QuestionQ14

Threat Hunting Techniques

A task has been assigned to strengthen defenses against APT actors in a mid-sized technology company. The adversaries conduct sophisticated, long-running attacks and employ varied tactics to infiltrate and remain within target networks. The company is concentrating on the tactics used by these adversaries to substantially improve its overall security posture. A review of the Pyramid of Pain model has been completed, emphasizing the different levels of threat indicators, from simple hash values to complex TTPs. The goal is to improve detection capabilities.

Which approach should be used to detect APT activity at the Tactics level of the Pyramid of Pain?

Explanation

Tactics-level detection identifies patterns of adversary behavior and objectives across telemetry. MITRE ATT&CK defines tactics as the adversary’s tactical goal, so analyzing logs for behavior that maps to known ATT&CK tactics detects higher-level APT activity more effectively than matching individual hashes, IP addresses, or domains.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!