Lesson 4: MITRE ATT&CK® Matrices - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Explore the MITRE ATT&CK® matrices and learn how tactics, techniques, and procedures are used in cybersecurity attacks. Learn how MITRE ATT&CK matrices are used to aid with cybersecurity defense and detection.

Video

Key points

  • MITRE ATT&CK is a community-driven knowledge base of tactics, techniques, and procedures that are used by malicious actors to compromise computers or mobile devices.

    • Tactic: goal or reason for a malicious actor to perform an action

    • Technique: action or method used to achieve a tactical goal

    • Procedure: real-world example of a technique in action

  • Techniques can contain sub-techniques, a more specific variant or lower-level description of a malicious technique.

    • For example, in the macOS Matrix, the Phishing technique contains the following sub-techniques:

      • Spearphishing Attachment

      • Spearphishing Link

      • Spearphishing via Service

      • Spearphishing Voice

  • MITRE ATT&CK matrices are organized by platform, and separated between computers and mobile devices.

  • Tactics, techniques, and procedures can be used to create detection analytics to monitor and respond to malicious actions.

  • Many MITRE ATT&CK techniques are used to create detection analytics in Jamf Protect.

    • Analytics in Jamf Protect are tagged with the technique and/or ID number from the MITRE ATT&CK Matrix.

    • These IDs can be used to search and filter analytics in the macOS Security portal.

Review

To view answers, click arrow next to each question.

  1. A tactic is the goal of a malicious actor and the reason for performing a specific action.
  2. A technique is the method used by a malicious actor to achieve a tactical goal.
  3. Tactics, techniques, and procedures are used to create detection analytics, or rules and behaviors that work to expose malicious actors on a system or network.

Practice

  1. In the MITRE ATT&CK iOS Matrix, select the Phishing technique and identify what mitigation methods are applicable to this technique.

  2. In the MITRE ATT&CK macOS Matrix, locate the Create or Modify System Process technique and identify its sub-techniques.

  3. In the macOS Security portal, locate analytics that are derived from the sub-techniques identified in Task 2.

    1. Navigate to Analytics > All Analytics.

    2. Filter the Analytics page to show only those tagged with LaunchAgent.

    3. Filter the Analytics page to show only those tagged with LaunchDaemon.

Resources

Jamf Protect Documentation

MITRE