The MITRE ATTACK (ATT&CK) Framework is a framework which describes all stages and methods cyberattacks attacks are launched on companies in the last 15 years. The main purpose of the framework is to help Red and Blue security teams to harden their systems and to provide a library of known attacks to help mitigate them.

MITRE is the organization who is in charge of this community-driven framework and is a non-profit organization. ATT&CK stands for:

  • Adversary -> Our opponents
  • Tactics
  • Techniques
  • Common Knowledge

The framework itself can help organizations help to secure their environment really good, but keep in mind that the framework is built based on known attacks and techniques. It doesn’t cover new techniques where an organization can be vulnerable to.


The framework itself

The framework can be found on this website: MITRE ATT&CK®


The stages of a cyberattack

Each cybersecurity attack follows multiple or all stages below. Also, i added a summary of that the stage contains:

StagePrimary goal
ReconnaissanceGathering information prior to the attack
Resource DevelopmentAquiring the components to perform the attack
Initial AccessInitial attempts to get access, the attack starts
ExecutionCustom-made code (if applicable) will be executed by the adversary
PersistenceThe attacker wants to keep access to the systems by creating backdoors
Privilege EscalationThe attacker tries to get more permissions than he already has
Defense EvasionThe attacker wants to avoid detection for a “louder bang”
Credential AccessStealing account names and passwords
DiscoveryPerforming a discovery of the network
Lateral MovementAquire access to critical systems
CollectionCollecting data which often is sensitive/PII* data
Command and ControlThe attacker has full control over the systems and can install malware
ExfiltrationThe attacker copies the collected data out of the victims network to his own storage
ImpactThe attacker destroys your systems and data

*PII: Personal Identifible Information, like birth names and citizen service numbers

The attack stages are described very consise, but the full explaination can be found on the official website.


Summary

The MITRE ATT&CK framework is a very great framework to get a clear understanding about what techniques and tactices an attacker may use. This is can be a huge improvement by securing your systems by thinking like a attacker.

The best part about the framework are the mitigation steps where you can implement changes to prevent attacks that already happend with a big impact.



End of the page 🎉

You have reached the end of the page. You can select a category, share this post on X, LinkedIn and Reddit or return to the blog posts collection page. Thank you for visiting this post.

If you think something is wrong with this post or you want to know more, you can send me a message to one of my social profiles at: https://justinverstijnen.nl/about/

Go back to Blog

The terms and conditions apply to this post.

Page visitors: No page-counter data available yet.
Categories: Microsoft Defender XDR

1 Comment

XMC.PL · May 4, 2025 at 18:15

Each paragraph flows like a river, guiding the reader through a landscape of ideas with ease and clarity.

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *