#mitreattack — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mitreattack, aggregated by home.social.
-
📄 New paper: mapping CVEs to MITRE ATT&CK techniques with a classifier trained on 1,207 expert-labeled CVEs
Live on every vulnerability page of https://vulnerability.circl.lu
Bonus negative result: LLM-generated labels at ≈0.39 expert agreement don't help and degrade rare-technique coverage. Curation beats generation.
Paper: https://arxiv.org/abs/2607.25572
Code: https://github.com/vulnerability-lookup/VulnTrain#CyberSecurity #mitreattack #infosec #AI #NLP #OpenSource #LLM #CVE #Qwen #Ollama
-
🚀 Vulnerability-Lookup 5.5.0 is out!
🔐 Full Role-Based Access Control replaces the legacy admin flags
🤖 AI-suggested MITRE ATT&CK techniques on the vulnerability page, powered by our model trained with VulnTrain
🇪🇺 EUVD ID allocation pipeline
🛠️ Feeder supervision, new VEX sources & feeders👉 https://www.vulnerability-lookup.org/2026/07/24/vulnerability-lookup-5-5-0/
#VulnerabilityLookup #cybersecurity #opensource #CVE #MITREATTACK
-
📢🔔 Just 1 more day to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more week to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 2 more weeks to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
📢🔔 Just 1 more month to submit your talk at ATT&CKcon 7.0 cc @mitreattack! https://cfptime.org/cfps/3472/ #cfp #infosec #mitreattack
-
Learn How Malware Survives Reboots and Cleanup Using Cron Persistence Technique in Linux Systems.
Full Details Here: https://ostechnix.com/cron-persistence-linux-malware/
#CronPersistence #Malware #Cronjob #Cron #LinuxSecurity #MitreAttack #Linux
-
Red and blue teams breaking down their silos and working in real time—imagine a cybersecurity defense that evolves with every simulated threat. Curious how continuous purple teaming is rewriting the playbook?
#purpleteaming
#cyberdefense
#breachandattacksimulation
#mitreattack
#redteam
#blueteam
#securityautomation
#continuousvalidation
#cybersecuritystrategy -
🚀 MITRE ATT&CK v18 = a major leap in detection depth.
The new version adds Detection Strategies and Analytics - helping defenders align detection logic to platform-specific threats.
Also new: CI/CD, Kubernetes, ransomware prep behaviors, mobile “linked devices” exploits, and ICS asset updates.
MITRE even launched the ATT&CK Advisory Council to strengthen community collaboration.
💬 What part of ATT&CK v18 do you think will have the biggest impact on detection engineering?
Follow @technadu for more #ThreatIntel insights.#CyberSecurity #MITREATTACK #DetectionEngineering #CTI #ThreatIntel #BlueTeam #Infosec #CyberDefense #MITRE #ICS #CloudSecurity #MobileSecurity
-
New phishing technique - CoPhish - weaponizes Microsoft Copilot Studio to steal Entra ID OAuth tokens.
Attackers build malicious AI agents hosted on legitimate Microsoft domains, exfiltrating tokens via “Login” flows that appear genuine.
Uses OAuth T1528 techniques + token forwarding through Microsoft IPs for stealth.
🛡️ Detection ideas:
- Monitor consent grants in Entra ID logs.
- Restrict unverified app registrations.
- Disable user app creation.
- Flag Copilot bots using trial tenants or untrusted domains.How are you tuning detections for AI-driven OAuth phishing?
💬 Share your strategies & follow @technadu for more technical threat intel.#OAuth #Phishing #Microsoft #Copilot #CloudSecurity #ThreatHunting #AIsecurity #EntraID #MITREATtack #InfoSec #TechNadu
-
Already becoming a tradition—our team is back in Brussels for the 2025 MITRE ATT&CK® Community Workshop!
This year, SOC Prime Founder & CEO Andrii Bezverkhyi held the stage to discuss AI and LLMs as game changers in the cybersecurity domain.
#mitreattack -
🔍 New blog post: Understanding Reconnaissance - How Attackers Gather Intelligence
-
I am looking for someone who has experience with the MITRE ATT&CK framework and can answer my questions (German/English)
#security #SecOps #mitre #MitreAttack #InformationSecurity #InformationsSicherheit #apt
-
📢 Hey #security analysts... let's talk about MITRE D3FEND! 🗣️ 👀 From the same people who brought you the MITRE ATT&CK framework comes the D3FEND knowledge graph — a standardized vocabulary for understanding the different actions you can take to protect yourself. By using D3FEND, you can map ATT&CK Mitigations to your current tooling to identify gaps and build a stronger security program. 🔒 🙌
In our latest blog you can learn all about"
🛡️ D3FEND tactics
🛡️ D3FEND techniques
🛡️ Digital artifacts
🛡️ How to use D3FEND
...and more.https://graylog.org/post/what-is-mitre-d3fend/ #mitreattack #mitredefend #cybersecurity #infosec
-
I'm just working on a #ThreatModeling workshop with #EoP and I just wondered, is there an equivalent of Threat Modeling for IT? You could use #MitreAttack for something similar but I'm missing the cooperative teamwork of EoP
#CyberSecurityDo you know about a similar technic, methodology, ... with a focus on IT? Please let me know what you use
-
I'm just working on a #ThreatModeling workshop with #EoP and I just wondered, is there an equivalent of Threat Modeling for IT? You could use #MitreAttack for something similar but I'm missing the cooperative teamwork of EoP
#CyberSecurity -
Duiding en Mitre ATT&CK mapping TK brief PolitieHack
"Zoals gemeld in mijn brief van 27 september"
- 2024-09-27 First reported
"is een politieaccount gehackt"
- Credential Access TA0006 https://attack.mitre.org/tactics/TA0006/
- Initial Access > Valid Accounts T1078 https://attack.mitre.org/techniques/T1078/
"Het lijkt te gaan om de global address list"
- Collection TA0009 https://attack.mitre.org/tactics/TA0009/
- Exfiltration TA0010 https://attack.mitre.org/tactics/TA0010/
"De AIVD en MIVD hebben de politie geïnformeerd over het cyberincident"
- Lijkt er op te duiden dat er geen (of te laat) eigen detectie was.
"[AIVD & MIVD] achten het zeer waarschijnlijk dat een statelijke actor verantwoordelijk is"
- "Zeer waarschijnlijk" is het hoogste niveau van waarschijnlijkheid van de diensten. Uit een recent stuk "Anti institutioneel extremisme in Nederland" (https://www.aivd.nl/onderwerpen/extremisme/documenten/publicaties/2023/05/25/anti-institutioneel-extremisme-in-nederland-een-ernstige-dreiging-voor-de-democratische-rechtsorde):
De AIVD geeft de onzekerheden in deze inschattingen aan door gebruik te maken van ‘waarschijnlijkheidstermen’. Van minst tot meest waarschijnlijk zijn dit: ‘onwaarschijnlijk’, ‘twijfelachtig’, ‘mogelijk’, ‘waarschijnlijk’ en ‘zeer waarschijnlijk’.
Next steps
Concrete duidelijkheid over alle punten waar we nu alleen de algemene "TA" duiding hebben, is relevant voor verdere detectie bij eventuele andere, en toekomstige slachtoffers.
Mitre ATT&CK (https://attack.mitre.org/tactics/enterprise/) heeft voor zover ik kan nagaan zwakke of geen goede adversary technieken en/of mitigatie technieken voor dit type aanval. Die stappen toevoegen gaat het model ook verder helpen.
Bronnen:
- Tweede Kamer brief: https://open.overheid.nl/documenten/dpc-6bb8e12115dcff7c81a03663a4e340f79fb2ec2f/pdf
- Interview met Corpschef Nationale Politie: https://npo.nl/start/serie/nieuwsuur/seizoen-2024/nieuwsuur_4863/afspelen
-
Why do adversaries deploy #DDoS attacks, and how do these attacks impact business operations? 😓 Get the 411 on DDoS attacks, in our latest blog. 👀
#Graylog's Jeff Darrington explains the common DDoS attack types, and most importantly, he shares 9 specific steps you can take to mitigate your DDoS attack risk. 🙌
https://graylog.org/post/how-to-stop-a-ddos-attack/ #cybersecurity #mitreattack
-
A good understanding of the MITRE ATT&CK API-based techniques will help you improve your overall #security posture.🔒👍 So, let's talk about API-based techniques and sub-techniques.🤔
This blog will walk you through:
✔ Enterprise API techniques and mitigations
✔ Native API, technique T1106
✔ Credential API hooking, sub-technique T1056.004
✔ Container API, sub-technique T1552.007
✔ Dynamic API resolution, sub-technique T127.007
✔ Cloud API, sub-technique T1059.009
✔ Cloud instance metadata API, sub-technique T1552.005Plus, learn about integrating API monitoring into threat detection and incident response. 🙌
https://graylog.org/post/mitre-attck-api-based-enterprise-techniques-and-sub-techniques/ #MITREattack #APIsecurity #TDIR #cybersecurity
-
As you build out your incident detection and response capabilities, you should consider how IP address alert investigations map to the MITRE ATT&CK Framework. 🤔 Plus, you will want to consider how to correlate these alerts with other information generated by your environment. 👀 Take a look at this article to learn about:
🔒 Why IP addresses are important to security alerts
🗺 Mapping IP address information to ATT&CK
⚠ Additional events to correlate with suspicious IP address alerts
🔍 Threat detection and incident response (#TDIR) for IP address alert investigationshttps://graylog.org/post/ip-address-alerting-with-mitre-attck/ #mitreattack #IPaddress