Empower Your Blue Team Defenders using MITRE ATT&CK
Through the ATT&CK framework, MITRE has generated a wealth of information about the most important tactics and techniques used by attackers and how the blue team can detect and prevent these actions. Blocking atomic attack indicators such as domain names and IP addresses might work in the short term, but understanding the higher-level tactics in ATT&CK helps the blue team identify and anticipate attacker activity at a higher level of abstraction, slowing attackers down, and giving defenders a fighting chance. In this webinar, John Hubbard, SANS instructor and dedicated blue team member, covers these key topics:
- Why the framework is important to security teams
- How the matrix is evolving
- Challenges when leveraging ATT&CK
- Using ATT&CK to improve operations
- Best practices and tools for successfully using the framework
Watch the webinar to understand how to leverage the MITRE ATT&CK framework in your organization.