MITRE Frameworks Flashcards

1
Q

What is MITRE Cyber Analytics Repository (CAR)?

A

methods and processes used to detect and analyze patterns, behaviors, and anomalies in network and system data that could indicate cybersecurity threats or incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of the analytics?

A

turn raw data (like logs, network traffic, system events) into actionable security insights
<br></br>
* Insight: An alert that identifies a user account logging in at unusual hours or from a geographically distant location, especially if the account has elevated privileges
* Action: Investigating the legitimacy of the login, potentially leading to actions like temporarily disabling the account or changing its credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of MITRE Engage?

A

framework for planning and discussing adversary engagement operations that empowers you to engage your adversaries and achieve your cybersecurity goals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of MITRE D3FEND?

A

outline defensive countermeasures that can be employed to protect against tactics and techniques described in MITRE ATT&CK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is MITRE ATT&CK

A

knowledge base of adversary behaviour, focusing on the indicators and tactics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly