MITRE ATT&CK — Matrice & Détection
Framework MITRE ATT&CK : 14 tactiques, techniques clés, mapping vers règles Sigma/SIEM et ATT&CK Navigator
Vue d'ensemble
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) est une base de connaissances des comportements adversariaux observés dans des attaques réelles.
URL https//attack.mitre.orgNavigator https//mitre-attack.github.io/attack-navigator/
Structure
Tactique POURQUOI Technique COMMENT Sous-technique dtailProcdure exemple rel
Les 14 Tactiques (Enterprise)
| ID | Tactique | Objectif attaquant | |----|----------|--------------------| | TA0043 | Reconnaissance | Collecter infos sur la cible | | TA0042 | Resource Development | Acquérir infra/comptes/outils | | TA0001 | Initial Access | Entrer dans le réseau | | TA0002 | Execution | Exécuter du code malveillant | | TA0003 | Persistence | Maintenir l'accès | | TA0004 | Privilege Escalation | Obtenir plus de droits | | TA0005 | Defense Evasion | Éviter la détection | | TA0006 | Credential Access | Voler des credentials | | TA0007 | Discovery | Cartographier l'environnement | | TA0008 | Lateral Movement | Se déplacer dans le réseau | | TA0009 | Collection | Collecter données d'intérêt | | TA0011 | Command and Control | Communiquer avec les implants | | TA0010 | Exfiltration | Exporter les données volées | | TA0040 | Impact | Détruire, chiffrer, saboter |
Techniques clés par tactique
Initial Access (TA0001)
| Technique | ID | Description | |-----------|-----|-------------| | Phishing | T1566 | Email malveillant avec pièce jointe/lien | | Valid Accounts | T1078 | Utiliser des credentials légitimes volés | | Exploit Public-Facing App | T1190 | CVE sur service exposé | | Trusted Relationship | T1199 | Compromission d'un partenaire/fournisseur |
Execution (TA0002)
| Technique | ID | Description | |-----------|-----|-------------| | PowerShell | T1059.001 | Scripts PowerShell malveillants | | Windows Command Shell | T1059.003 | cmd.exe | | Scheduled Task | T1053.005 | Tâches planifiées | | WMI | T1047 | Windows Management Instrumentation |
Persistence (TA0003)
| Technique | ID | Description | |-----------|-----|-------------| | Registry Run Keys | T1547.001 | Clés Run/RunOnce | | Scheduled Task | T1053.005 | Persistance via tâche | | Create Account | T1136 | Nouveau compte backdoor | | Boot/Logon Script | T1037 | Script exécuté au démarrage |
Privilege Escalation (TA0004)
| Technique | ID | Description | |-----------|-----|-------------| | Sudo/Sudo Caching | T1548.003 | Abus de sudo Linux | | Token Impersonation | T1134 | Usurpation de token Windows | | DLL Hijacking | T1574.001 | Charger DLL malveillante | | Kerberoasting | T1558.003 | Attaque tickets Kerberos |
Defense Evasion (TA0005)
| Technique | ID | Description | |-----------|-----|-------------| | Obfuscated Files | T1027 | Obfuscation de payload | | Indicator Removal | T1070 | Effacement de logs | | LOLBAS | T1218 | Living off the Land | | Disable Security Tools | T1562 | Désactiver AV/EDR |
Credential Access (TA0006)
| Technique | ID | Description | |-----------|-----|-------------| | OS Credential Dumping | T1003 | LSASS, SAM, NTDS.dit | | Brute Force | T1110 | Password spraying | | Keylogging | T1056.001 | Capture clavier | | Pass the Hash | T1550.002 | Réutilisation de hash NTLM |
Lateral Movement (TA0008)
| Technique | ID | Description | |-----------|-----|-------------| | Pass the Hash | T1550.002 | Mouvement avec hash | | Remote Services (SMB) | T1021.002 | PsExec, SMB exec | | Remote Desktop | T1021.001 | RDP | | WMI | T1047 | Exécution distante via WMI |
Mapping vers règles Sigma
# Exemple : détection Kerberoasting (T1558.003)title: Kerberoasting - SPN Requestid: 18a21fc4-a72b-11ed-a8fc-0242ac120002status: stabledescription: Detects Kerberoasting via TGS-REQ with RC4 encryptionreferences:- https://attack.mitre.org/techniques/T1558/003/tags:- attack.credential_access- attack.t1558.003logsource:product: windowsservice: securitydetection:selection:EventID: 4769TicketOptions: '0x40810000'TicketEncryptionType: '0x17' # RC4 — signe de Kerberoastingfilter:ServiceName|endswith: '$' # Exclure comptes machinecondition: selection and not filterfalsepositives:- Applications legacy utilisant RC4level: high
# Détection PowerShell encodé (T1059.001)title: Suspicious PowerShell Encoded Commandtags:- attack.execution- attack.t1059.001logsource:product: windowscategory: process_creationdetection:selection:CommandLine|contains:- ' -EncodedCommand '- ' -enc '- ' -ec 'Image|endswith: '\powershell.exe'condition: selectionlevel: medium
ATT&CK Navigator — Utilisation
# Créer une couverture de détection1 Ouvrir navigatormitreorg2 New Layer > Enterprise ATT&CK3 Colorer les techniques selon le statutVert Dtecte rgle SIEM en placeJaune Partielle log disponible pas de rgleRouge Non couverte4 Exporter en SVG/PNG/JSON pour reporting# Cas d'usagevaluer la couverture dtection de votre SOCMapper les TTP dun APT spcifiquePlanifier les exercices Red TeamPrioriser les investissements dfensifs
Groupes APT et leurs TTP
| Groupe | ID | TTP principaux | |--------|-----|----------------| | APT28 (Fancy Bear) | G0007 | T1566, T1078, T1059 | | Lazarus | G0032 | T1189, T1190, T1071 | | FIN7 | G0046 | T1566.001, T1059.001, T1055 | | Cozy Bear (APT29) | G0016 | T1078, T1021, T1003 |
# Récupérer les TTP d'un groupe via APIcurl https//attack.mitre.org/api/groups/G0007 | jq '.techniques'
Intégration SIEM — Tableau de bord
# Champs recommandés dans les logsmitre_tacticmitre_technique_idmitre_technique_name# Règle ELK (Kibana Alerting)Chaque alerte Sigma mappe tag mitreDashboard rpartition des alertes par tactique MITREvisualiser instantanment les gaps de couverture