ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Using the MITRE ATT&CK framework for cyber-defence

In part one of a three part series, Adrian Bishop, Head of engineering at Huntsman Security, explains how to use the MITRE ATT&CK framework to defend against cyber-attacks

 

No matter how small or large, any business could easily fall into the sights of a cyber-criminal out to make a quick buck. But becoming a target doesn’t have to mean falling victim. There are several stages during an attack where your organisation has the opportunity to ward off an attacker and keep your data safe.

 

One strategy for staying out of the headlines is by using cyber-security frameworks such as MITRE ATT&CK®. Specifically, MITRE ATT&CK is a vast knowledge base which details the tactics and techniques used by cyber-adversaries, giving you a way of getting inside an attacker’s head and ensuring your cyber-defences are up to scratch.

 

MITRE ATT&CK uses Techniques to detail the different actions an attacker can perform.  Techniques are given unique IDs and grouped into Tactics each of which describes the objective the attacker is trying to achieve at different stages of an attack.

 

Unfortunately, the sheer amount of information within MITRE ATT&CK can make it hard to apply the learnings from the framework to your organisation’s defence strategies.

 

To help organisations make use of the MITRE ATT&CK framework this series of three articles will analyse a theoretical cyber-attack and explain how you could apply MITRE ATT&CK to prevent and detect an attack by improving your security defences, monitoring and processes.

 

The different stages of the attack scenario will be described under the relevant Tactic group, followed by details of how the MITRE ATT&CK® Framework maps these to the observed actions.

 

In this first part, we will follow the first few stages of an attack, highlighting what our hypothetical hacker has done and what teams could do to defend against the attack.

 

Stage 1: The initial attack

Our theoretical scenario begins with a spear-phishing email, sent by an attacker to specific employees to lure them into browsing a compromised website. There’s no attachment, and the website does not have a malicious reputation, so the email is not blocked by email filters. The website is or appears familiar to the user, so they are confident browsing it. This is exactly what the attacker wants.

 

When infiltrating a system or network, attackers need to find and exploit a weakness. The techniques used to achieve this initial entry to a system fall under the Initial Access Tactic group and include: 

  • Compromising external websites visited by employees
  • Hacking Internet facing applications within the organisation
  • Abusing remote access solutions
  • Targeting employees with phishing campaigns
  • Using compromised valid user accounts 

In our attack scenario a combination of two Techniques are used:

  • T1566.002 – Spear-phishing Link: a spear-phishing email containing a link to a compromised website. This has been widely used by many attackers including the Chinese based APT1 and APT3 threat groups.
  • T1189 – Drive-by Compromise: so called, because a user may “drive-by” or visit the compromised website simply as part of their normal browsing routine. The APT19 threat group used this technique in 2014 when they compromised forbes.com to target visitors to the site. 

Stage 2: Execution

When an employee is lured into clicking on the malicious link, the attack moves from the Initial Access phase to Execution which is the point where the attacker will try to run malicious code.

 

When the user browses the compromised website JavaScript is used to exploit a vulnerability within the web browser and in turn run a VBscript. The VBscript executes PowerShell commands on the host to download and run staging files that can continue the attack.

 

Being able to execute code is a foundation of many Tactics and their Techniques, and so Execution Techniques are frequently seen at multiple stages of an attack, such as:

  • Using in-built commands, scripting tools or commonly found languages e.g. PowerShell, Unix shells, Python and JavaScript
  • Exploiting application weaknesses and vulnerabilities
  • Creating scheduled tasks / events or system services
  • Socially engineering a user to run software 

At this point in our scenario, the attackers have executed a sequence of four Techniques in quick succession:

  • T1059.007 – JavaScript: web page exploit code
  • T1203 – Exploitation for Client Execution: JavaScript code exploits the web browser
  • T1059.005 – Visual Basic: internal language within the web browser provides access to an operating system
  • T1059.001 – PowerShell: operating system command shell provides access to commands to download files 

Stage 3: Persistence

At this point the attacker has almost finished laying the foundation for their future activities, but they need to ensure they can re-access the system at any time, for instance, if it is restarted.

 

As such, once the staging files are downloaded they are executed and establish connectivity with the attacker’s Command & Control server from which further files can be downloaded and executed on the compromised system when needed.

 

The staging files also set up a persistent presence on the target system, by creating a scheduled task that executes whenever the user logs on.

 

The attacker has now created a reliable means for future access and control and the Persistence Tactic includes Techniques associated with this objective:

  • Creating or modifying accounts so that they can be used for remote access or control
  • Modifying authentication processes
  • Downloading and executing files
  • Automatically starting or executing scripts or programs
  • Utilising external remote services 

Our scenario uses two Techniques to establish persistence:

  • T1059.001 – PowerShell: an Execution Technique used to execute downloaded files
  • T1053.005 – Scheduled Task: the executed files create a scheduled task to ensure they get re-executed each time the user logs on

What can you do to defend yourself?

MITRE ATT&CK details both the steps and commands an attacker can use to perform the stages in this attack, and also recommendations for detecting and mitigating the Techniques used.

 

Recommendations may be specific to one particular Technique or broad and cover a number of Techniques in different Tactics. This allows the detection and mitigation recommendations to be assessed so those that are easier to perform or provide wider coverage can be implemented first.

 

For the Techniques used in the three stages of our attack scenario, MITRE ATT&CK includes the following mitigations:

  • Email gateway content verification: so spearfishing attempts are automatically spotted
  • Web content inspection: to stop employees browsing to malicious websites and block malicious scripts
  • Enable browser sandboxes, adblockers and OS exploit mitigation tools: to minimise the risk of downloading malicious code
  • Install software and operating system updates: to minimise exploit opportunities
  • Install endpoint protection / anti-malware solutions on endpoints: to reduce the risk of malicious code being executed
  • Require PowerShell scripts to be signed or block script execution: Tto reduce the risk of some exploits succeeding
  • Disable / uninstall PowerShell on hosts: as above, a further step to reduce the risk of exploits being executed
  • User training: to educate employees on cyber-risks

 To further assist mitigation efforts MITRE ATT&CK includes the following detection recommendations:

  • Detect connections to known malicious websites and servers: to highlight attempted breaches from malware
  • Detect the creation of unusual processes, or executed commands, by scripts: to ensure potential attacks can be spotted and foiled as soon as possible
  • Detect the creation of scheduled tasks: to ensure these aren’t being used to execute malware

If you are unable to detect and stop the attack at this point, then the next stage will be infiltration, where attackers explore the network and compromise other systems and accounts. This will be the focus of the second article in this three-part series, so be sure to check back for part 2 next week.

 


 

Adrian Bishop is Head of Engineering at Huntsman Security

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543