ATT&CK™ and D3FEND™: Incorporating Frameworks into Your Analysis & Intelligence

Logo
Presented by

Matt Bromiley, Principal Incident Response Consultant | Chase Snyder, Sr. Product Marketing Manager

About this talk

For many years, organizations have relied on the MITRE ATT&CK™ framework as a valuable resource to catalog adversary tactics and techniques. The information security community has leveraged ATT&CK to help guide investigations, write robust detections, and enrich threat intelligence. In June 2021, a cooperation between the National Security Agency (NSA) and MITRE released D3FEND, a complementary framework that provides insight into defensive measures for enterprise defense. This webcast will explore: How to leverage D3FEND to enhance enterprise security defenses How to utilize ATT&CK and D3FEND together to detect and counter attacker tactics and techniques How to incorporate D3FEND countermeasures into your daily *DR workflows How the security community can give back and make D3FEND even better
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (105)
Subscribers (12477)
ExtraHop is reinventing network detection and response (NDR) to help enterprises stay ahead of emerging threats with unparalleled network visibility, context, and control. As new attack vectors rapidly emerge, SOCs face an escalating challenge: Expand visibility to effectively detect and respond to threats, enhance productivity to manage the increased volume, and do it all while reducing operational complexity. By combining the power of NDR with network performance management (NPM), intrusion detection (IDS), and packet forensics in a single, integrated platform, enterprises benefit from complete visibility and contextual insights across their entire hybrid infrastructure - from data center campuses to cloud and SASE infrastructures and beyond. ExtraHop can decrypt and unlock packet-level data at wire speeds, analyzing and correlating it with its cloud-scale machine learning models to detect, investigate, and remediate cyber risks in real-time, without the added complexity of multiple tools. Unlock the full power of network detection and response with ExtraHop today. Learn more at www.extrahop.com