article Open access

Automated ATT&CK Technique Chaining

  • Digital Threats Research and Practice
  • Association for Computing Machinery
Research footprint

At a glance

Citations
2
References
4
Comments
0
Paper overview

Abstract

Incident response teams need to determine what happened before and after an observation of adversary behavior in order to effectively respond to incidents. The MITRE ATT&CK knowledge base provides useful information about adversary behaviors but provides no guidance on what most likely happened before and after an observed behavior. We have developed methods and open source tools to help incident responders answer the questions “What did most likely happen prior to this observation?” and “What are the adversary’s most likely next steps given this observation?” To be able to answer these questions, we combine semantic modeling of subject matter expert knowledge with data-driven methods trained on data from computer security incidents.

Record transparency

Publication details

DOI
10.1145/3696013
OpenAlex
W4402513958
Document type
article
Language
EN
Source
Digital Threats Research and Practice
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.