How to use MITRE ATT&CK to analyze a cyber threat?

Cyberwatch Vulnerability Manager can generate a MITRE ATT&CK matrix to perform a risk analysis on your information system. Learn how this method works in this technical article on our blog.

MITRE ATT&CK is a threat analysis tool

MITRE is a non-profit organization founded in 1958 with the goal of "solving problems for a safer world."

MITRE is historically known in the cybersecurity world for maintaining the list of Common Vulnerabilities and Exposures (CVE), where every internationally published vulnerability receives a code in the format CVE-YEAR-REFERENCE (where YEAR corresponds to the year of publication, and REFERENCE to a number that increments with each new vulnerability published in the year in question).

In 2013, MITRE created a model for analyzing threats to enterprise Windows environments.

This model was subsequently analyzed and further developed until May 2015, when it was made public for the first time with 96 techniques organized into 9 tactics.

MITRE then expanded the scope of its analysis model to cover a broader spectrum of systems, including Windows, Linux, and macOS, releasing the MITRE ATT&CK For Enterprise tool in 2017.

Since then, MITRE has created other analysis frameworks such as MITRE ATT&CK For Mobile, dedicated to Android and iOS devices, and MITRE ATT&CK for ICS for industrial systems.

Today, MITRE ATT&CK for Enterprise is the best-known threat analysis model in the series. When a cybersecurity expert mentions MITRE ATT&CK without further clarification, they are almost certainly referring to MITRE ATT&CK for Enterprise.

MITRE ATT&CK is based on an analysis of the tactics and techniques used by adversaries

ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge.

MITRE ATT&CK for Enterprise breaks down a complete cyberattack into 14 stages called tactics

MITRE ATT&CK for Enterprise categorizes a cyberattack into 14 tactics (12 from the classic MITRE ATT&CK matrix, and 2 additional ones from the PRE or pre-attack matrix):

  1. Reconnaissance (pre-attack, TA0043): the adversary is trying to gather information they can use to plan future operations;
  2. Resource Development (pre-attack, TA0042): the adversary is trying to establish resources they can use to support operations;
  3. Initial Access (TA0001): the adversary is trying to get into your network;
  4. Execution (TA0002) : the adversary is trying to execute malicious code;
  5. Persistence (TA0003) : the adversary is trying to maintain their foothold;
  6. Privilege Escalation (TA0004) : the adversary is trying to gain higher-level permissions;
  7. Defense Evasion (TA0005) : the adversary is trying to avoid being detected;
  8. Credential Access (TA0006) : the adversary is trying to steal account names and passwords;
  9. Discovery (TA0007) : the adversary is trying to understand your environment;
  10. Lateral Movement (TA0008) : the adversary is trying to move through your environment;
  11. Collection (TA0009) : the adversary is trying to gather data of interest to their goal;
  12. Command and Control (TA0011) : the adversary is trying to communicate with compromised systems to control them;
  13. Exfiltration (TA0010) : the adversary is trying to steal data;
  14. Impact (TA0040) : the adversary attempts to manipulate, interrupt, or destroy your systems and data.

These 14 steps or tactics form the 14 columns of the complete MITRE ATT&CK for Enterprise matrix. Tactics are referenced as TAXXX in MITRE ATT&CK, where XXX is a series of numbers.

These 14 tactics consist of 188 techniques and 379 sub-techniques that allow an adversary to carry out a cyberattack.

To advance through each stage of a complete cyberattack, an adversary uses attack techniques, denoted as TXXXX where XXXX is a series of numbers.

For example, the "Initial Access" stage (TA0001) can be achieved via an attack technique such as "Phishing" (T1566) or by "Exploit Public-Facing Application" (T1190).

The analysis provided by MITRE ATT&CK is extremely detailed and allows for the precise definition of the techniques used. This breakdown leads to what are known as sub-techniques. For instance, a "Phishing" attack can occur via a targeted operation, such as Spearphishing (or " Spearphishing "), through "Spearphishing Attachment" (T1566.001) or through "Spearphishing Link" (T1566.002).

MITRE ATT&CK for Enterprise thus lists 188 techniques, which are themselves broken down into 379 sub-techniques.

Each sub-technique is denoted as TXXXX.YYY, where XXXX and YYY are series of numbers. A sub-technique TXXXX.YYY will always be part of the TXXXX technique.

Each technique is part of one or more tactics. A technique is formatted in the MITRE ATT&CK matrix as a box, located under the corresponding tactic(s).

A MITRE ATT&CK analysis involves mapping the cyber risk of a perimeter based on available security data, then comparing it to a known threat.

A cyber risk can be mapped to the MITRE ATT&CK matrix using security data.

A MITRE ATT&CK analysis is performed on a specific perimeter. For this perimeter, you must then collect the available security data.

In the context of a vulnerability scan, for example, the available data consists of the CVEs affecting the studied perimeter.

However, the MITRE ATT&CK matrix cannot directly process CVEs. It is essential to go through its underlying data, specifically by calculating the list of related techniques and sub-techniques that could be used on the studied perimeter.

To do this, we will use vulnerability categories, also known as Common Weakness Enumeration (CWE).

When a CVE vulnerability is evaluated by the National Vulnerability Database (NVD), it receives a score from 0 to 10 (CVSS score), as well as a category in the CWE format.

This classification helps describe the type of vulnerability and its primary use in the context of a cyberattack.

For example, the vulnerability CVE-2022-21994 is linked to CWE-269, "Improper Privilege Management."

To move from this information to MITRE ATT&CK techniques, we will use a classification mechanism called Common Attack Pattern Enumeration and Classification (CAPEC), which describes possible attack patterns.

A CVE can be translated into techniques via CAPEC.

Starting from a CWE code, it is possible to view all attack patterns that utilize the studied family of vulnerabilities.

For example, CWE-269 "Improper Privilege Management" is used in 3 types of attack patterns according to MITRE:

  • CAPEC-122: Privilege Abuse;
  • CAPEC-233: Privilege Escalation;
  • CAPEC-58: Restful Privilege Elevation.

You must then consult each CAPEC to identify the presence of markers in the form of attack techniques.

Here, CAPEC-233 corresponds to attack technique T1548 according to MITRE.

The MITRE ATT&CK matrix can then be mapped based on the techniques linked to the various CVEs present, in order to establish the kill chain of the system under study

Based on the attack techniques calculated from the CVEs, an analyst can map the MITRE ATT&CK matrix as a statistical representation.

By counting all the techniques enabled by the various CVEs in the information system, it is possible to highlight the techniques that represent the most significant risks in terms of exploitation.

This map represents what is known as the "kill chain" of the system under study, i.e., a plausible attack path for carrying out a cyberattack.

MITRE ATT&CK analysis then allows you to compare the kill chain of a system under study with a potential threat

Once the kill chain has been identified, simply project the attack techniques that characterize a threat onto the MITRE ATT&CK matrix to identify the overlap between the analyzed threat and the existing kill chain.

The greater the overlap, the higher the risk of the analyzed threat being executed.

Use case: is your organization affected by Hermetic Wiper?

Hermetic Wiper is a wiper-type virus that was used against Ukrainian companies in January and February 2022.

According to ZScaler, the attack mechanism used involves several points close to the threat Gamaredon.

MITRE provides a comprehensive database of studied threats with associated techniques.

To check if your information system is exposed to Gamaredon, simply combine your current cyber risk projection with Gamaredon's data.

The low level of overlap shows, in this example, that the system has little to no exposure to an attack like Gamaredon.

If the analyst still wishes to harden the information system, the approach will be to prioritize neutralizing vulnerabilities in the Discovery column, which shows the highest number of overlaps.

The Cyberwatch platform allows you to map your vulnerabilities to the MITRE ATT&CK matrix and compare your exposure against a library of threats

The Cyberwatch vulnerability management platform allows you to calculate your exposure to a threat using MITRE ATT&CK for Enterprise.

The mapping is done automatically for you and includes numerous preconfigured threat families to facilitate your risk analysis.

Request a demo with our experts via the dedicated form or by phone at +33 1 85 08 69 79.

Thanks for submitting the form.