DeTT & CT: Mapping Blue Team to ATT & CK

所在平台: Udemy

课程主页: https://www.udemy.com/course/dettct-mapping-blue-team-to-attck/

课程评论:没有评论

第一个写评论        关注课程

课程简介

**Coursera 课程总结:DeTT & CT - 将蓝队能力与 ATT&CK 对齐** 本课程介绍了 DeTT & CT 框架,这是一个旨在帮助蓝队(防御方)团队评估和优化其安全检测能力的工具。随着数据源的不断增加,检测工程师在管理日志、记录检测规则和避免重复规则方面面临巨大挑战。 **核心价值:** * **提升可见性和覆盖率:** DeTT & CT 框架帮助安全运营中心(SOC)清晰了解其现有的可见性,识别检测覆盖的盲点,并优先开发新规则或引入新数据源。 * **数据源质量评分:** 该框架允许评估各种数据源(如安全设备、网络设备和终端日志)的质量,并在 ATT&CK 框架下进行管理。 * **自动化比对:** DeTT & CT 可以将团队拥有的关于 ATT&CK 实体的信息进行映射,并帮助管理蓝队的数据、可见性和检测覆盖率。 **DeTT & CT 框架:** * **名称由来:** Detect Tactics, Techniques & Combat Threats(检测策略、技术与对抗威胁)。 * **起源:** 由 Rabobank 网络防御中心创建,由 Marcus Bakker 和 Ruben Bouman 开发与维护。 * **目标:** 协助蓝队利用 MITRE ATT&CK 框架,对数据日志源的质量、可见性覆盖和检测覆盖进行评分和比较。 * **优势:** 能够快速发现检测或可见性覆盖的差距,并优先处理新日志源的接入。 **数据源管理:** ATT&CK 框架包含超过 30 种数据源,细分为 90 多个数据组件,均已纳入 DeTT & CT 框架。这些数据源在 YAML 文件中进行管理,允许对每个数据源进行数据质量评分。同时,这些数据源也在 ATT&CK 的技术中(例如 T1003 的检测部分)有所体现。 **课程目标:** Empower blue teams with a structured approach to understand, manage, and improve their detection capabilities by aligning them with the MITRE ATT&CK framework, ultimately enhancing their ability to combat threats effectively.

课程评论(0条)

课程详情

Building detection is a complex task, especially with a constantly increasing amount of data sources. Keeping track of these data sources and their appropriate detection rules or avoiding duplicate detection rules covering the same techniques can give a hard time to detection engineers.For a SOC, it is crucial to have an good overview and a clear understanding of its actual visibility and detection coverage in order to identify gaps, prioritize the development of new detection rules or onboard new data sources.DeTT & CT stands for Detect Tactics, Techniques & Combat Threats. This framework has been created at the Cyber Defence Center of Rabobank and is developed and at the time of writing maintained by Marcus Bakker and Ruben Bouman.The purpose of DeTT & CT is to assist blue teams using MITRE ATT & CK to score and compare data log source quality, visibility coverage and detection coverage. By using this framework, blue teams can quickly detect gaps in the detection or visibility coverage and prioritize the ingest of new log sources.DeTT & CT delivers a framework than can map the information you have on the entities available in ATT & CK and help you manage your blue teams data, visibility, and detection coverage.Data Sources:Data sources are the raw logs or events generated by systems, e.g., security appliances, network devices, and endpoints. ATT & CK has over 30 different data sources which are further divided into over 90 data components. All those data components are included in this framework. These data sources are administered within the data source administration YAML file. For each data source, among others, the data quality can be scored. Within ATT & CK, these data sources are listed within the techniques themselves (e.g. T1003 in the Detection section).

课程标签

0人关注该课程

主题相关的课程