
Christopher brings a decade of azure and cybersecurity experience, including Microsoft work, to guide you through the Mitre attack framework course with real-world, hands-on insights.
Confront rising cyber security complexity by securing people, cloud, endpoints, mobile, OT/ICS, and IoT, while tackling talent shortages, automation gaps, data overload, and noisy alerts.
Discover how a security operations center uses threat intelligence, threat hunting, and log management to detect threats, with incident response and forensics to reduce the attack surface.
Explore the three tier soc model where automation handles commodity malware, tier one handles easier alerts, tier two addresses advanced threats, and tier three conducts proactive threat hunting and forensics.
Follow the NIST-based incident response process: prepare with stakeholder alignment, detect and analyze incidents, contain, eradicate, and recover, then review lessons learned to prevent recurrence.
Explore how EDR, XDR, SIEM, and SOAR enable security tooling, including defender for endpoint, sentinel, and logic apps, for behavior monitoring and automated incident response across the IT infrastructure.
Define cyber threats with NIST: a threat is any event that can harm operations or assets through an information system, via unauthorized access, destruction, disclosure, modification, or denial of service.
Clarify how cyber threat intelligence focuses on adversaries and their TTPs within cybersecurity, while broader threat intelligence may apply to non-cyber domains.
Define cyber threat intelligence as knowledge about adversaries' motivations, intentions, and methods gathered to protect assets. It focuses on tactics, techniques, and procedures to enable threat-informed defense.
Define threat actors, vulnerabilities, and risk in cybersecurity, and explain how exploiting vulnerabilities leads to downtime, confidentiality or integrity impacts, with risk tied to financial impact and likelihood.
Threat informed defense uses cyber intelligence to align the mission, identify threat actors and their TTPs, and focus detection and protection with SoC, EDR, XDR, and SIEM.
Explain tactics, techniques and procedures (TTPs) as a hierarchy from high-level threat actor objectives to detailed procedures, showing how techniques realize objectives and how procedures sequence actions.
Compare IOCs and IOAs to understand breaches via file hashes, domains, and NetFlow logs. Learn how IOAs detect attacker intent and behavior, not malware.
The pyramid of pain ranks attacker difficulty to change artifacts from hashes and IPs to ttps. Focus on detecting ttps to harden defenses.
Explore cyber threat intelligence sources: enterprise, OSINT, and social media. Highlight tools like Microsoft Defender Threat Intelligence, VirusTotal, Shodan, and the meta attack framework, plus IOCs, IOAs, and TTPs sharing.
Explore the MITRE ATT&CK framework, detailing adversarial tactics and techniques to enable threat-informed defense, with a Sentinel case study and free MITRE resources to browse the MITRE matrix for coverage.
Align the pyramid of pain with Mitre att&ck by mapping tactics, techniques and sub techniques to the tps framework, clarifying that artifacts like IP addresses are outside the focus.
Explore the MITRE ATT&CK framework by examining the enterprise, mobile, and ICS matrices and their submatrices for Windows, Linux, macOS, and cloud tools like Azure AD, O365, and Google Workspaces.
Dive into the MITRE ATT&CK tactics, the top-level objectives guiding adversaries, and the 14 enterprise tactics from reconnaissance to impact, with example behaviors and a kill chain flow.
Explore the MITRE ATT&CK techniques layer, illustrating 201 techniques across tactics with examples like active scanning, phishing, masquerading, account discovery, internal spearphishing, and encrypted C2.
Explore MITRE ATT&CK subtechniques with concrete examples across tactics like reconnaissance, execution, persistence, credential access, and exfiltration, and see how 424 subtechniques evolve.
Explore the MITRE ATT&CK framework by examining tactics, techniques, and subtechniques to explain adversary motivation and how they achieve objectives, from the execution tactic to the Python sub-technique.
Explore how data sources provide telemetry to detect adversaries in the MITRE ATT&CK framework, including network traffic, CIM system data, and web application firewall logs.
Explore MITRE ATT&CK detections, focusing on techniques and sub-techniques like reconnaissance and scanning; learn to use web application firewall logs and CIM rules to detect and alert on scans.
Learn how mitigations reduce attack surfaces through preventative configurations, prioritizing minimized data exposure and privileged account management, with a focus on pre-compromise techniques and web application firewall controls.
Groups in the MITRE ATT&CK framework are clusters of related attacker behaviors tracked under vendor-specific names, such as apt41, with different naming by Mandiant, CrowdStrike, and Microsoft.
Explore software in the MITRE ATT&CK framework as adversary tools and malware, linked to techniques, groups, and campaigns, including built-in, commercial, custom, open source, and PowerShell options.
Campaigns orchestrate intrusion operations over a period with common targets and objectives, exemplified by the Ukraine electric power grid attack by Sandworm and the cuckoo bees espionage campaign.
Relate groups, tactics, objectives, and motivations to explain campaign dynamics, where exploit tools enable techniques and sub-techniques to accomplish tactics. Highlight how data sources support detections that reveal adversary activity.
Explore the MITRE ATT&CK enterprise matrix, navigate tactics, techniques, and sub-techniques, review mitigations and detections, and examine CTI, data sources, and case study applications.
The MITRE ATT&CK framework continually evolves, updating roughly every six months with new techniques and sub techniques observed by the intelligence community.
Imagine a security operations center scenario: analyze news of high-profile breaches and assess how APT 41 Winnti could target your organization, guiding your threat intel response.
APT 41 and Win NTI operate as Chinese state sponsored threat actors, targeting healthcare, telecom, technology, and gaming across 14 countries, using zero day vulnerabilities and techniques to exfiltrate data.
Examine the OS credential dumping technique (T1003) and its subtechnique, focusing on lsass memory in Windows. Show how Mimikatz harvests credentials for lateral movement and pass-the-hash attacks.
Explore detections and mitigations for OS credential dumping, including attack surface reduction, credential guard, and behavior-based analytics to thwart Mimikatz and APT 41 techniques.
Monitor behavior over individual tools using the pyramid of pain to defend against changing hashes, IP addresses, domains, and artifacts. Advocates threat-informed MITRE ATT&CK defense against mimikatz techniques, not tools.
Operationalizing the meta attack framework standardizes communication across the SoC and CTI teams, shifting focus from tool syntax to adversary behavior and enabling scalable, behavior-based detections.
Use the Mitre attack framework to enable threat informed decision making by measuring coverage, prioritizing TTPs with threat intel, and aligning detections and mitigations through continuous reviews.
Explore the MITRE ATT&CK Navigator heat map to visualize enterprise tactics, techniques, and subtechniques with an interactive layer, color-code detections and mitigations, and identify blind spots and key TTPs.
Leverage purple teaming with the MITRE ATT&CK framework to align blue and red teams, build detections for ttps, and enable threat informed decision making through continuous lessons learned.
Explore the Meitar attack evaluations to compare Microsoft Defender for Endpoint and CrowdStrike across the Sandworm scenario, reviewing tactic and technique detections, telemetry, and console screenshots.
Discover Microsoft Digital Defense Report 2023 highlights on defending against adversaries using multi-factor authentication, zero trust, assume breach, and XDR with encryption and data loss prevention.
Explore the diamond model of intrusion analysis, outlining its four edges: adversaries, infrastructure, capabilities, and victims, and how adversaries deploy capabilities over infrastructure to attack victims, emphasizing behavior over tools.
Describe the LM cyber kill chain and its seven steps from reconnaissance to actions on objectives. Explain how it models adversary behavior and complements the diamond model of intrusion analysis.
Define large language models as probabilistic predictors of the next token based on prior context. They respond by selecting the highest probability token, not expressing feelings or agency.
Atlas follows the same logic as the attack framework, focused on adversarial threats to AI systems. It highlights AI-specific tactics like ML attack staging and LM prompt injection with mitigations.
Map Atlas to the pyramid of pain, showing how Atlas tactics, techniques, and sub-techniques fit cyber threat intelligence, with TPS at the top indicating higher attacker difficulty.
Explore how the MITRE ATT&CK framework uses tactics in Atlas to explain adversary objectives, including initial access and new machine learning related tactics.
Explore how techniques in the attack framework and Atlas reveal how adversaries perform attacks, including prompt injection and backdoors in machine learning models.
Explore MITRE ATT&CK framework subtechniques, including prompt injection with indirect and direct variants, and note cases like machine learning model inference API access and backdoor poisoning.
Explore how tactics, techniques and sub techniques interrelate within the MITRE ATT&CK framework, using actionable examples like initial access and a prompt injection to ChatGPT in a large language model.
Explore mitigations in the MITRE ATT&CK framework, showing how preventative configurations reduce attack surface, with encrypting sensitive information and restricting machine learning model queries as examples.
Atlas introduces case studies that illustrate AI security risks—evasion, poisoning, and model replication—across cloud, on-premises, and edge ml deployments.
Explore a 2020 Microsoft Azure disruption carried out by the AI red team, blending traditional techniques with adversarial ML evasion and mapping to MITRE ATT&CK techniques in the Atlas framework.
Examine how Mithril Security researchers poisoned an open-source pre-trained language model to return false facts, uploading the poisoned model to Hugging Face to demonstrate supply-chain risks.
Analyze the May 2023 ChatGPT plugin privacy leak, showing indirect prompt injection through plugins. See how attackers exfiltrate chat history and cause PII leakage for OpenAI and ChatGPT users.
Explore the atlas matrix and compare it to attack, navigate tactics and techniques, view case studies, and use the embedded navigator for blue red team exercises and threat modeling.
Explore prompt injection vulnerabilities in large language models, including direct jailbreaks that ignore developer prompts and leak data. Examine indirect attacks using inputs hidden in PDFs and resumes.
Explore how the MITRE defense matrix, D3FEND, provides a model to precisely specify countermeasure components and capabilities, contrasting with attack's mitigation and detection, including password policy and DNS traffic analysis.
Map d3fend to the pyramid of pain by prioritizing defender-focused tactics and procedures over IOCs, highlighting TTP-based defenses within the MITRE ATT&CK framework.
Explore TTPs in D3FEND, detailing how defend maps tactics and techniques to CDI, replaces sub techniques with subclasses, and explains the relation to attack procedures.
Discover seven defender tactics—model, harden, detect, isolate, deceive, evict, restore—and how they deter attacker objectives, increase security, and guide incident response and system restoration.
Explore how defend and attack techniques link tactics to countermeasures, including application hardening that authenticates and validates pointers and stack frames, hardens configurations, and maps artifacts via a knowledge graph.
Explore how subclasses in the MITRE ATT&CK framework refine detect techniques into concrete countermeasures, such as homoglyph detection and reputation analyses, by matching IOCs to network traffic.
Discover how artifacts form a knowledge graph in defend, linking files, urls, and file sections. See how create file artifacts and delete file artifacts illustrate interactions across directories and emails.
Explore the MITRE D3FEND defense framework alongside MITRE ATT&CK, examining tactics, techniques, artifacts, and the knowledge graph to strengthen SOC defenses and map defenses to attacker techniques.
This course contains the use of artificial intelligence.
MITRE ATT&CK Framework, is a carefully curated Udemy course designed for IT professionals who aim to excel in utilizing the MITRE ATT&CK Framework for enhanced threat detection and response. This course takes you on a detailed journey from basic concepts to advanced strategies, emphasizing practical applications and real-world scenarios.
Through this course, you'll develop expertise in the MITRE ATT&CK Framework, a comprehensive knowledge base widely recognized for its effectiveness in understanding tactics, techniques and procedures of adversaries and defending against cyber threats.
This deep dive into the framework equips you with the skills necessary for a cutting-edge career in cybersecurity, emphasizing the application of the framework within blue, red and purple teams.
Key benefits for you:
SOC Basics: Establish a strong foundation with an overview of core concepts for a Security Operations Centers
CTI Basics: Learn the key concepts of Cyber Threat Intelligence
The MITRE ATT&CK Framework: Master the terminology and logic of the MITRE ATTACK Framework
Case Study – Group APT41 / Winnti: Apply your new skills in a case study to identify and defend against TTPs of APT41
Operationalizing ATT&CK: Discover how to operationalize ATT&CK in Blue, Red and Purple Teaming
Other resources leveraging ATT&CK: Explore other cyber security resources leveraging ATT&CK
ATT&CK vs. other Cyber Security Frameworks: Compare ATT&CK vs. the Diamond Model of Intrusion Analysis and the LM Cyber Kill Chain
MITRE ATLAS: Discover ATLAS - A new MITRE framework focused on TTPs for AI
MITRE D3FEND: Explore D3FEND - A new MITRE framework focused on defending against TTPs
This course contains promotional materials.