these mappings can help you more completely and accurately capture the story you are telling.
    View upcoming Summits: www.sans.org/u/DuS
    SANS Cyber Threat Intelligence Summit 2024
    Let’s Be Honest About MITRE ATT&CK®Mappings and the “So What?”
    Jamie Williams, Principal Adversary Emulation Engineer, The MITRE Corporation
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น •