Threat Intelligence with MITRE ATT&CK: Prioritize and Defend Better
1. Introduction Threat intelligence with MITRE ATT&CK has become the favorite combination of defense teams that want to stop chasing alerts at random. Threat intelligence provides the data (indicators, campaigns, adversary tactics) and MITRE ATT&CK provides the common language to structure it. Working with threat intelligence with MITRE ATT&CK means applying real information about adversaries to a reference framework that every security professional understands, from the SOC analyst to the security architect. In this article you will see the complete workflow: how to collect intelligence through STIX and TAXII, how to map techniques against the MITRE ATT&CK framework, how to …

