MITRE ATT&CK®: Understanding Adversary Behavior
Attackers change their malware and infrastructure constantly, yet Process Injection has topped the list of most-observed techniques three years running. Chase the hashes and you are always a step behind the last attack; learn the behavior and you get ahead of the next one. This in-depth method and reference course on MITRE ATT&CK builds from the ground up (no threat-intelligence, SOC, or red-team background assumed) through the object model, the Enterprise matrix, real adversaries, detection and mitigation, the four use cases, and three worked cases: anticipating a live intruder, prioritizing vulnerabilities, and designing with ATT&CK. Every lesson is self-contained, so it doubles as a reference you return to. Note: This course is voiced by AI voices (AI narrated).
What you'll learn
- Explain why adversary behavior (TTPs) is more durable and valuable to defenders than indicators
- Read the ATT&CK object model: tactics, techniques, sub-techniques, procedures, groups, software, campaigns, mitigations, detections
- Navigate the Enterprise matrix and read a technique page without memorizing it
- Ground techniques in real actors via groups, software, and campaigns, and weigh attribution honestly
- Apply ATT&CK across the four use cases: threat intelligence, detection, emulation, assessment
- Work three real cases: anticipate an active intruder, prioritize vulnerabilities, and design with ATT&CK
- Use the course as a knowledge base: every lesson is a self-contained reference chapter
Tags
Module 01 - Why ATT&CK? The Problem It Solves ▶
- ▶ Introduction 2:44
- ▶ Attackers Swap IPs in Seconds: Their Behavior, They Can't 5:22
- ▶ TTP Means Why, How, and With-What, and ATT&CK Is Not a Timetable 5:17
- ? Match the Statement to Its Layer
Module 02 - The ATT&CK Model: Its Origin and Its Blueprint ▶
- ▶ The ATT&CK Model: Its Origin and Its Blueprint 0:18
- ▶ ATT&CK Was Born as a Shared Language for Attack and Defense 5:54
- ▶ A Small Set of Object Types, Each With Its Own ID, Carries the Whole Model 5:57
- ▶ A Technique Page Answers Three Questions: Does It Hit Me, Who Did It, How Do I Catch It 5:51
- ? Match Each Object to Its ID Scheme, and Sort Revoked From Deprecated
Module 03 - Reading the Enterprise Matrix: the Fifteen Tactics ▶
- ▶ Reading the Enterprise Matrix: the Fifteen Tactics 0:18
- ▶ Fifteen Tactics Read as a Narrative, but the Story Has No Fixed Order 7:22
- ▶ The Run-Up Happens Off Your Network: Reconnaissance and Resource Development 7:51
- ▶ The Attacker Forces the Door and Runs Code: Initial Access and Execution 8:52
- ▶ The Attacker Digs In and Climbs: Persistence and Privilege Escalation 8:35
- ▶ The Attacker Hides and Then Blinds You: Stealth and Defense Impairment 8:30
- ▶ The Attacker Steals Keys, Maps the Terrain, and Spreads: Credential Access, Discovery, and Lateral Movement 9:04
- ▶ The Attacker Reaches the Goal: Collection, Command and Control, Exfiltration, and Impact 8:57
- ? Match Each Observed Action to Its Tactic
- ? Which Tactic Column Does Each Technique Belong To?
Module 04 - Reading and Assessing a Technique ▶
- ▶ Reading and Assessing a Technique 0:18
- ▶ Sub-Techniques Are the Same Behavior, Only Mapped More Precisely 5:30
- ▶ ATT&CK Does Not Prioritize for You, Three External Levers Do 5:33
- ? Technique or Sub-Technique, and Which Lever Is It?
Module 05 - The Living Layer Grounds Techniques in Real Actors, Tools, and Campaigns ▶
- ▶ The Living Layer Grounds Techniques in Real Actors, Tools, and Campaigns 0:22
- ▶ A Group Is an Activity Cluster, Not an Org Chart 5:29
- ▶ Malware, Tool, Campaign: Precision Instead of 'the Russians' 5:34
- ▶ APT28: One Cluster, Three Brand Names 7:13
- ▶ SolarWinds Shows Why the Operation and the Actor Belong Apart 7:01
- ▶ Lazarus: When a Name Becomes a Catch-All 7:12
- ▶ Sandworm: The Path From the IT Network Into the Factory 7:12
- ? Match the Alias to Its Primary Group
- ? Operation or Actor? Tell the Campaign From the Group
Module 06 - The Defensive Side: Detection and Mitigations ▶
- ▶ The Defensive Side: Detection and Mitigations 0:19
- ▶ A Mitigation Is Coarse by Intent, and the Fine-Grained Design Is Called D3FEND 5:52
- ▶ Since Version 18, Detection Means Detection Strategy to Analytic to Data Component to Log Source 6:11
- ▶ A Technique's Required Telemetry Shows You Exactly Where Your Blind Spots Are 6:13
- ? Put the Detection Chain in the Right Order
- ? Which Detection Model Does It Belong To, v17 or v18 and Later?
Module 07 - Applying ATT&CK: Fabrikat Nord and the Four Use Cases ▶
- ▶ Applying ATT&CK: Fabrikat Nord and the Four Use Cases 0:19
- ▶ Use Case 1: A Threat Report Becomes a Shareable ATT&CK Layer 5:44
- ▶ Use Case 2: Mapped Techniques Become Real, Prioritized Detection 6:19
- ▶ Use Case 3: Replay a Real Actor Instead of Testing Generically 5:56
- ▶ Use Case 4: Threat Profile Minus Coverage Equals Your Roadmap 5:33
- ▶ The Result Carries Decisions, and “All Green” Is Not One 5:13
- ? Match Each Use Case to Its Tooling, and Each Report Line to Its Technique
Module 08 - ATT&CK in Practice: Three Cases Where the Map Makes the Decision ▶
- ▶ ATT&CK in Practice: Three Cases Where the Map Makes the Decision 0:20
- ▶ From the Map to the Decision: Three Stances, One Knowledge Base 2:44
- ▶ Case 1, Reactive: The Break-In Is Underway, so You Forecast and Defend the Next Moves 10:03
- ▶ Case 2, Analytic: Two Hundred Vulnerabilities, and ATT&CK Tells You Which Come First 9:29
- ▶ Case 3, Constructive: ATT&CK Shapes the Architecture Before It Is Built 9:56
- ▶ Synthesis: How Powerful ATT&CK Is, and Where That Power Honestly Ends 2:52
- ? Match Each Situation to Its Stance, and Sort Valid Forecasts From Fallacies
Module 09 - Enterprise Is One World of Three, and ATT&CK Is a Language, Not a Report Card ▶
- ▶ Enterprise Is One World of Three, and ATT&CK Is a Language, Not a Report Card 0:19
- ▶ Smartphone and Factory Each Need Their Own Matrix 7:40
- ▶ ATT&CK Is a Language, Not a Report Card 6:11
- ▶ Staying Current Means Checking Your Layers Against the Release Diff 5:47
- ▶ Take-home messages 1:02