The Cyber Kill Chain & MITRE ATT&CK Framework Explained
HELLO FRIENDS
WELCOME TO MY CYPHER LOG
guys in this blog we are going to see about an interesting concept which is cyber kill chain and MITRE ATT & CK, that's what I have learned today actually it's quite interesting.
LETS DIVE INTO THE TOPIC
The cyber kill chain attack
You can easily figure out what it would be by its name, yeah it acts like a chain of 7 sequential steps for an attack to get succeed, an attacker needs to complete all these steps in this chain to make his plan succeed.
Now you may think about how this cyber kill chain works, as we have seen above attackers need to do 7 steps but an investigator needs to identify a single step in this to break the chain,
I know it would make you guys a little confused, we can take an example for this to be more clear, we all know that if we plant a tree we need to do more processes and procedures like watering the plant and protecting it and it also takes months of time, but if we want to cut that same tree all we need to do is to cut that's how this this cyber kill chain works.
Like we watering the tree here are the 7 steps to make that attack possible
Reconnaissance
Reconnaissance is doing research about the victim whom the attacker wants to attack and this is the first step because if the attacker gets an overview about the victim he can easily approach them.
Weaponization
The attacker creates a malicious payload like how he wants to attack if he wants to send the Trojan horse through a fake pdf invoice. He set that weapon
If there's a war about to happen then the military officers will make their weapons ready to attack anytime that's how it works.
Delivery
Delivery is nothing but delivering the weapon he already created through phishing or hosting the malware on a compromised website.
Exploitation
As we have seen in the above example of weaponization, if the war began and they throw the grenade and someone needs to trigger it by removing the pin.
Attackers already send the malicious code, if we open the phishing email and touch the link it would trigger the malicious code.
Installation
The malware triggered and it installs a persistent backdoor on the victim's system by this the attacker can return later, to be more clear, as the grenade triggered by removing the pin and now it would break the door or it destroys the hurdles in front the enemies and it would make a pathway for them.
Command control
We have already seen this command control in our 8th day blog which is network based attacks.
The machine which was installed an persistent malware or an infected machine of the victim would connects back to the attacker's server to receive instruction to move that attack forward,
To make it clear,
The grenade made a pathway now the soldiers would enter through that and they must connect to the commander to do the next move to tackle the opposition.
That's how it works.
Action on objectives
This is the last step which the attacker successfully achieved his goal to steal the data or any type of attack he wants to do.
Now let's move into the next part which is,
The MITRE ATT & CK Framework
While The cyber kill chain is a great high level overview, it is a bit too simple for modern complex problems,
Here the ATT & CK stands for adversarial tactics, technique and common knowledge.
This is act like an dictionary or an encyclopedia which have every types tactics of the attacker by this we can easily identify what the attacker going to do with some suspicious behaviour.
In the dictionary we would search the word by the first letter here we can find the hackers behaviour by a word.
Key concepts of TTPs
The TTPs stands for Tactics, Techniques and procedures.
Tactics
Tactics is, why the attacker doing something.
Techniques
Techniques is how the attacker do something.
Procedures
Procedure is how the attacker use some specific ways to do the attack.
By this,
If an investigator sees a specific unusual procedure they would search that in the MITRE database and it would give the whole information about how it can happen where it is already happened. By this investigators easily find out the attacker.
So that's it guys it's all I have learned today let's see in another blog stay tuned for the next blog.
If you want study guide to know more about this topic you can get through this link.

Comments
Post a Comment