Главная
Study mode:
on
1
Introduction
2
Take stock
3
Detection Focus
4
High Fidelity Alerts
5
Uncontrolled Environment
6
Big Data
7
Detections vs Alerts
8
Detects vs Alerts
9
What will drive Intel
10
Partnership with MITRE
11
How to use ATTCK
12
Jerry Springer moment
13
Dont treat it as a sacred document
14
Break PowerShell up
15
Roadmap
16
ATTCK as a Communications Tool
17
How are you instrumented for MITRE
18
Do you have anything to add
19
How are you integrating
20
What should vendors be doing
21
Dark Block June
22
Advice for Vendors
23
Manual vs Automated
24
Using Attack as a Resource
25
Admitting Your First Step
26
Transparency
27
Testdriven development
28
Enel test
29
Creating regression
30
Testing analytics
31
Using attribution
32
Attribution
33
Impact
34
Measuring Impact
35
Educational Tool
36
Following the right people
37
Free tools
38
Analytics
Description:
Explore the practical applications and lessons learned from implementing MITRE ATT&CK in real-world cybersecurity operations through this 50-minute panel discussion featuring experts from MITRE Corporation, Microsoft, Pfizer, and Target. Gain insights into using adversary behavior knowledge to enhance cyber-defense strategies, learn from other organizations' experiences, and discover how to quickly apply these concepts within your own security framework. Understand the nuances of detection focus, high-fidelity alerts, and managing big data in uncontrolled environments. Delve into topics such as the distinction between detections and alerts, leveraging MITRE ATT&CK as a communication tool, and integrating it into existing systems. Acquire valuable advice for vendors, explore manual versus automated approaches, and learn how to use ATT&CK as an educational resource. Discuss the importance of transparency, test-driven development, and measuring impact while gaining practical tips on following industry experts and utilizing free tools to bolster your cybersecurity analytics. Read more

Lessons from Applying MITRE ATT&CK in the Wild

RSA Conference
Add to list
0:00 / 0:00