MITRE ATT&CK Framework
The MITRE Adversarial Tactics, Techniques, & Common Knowledge (ATT&CK) framework is a collection of knowledge about attackers based on real-world observations.
- https://attack.mitre.org/
- provide access to a database of known tactics, techniques, and procedures (TTPs)
- tags each technique with a unique ID and places it in one or more tactic categories
- sequence in which attackers may deploy any tactic is not defined
- analysts must interpret each attack lifecycle from local evidence
- allows analysts to compare the TTPs used by different threat groups