UK Channel: Threat Hunting Mitre ATT&CK™ TTPS to Identify Adversarial Behaviors
18th July at 09:30 - 17:00
In this Fast Track attendees will gain hands-on experience developing and understanding the analytics needed to discover the techniques used by adversaries during a cyber security breach.
In this educational challenge, you will assume the role of a security analyst and be asked to identify any undetected threats on AcmeCorp's network. To do this you will make use of Mitre ATT&CK™, which is a knowledge base of adversarial behavior based on real-world observations. ATT&CK™ allows analysts to hunt for patterns of behavior rather than artifacts such as hashes, IPs, or Domains. Why is this important? Well, according to 'The Pyramid of Pain' by David Bianco, while it is very easy for attackers to change these artifacts it is much harder for them to change their Tactics, Techniques, and Procedures (TTPs). Therefore, TTPs are a more reliable way of identifying adversary behavior.
The challenge is set up with several exercises set around the technical goals the adversary is trying to achieve (ATT&CK™ Tactics), for example, Initial Access, Persistence, Privilege Escalation, Command and Control. You will be asked to detect any techniques being used by an adversary to achieve these goals.
The workshop will use FortiAnalzyer, FortiEDR and FortiSIEM for analytics and reporting, and for data sources will use FortiGate, FortiWeb, FortiMail, FortiDeceptor and FortiSandbox.
Workshop Agenda
9:30 - 10:00 |
Arrival & Set Up |
10:00 - 10:30 |
Identify Adversarial Behaviors Presentation |
10:30 - 11:00 |
Overview of the ATT&CK™ TTPs Challenge |
11:00 - 13:00 |
ATT&CK™ TTPs Lab |
13:00 - 14:00 |
Lunch Break |
14:00 - 14:20 |
Overview of the Fortinet Challenge |
14:20 - 16:30 |
Fortinet Challenge |
16:30 - 17:00 |
Summary of the challenges, Team Awards & Prizes |
Please note: All attendees will have an opportunity to experience hands-on labs therefore you will require your laptop.
Lunch and Refreshments will be provided throughout the day.
Etc Venue: Manchester, Piccadilly