← All courses

MITRE ATT&CK®: Understanding Adversary Behavior

Attackers change their malware and infrastructure constantly, yet Process Injection has topped the list of most-observed techniques three years running. Chase the hashes and you are always a step behind the last attack; learn the behavior and you get ahead of the next one. This in-depth method and reference course on MITRE ATT&CK builds from the ground up (no threat-intelligence, SOC, or red-team background assumed) through the object model, the Enterprise matrix, real adversaries, detection and mitigation, the four use cases, and three worked cases: anticipating a live intruder, prioritizing vulnerabilities, and designing with ATT&CK. Every lesson is self-contained, so it doubles as a reference you return to. Note: This course is voiced by AI voices (AI narrated).

What you'll learn

  • Explain why adversary behavior (TTPs) is more durable and valuable to defenders than indicators
  • Read the ATT&CK object model: tactics, techniques, sub-techniques, procedures, groups, software, campaigns, mitigations, detections
  • Navigate the Enterprise matrix and read a technique page without memorizing it
  • Ground techniques in real actors via groups, software, and campaigns, and weigh attribution honestly
  • Apply ATT&CK across the four use cases: threat intelligence, detection, emulation, assessment
  • Work three real cases: anticipate an active intruder, prioritize vulnerabilities, and design with ATT&CK
  • Use the course as a knowledge base: every lesson is a self-contained reference chapter

Tags

securitymitre-attackthreat-intelligencedetectioneacgAI narrated
Module 01 - Why ATT&CK? The Problem It Solves
  • Introduction 2:44
  • Attackers Swap IPs in Seconds: Their Behavior, They Can't 5:22
  • TTP Means Why, How, and With-What, and ATT&CK Is Not a Timetable 5:17
  • Match the Statement to Its Layer
Module 02 - The ATT&CK Model: Its Origin and Its Blueprint
  • The ATT&CK Model: Its Origin and Its Blueprint 0:18
  • ATT&CK Was Born as a Shared Language for Attack and Defense 5:54
  • A Small Set of Object Types, Each With Its Own ID, Carries the Whole Model 5:57
  • A Technique Page Answers Three Questions: Does It Hit Me, Who Did It, How Do I Catch It 5:51
  • Match Each Object to Its ID Scheme, and Sort Revoked From Deprecated
Module 03 - Reading the Enterprise Matrix: the Fifteen Tactics
  • Reading the Enterprise Matrix: the Fifteen Tactics 0:18
  • Fifteen Tactics Read as a Narrative, but the Story Has No Fixed Order 7:22
  • The Run-Up Happens Off Your Network: Reconnaissance and Resource Development 7:51
  • The Attacker Forces the Door and Runs Code: Initial Access and Execution 8:52
  • The Attacker Digs In and Climbs: Persistence and Privilege Escalation 8:35
  • The Attacker Hides and Then Blinds You: Stealth and Defense Impairment 8:30
  • The Attacker Steals Keys, Maps the Terrain, and Spreads: Credential Access, Discovery, and Lateral Movement 9:04
  • The Attacker Reaches the Goal: Collection, Command and Control, Exfiltration, and Impact 8:57
  • Match Each Observed Action to Its Tactic
  • Which Tactic Column Does Each Technique Belong To?
Module 04 - Reading and Assessing a Technique
  • Reading and Assessing a Technique 0:18
  • Sub-Techniques Are the Same Behavior, Only Mapped More Precisely 5:30
  • ATT&CK Does Not Prioritize for You, Three External Levers Do 5:33
  • Technique or Sub-Technique, and Which Lever Is It?
Module 05 - The Living Layer Grounds Techniques in Real Actors, Tools, and Campaigns
  • The Living Layer Grounds Techniques in Real Actors, Tools, and Campaigns 0:22
  • A Group Is an Activity Cluster, Not an Org Chart 5:29
  • Malware, Tool, Campaign: Precision Instead of 'the Russians' 5:34
  • APT28: One Cluster, Three Brand Names 7:13
  • SolarWinds Shows Why the Operation and the Actor Belong Apart 7:01
  • Lazarus: When a Name Becomes a Catch-All 7:12
  • Sandworm: The Path From the IT Network Into the Factory 7:12
  • Match the Alias to Its Primary Group
  • Operation or Actor? Tell the Campaign From the Group
Module 06 - The Defensive Side: Detection and Mitigations
  • The Defensive Side: Detection and Mitigations 0:19
  • A Mitigation Is Coarse by Intent, and the Fine-Grained Design Is Called D3FEND 5:52
  • Since Version 18, Detection Means Detection Strategy to Analytic to Data Component to Log Source 6:11
  • A Technique's Required Telemetry Shows You Exactly Where Your Blind Spots Are 6:13
  • Put the Detection Chain in the Right Order
  • Which Detection Model Does It Belong To, v17 or v18 and Later?
Module 07 - Applying ATT&CK: Fabrikat Nord and the Four Use Cases
  • Applying ATT&CK: Fabrikat Nord and the Four Use Cases 0:19
  • Use Case 1: A Threat Report Becomes a Shareable ATT&CK Layer 5:44
  • Use Case 2: Mapped Techniques Become Real, Prioritized Detection 6:19
  • Use Case 3: Replay a Real Actor Instead of Testing Generically 5:56
  • Use Case 4: Threat Profile Minus Coverage Equals Your Roadmap 5:33
  • The Result Carries Decisions, and “All Green” Is Not One 5:13
  • Match Each Use Case to Its Tooling, and Each Report Line to Its Technique
Module 08 - ATT&CK in Practice: Three Cases Where the Map Makes the Decision
  • ATT&CK in Practice: Three Cases Where the Map Makes the Decision 0:20
  • From the Map to the Decision: Three Stances, One Knowledge Base 2:44
  • Case 1, Reactive: The Break-In Is Underway, so You Forecast and Defend the Next Moves 10:03
  • Case 2, Analytic: Two Hundred Vulnerabilities, and ATT&CK Tells You Which Come First 9:29
  • Case 3, Constructive: ATT&CK Shapes the Architecture Before It Is Built 9:56
  • Synthesis: How Powerful ATT&CK Is, and Where That Power Honestly Ends 2:52
  • Match Each Situation to Its Stance, and Sort Valid Forecasts From Fallacies
Module 09 - Enterprise Is One World of Three, and ATT&CK Is a Language, Not a Report Card
  • Enterprise Is One World of Three, and ATT&CK Is a Language, Not a Report Card 0:19
  • Smartphone and Factory Each Need Their Own Matrix 7:40
  • ATT&CK Is a Language, Not a Report Card 6:11
  • Staying Current Means Checking Your Layers Against the Release Diff 5:47
  • Take-home messages 1:02