Essential MITRE ATT&CK Framework Resources and Free Courses

Search for a command to run...

No comments yet. Be the first to comment.
Security dashboards are lying to you. That critical CVE flagged in your dependency scan? Odds are, your application never touches the vulnerable code path. The result is alert fatigue, wasted engineer

Harbor is an enterprise-class private container registry with advanced features like RBAC, replication, vulnerability scanning, and more. In this guide, we'll set up Harbor on a Ubuntu machine, secure it with Let's Encrypt certificates, and use Cloud...

Introduction This document provides a step-by-step guide to installing and configuring the AWS CLI and Pulumi on Ubuntu 24.04. Prerequisites Ubuntu 24.04 installed and configured. A user account with sudo privileges. An active AWS account. 1. In...

What motivated me to do this? While reading the book Container Security, a strange question popped into my head. Since everything inside a container is essentially a process running on the host machine's Linux kernel, what about creating nested conta...

Introduction This document outlines the procedures for creating AWS Access Keys for both IAM users and IAM Identity Center (Federated) Users. These credentials are used for programmatic access to AWS services, enabling applications and tools to inter...

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations.
MITRE Attack Navigator is a web-based tool for annotating and exploring ATT&CK matrices. It can be used to visualize defensive coverage, red/blue team planning, the frequency of detected techniques, and more.
The MITRE Cyber Analytics Repository (CAR) is a collection of analytics for detecting adversary behaviors based on the MITRE ATT&CK model. CAR provides pseudocode and code implementations for various tools (e.g., Splunk, EQL) and data sources. CAR also defines a data model and a sensor framework for observable data.
Search Katie Nickels on google. Everything she shared on Cyber Threat Intelligence (CTI) is valuable.
She is the Director of Intelligence at Red Canary and a Nonresident Senior Fellow at the Atlantic Council. She has worked on cyber threat intelligence (CTI), network defense, and incident response for nearly a decade for the U.S. Department of Defense (DoD), MITRE, Raytheon, and ManTech.
Link: academy.picussecurity.com
Link: academy.attackiq.com
Link: www.cybrary.it
MAD is a training and credentialing program for cybersecurity operations and individuals looking to strengthen their threat-informed defense approach to security. This is the official website for MITRE ATT&CK Certification exam.
Link: mad.mitre-engenuity.org
Suggested video on MITRE ATT&CK Fundamentals.
TTP based Threat Hunting (PDF).
MITRE ATT&CK for Dummies (PDF).