2020-10-23 17:30:38 +08:00
|
|
|
---
|
2020-10-23 22:46:23 +08:00
|
|
|
title: "MITRE ATT&CK assessment"
|
2020-10-23 17:30:38 +08:00
|
|
|
date: 2020-10-22T16:58:22+03:00
|
|
|
|
draft: false
|
2020-10-23 22:46:23 +08:00
|
|
|
description: "Assess your network security detection and prevention capabilities."
|
|
|
|
weight: 2
|
2020-10-23 17:30:38 +08:00
|
|
|
---
|
|
|
|
|
|
|
|
## Overview
|
|
|
|
|
2020-10-23 22:46:23 +08:00
|
|
|
Infection Monkey can simulate various [ATT&CK](https://attack.mitre.org/matrices/enterprise/) techniques on the network.
|
2021-01-28 02:13:25 +08:00
|
|
|
Use it to assess your security solutions' detection and prevention capabilities. Infection Monkey will help you find
|
2020-10-23 22:46:23 +08:00
|
|
|
which ATT&CK techniques go unnoticed and will provide recommendations about preventing them.
|
|
|
|
|
2020-10-23 17:30:38 +08:00
|
|
|
|
|
|
|
## Configuration
|
|
|
|
|
2020-10-23 22:46:23 +08:00
|
|
|
- **ATT&CK matrix** You can use ATT&CK configuration section to select which techniques you want the Monkey to simulate.
|
|
|
|
Leave default settings for the full simulation.
|
2020-10-23 17:30:38 +08:00
|
|
|
- **Exploits -> Credentials** This configuration value will be used for brute-forcing. We use most popular passwords
|
2020-10-23 22:46:23 +08:00
|
|
|
and usernames, but feel free to adjust it according to the default passwords used in your network. Keep in mind that
|
|
|
|
long lists means longer scanning times.
|
|
|
|
- **Network -> Scope** Disable “Local network scan” and instead provide specific network ranges in
|
|
|
|
the “Scan target list”.
|
2020-10-23 17:30:38 +08:00
|
|
|
|
|
|
|
![ATT&CK matrix](/images/usage/scenarios/attack-matrix.png "ATT&CK matrix")
|
|
|
|
|
|
|
|
## Suggested run mode
|
|
|
|
|
2020-10-23 22:46:23 +08:00
|
|
|
Run the Infection Monkey on as many machines in your environment as you can to get a better assessment. This can be easily
|
|
|
|
achieved by selecting the “Manual” run option and executing the command shown on different machines in your environment
|
|
|
|
manually or with your deployment tool.
|
2020-10-23 17:30:38 +08:00
|
|
|
|
|
|
|
## Assessing results
|
|
|
|
|
2020-10-23 22:46:23 +08:00
|
|
|
The **ATT&CK Report** shows the status of ATT&CK techniques simulations. Click on any technique to see more details
|
|
|
|
about it and potential mitigations. Keep in mind that each technique display contains a question mark symbol that
|
|
|
|
will take you to the official documentation of ATT&CK technique, where you can learn more about it.
|