Map Alerts to ATT&CK Tactics
Use MITRE ATT&CK tactics and techniques to describe what an alert may mean.
The reframe: Tool names tell you what fired; ATT&CK helps you explain what the adversary may be trying to do. Tactic The tactic is the objective. A suspicious process may be execution, defense evasion, discovery, or credential access depending on context. Technique The technique is the method. Scheduled task creation, PowerShell, valid accounts, remote services, and data staged each point to a different investigation path. Scope question Once you map the behavior, ask the next question tied to that tactic: persistence asks where else it was installed, credential access asks what secrets were touched, and command and control asks which…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in