In part one of a three part series, Adrian Bishop, Head of engineering at Huntsman Security, explains how to use the MITRE ATT&CK framework to defend against cyber-attacks
No matter how small or large, any business could easily fall into the sights of a cyber-criminal out to make a quick buck. But becoming a target doesn’t have to mean falling victim. There are several stages during an attack where your organisation has the opportunity to ward off an attacker and keep your data safe.
One strategy for staying out of the headlines is by using cyber-security frameworks such as MITRE ATT&CK®. Specifically, MITRE ATT&CK is a vast knowledge base which details the tactics and techniques used by cyber-adversaries, giving you a way of getting inside an attacker’s head and ensuring your cyber-defences are up to scratch.
MITRE ATT&CK uses Techniques to detail the different actions an attacker can perform. Techniques are given unique IDs and grouped into Tactics each of which describes the objective the attacker is trying to achieve at different stages of an attack.
Unfortunately, the sheer amount of information within MITRE ATT&CK can make it hard to apply the learnings from the framework to your organisation’s defence strategies.
To help organisations make use of the MITRE ATT&CK framework this series of three articles will analyse a theoretical cyber-attack and explain how you could apply MITRE ATT&CK to prevent and detect an attack by improving your security defences, monitoring and processes.
The different stages of the attack scenario will be described under the relevant Tactic group, followed by details of how the MITRE ATT&CK® Framework maps these to the observed actions.
In this first part, we will follow the first few stages of an attack, highlighting what our hypothetical hacker has done and what teams could do to defend against the attack.
Our theoretical scenario begins with a spear-phishing email, sent by an attacker to specific employees to lure them into browsing a compromised website. There’s no attachment, and the website does not have a malicious reputation, so the email is not blocked by email filters. The website is or appears familiar to the user, so they are confident browsing it. This is exactly what the attacker wants.
When infiltrating a system or network, attackers need to find and exploit a weakness. The techniques used to achieve this initial entry to a system fall under the Initial Access Tactic group and include:
In our attack scenario a combination of two Techniques are used:
When an employee is lured into clicking on the malicious link, the attack moves from the Initial Access phase to Execution which is the point where the attacker will try to run malicious code.
When the user browses the compromised website JavaScript is used to exploit a vulnerability within the web browser and in turn run a VBscript. The VBscript executes PowerShell commands on the host to download and run staging files that can continue the attack.
Being able to execute code is a foundation of many Tactics and their Techniques, and so Execution Techniques are frequently seen at multiple stages of an attack, such as:
At this point in our scenario, the attackers have executed a sequence of four Techniques in quick succession:
At this point the attacker has almost finished laying the foundation for their future activities, but they need to ensure they can re-access the system at any time, for instance, if it is restarted.
As such, once the staging files are downloaded they are executed and establish connectivity with the attacker’s Command & Control server from which further files can be downloaded and executed on the compromised system when needed.
The staging files also set up a persistent presence on the target system, by creating a scheduled task that executes whenever the user logs on.
The attacker has now created a reliable means for future access and control and the Persistence Tactic includes Techniques associated with this objective:
Our scenario uses two Techniques to establish persistence:
MITRE ATT&CK details both the steps and commands an attacker can use to perform the stages in this attack, and also recommendations for detecting and mitigating the Techniques used.
Recommendations may be specific to one particular Technique or broad and cover a number of Techniques in different Tactics. This allows the detection and mitigation recommendations to be assessed so those that are easier to perform or provide wider coverage can be implemented first.
For the Techniques used in the three stages of our attack scenario, MITRE ATT&CK includes the following mitigations:
To further assist mitigation efforts MITRE ATT&CK includes the following detection recommendations:
If you are unable to detect and stop the attack at this point, then the next stage will be infiltration, where attackers explore the network and compromise other systems and accounts. This will be the focus of the second article in this three-part series, so be sure to check back for part 2 next week.
Adrian Bishop is Head of Engineering at Huntsman Security
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543