MITRE Frameworks Flashcards
What is MITRE Cyber Analytics Repository (CAR)
?
methods and processes used to detect and analyze patterns, behaviors, and anomalies in network and system data that could indicate cybersecurity threats or incidents
What is the purpose of the analytics
?
turn raw data (like logs, network traffic, system events) into actionable security insights
<br></br>
* Insight: An alert that identifies a user account logging in at unusual hours or from a geographically distant location, especially if the account has elevated privileges
* Action: Investigating the legitimacy of the login, potentially leading to actions like temporarily disabling the account or changing its credentials
What is the purpose of MITRE Engage
?
framework for planning and discussing adversary engagement operations that empowers you to engage your adversaries and achieve your cybersecurity goals
What is the purpose of MITRE D3FEND
?
outline defensive countermeasures that can be employed to protect against tactics and techniques described in MITRE ATT&CK
What is MITRE ATT&CK
knowledge base of adversary behaviour, focusing on the indicators and tactics