Tag: TDM

Warming Up. Using ATT&CK for Self Advancement

Introduction Many blue teams are using MITRE ATT&CK for advancement in the maturity of their detection and response. Blue teamā€™s arsenal of EDR tools, event logs, and triage tools are all opening up the story of whatā€™s occurring on endpoints. However, anomalies are normal and these alerts and data sources need to be triaged to […]

Read More