What is MITRE ATT&CK Framework? - Check Point Software

What is MITRE ATT&CK Framework?

The MITRE ATT&CK framework, a tool created by the MITRE Corporation, breaks down the cyberattack lifecycle into its component stages and provides in-depth information about how each stage can be accomplished. This information can be leveraged by security teams in a number of ways to improve threat detection and response (TDR).

The MITRE ATT&CK Framework

The MITRE ATT&CK framework is designed to build awareness and understanding of how cyberattacks work. To accomplish this, it organizes information into a hierarchy, including:

MITRE ATT&CK’s Tactics, Techniques, and Sub-Techniques drill down to a specific way in which an attacker can achieve a goal. For each of these techniques, MITRE ATT&CK includes a description of the attack, as well as the following:

Leveraging MITRE ATT&CK for Cyber Defense

The MITRE ATT&CK framework is designed as a tool, not solely a repository of information. Security operation center (SOC) teams can operationalize the MITRE ATT&CK matrix in a number of ways, including:

Check Point and MITRE ATT&CK

The MITRE ATT&CK framework is a valuable tool for improving communication and understanding of cyberattacks. Check Point has integrated MITRE ATT&CK’s taxonomy into its entire solution portfolio, including Check Point SOC and Check Point XDR. Mappings to MITRE ATT&CK techniques are included in forensic reports, malware capability descriptions, and more.

This provides a SOC analyst with a number of advantages. When analyzing a particular attack, the use of MITRE ATT&CK makes it easy to understand the root causes, attack flow, and the attacker’s intent in each stage. By understanding what the attacker is trying to achieve and how, a SOC team can easily understand the scope of an attack, any necessary remediation, and how to improve defenses for the future.

By integrating MITRE ATT&CK, Check Point SOC makes cyberattacks more transparent and comprehensible.