Attack framwork Flashcards
Kill Chain
A model by LM that describes the stage of a threat actors operation
What are the 7 steps to a kill chain
Rhonda wet dads eggs in colorado already Recon Weaponization Delivery Exploitation Installation C2 Actions on Objective
Reconnaissance Kill chain
Attacker determines what methods to use
Using open source and passive information gathering
Weaponization - Kill chain
Attacker couples payload code that will enable access with exploit code that will use a vulnerability to execute on the system
coding or creating the malware but its not executed yet
Delivery
`Attacker choses avenue of approach. Via email, application, etc
Exploitation
The exececution of the code.
clicking the link
Installation
allows the code to run a RAT to give control
C2
Esstablishes the outbound channel to remote server
Actions on Obj
execute goals
Kill chain analysis
defense course of action matrix to counter progress
MITRE ATT&CK Framework
a knowledge base list that you use to help stop future or progressing attacks
Pre- ATT&ck
Helps with recon and weapon phases
Diamond Model of Intrusion Analysis
analysis CS incidents and intrustions by looking at Adversary, caoability, infrastruction, and victim