MDstable
NoteSnippetChecklistPlaybook

MITRE ATT&CK — Matrice & Détection

Framework MITRE ATT&CK : 14 tactiques, techniques clés, mapping vers règles Sigma/SIEM et ATT&CK Navigator

noteintermediate 2026-05-30 5 min read
mitreattckttpdetectionsigmasocthreat-intel

Vue d'ensemble

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) est une base de connaissances des comportements adversariaux observés dans des attaques réelles.

URL https//attack.mitre.org
Navigator https//mitre-attack.github.io/attack-navigator/

Structure

Tactique POURQUOI Technique COMMENT Sous-technique dtail
Procdure exemple rel

Les 14 Tactiques (Enterprise)

| ID | Tactique | Objectif attaquant | |----|----------|--------------------| | TA0043 | Reconnaissance | Collecter infos sur la cible | | TA0042 | Resource Development | Acquérir infra/comptes/outils | | TA0001 | Initial Access | Entrer dans le réseau | | TA0002 | Execution | Exécuter du code malveillant | | TA0003 | Persistence | Maintenir l'accès | | TA0004 | Privilege Escalation | Obtenir plus de droits | | TA0005 | Defense Evasion | Éviter la détection | | TA0006 | Credential Access | Voler des credentials | | TA0007 | Discovery | Cartographier l'environnement | | TA0008 | Lateral Movement | Se déplacer dans le réseau | | TA0009 | Collection | Collecter données d'intérêt | | TA0011 | Command and Control | Communiquer avec les implants | | TA0010 | Exfiltration | Exporter les données volées | | TA0040 | Impact | Détruire, chiffrer, saboter |


Techniques clés par tactique

Initial Access (TA0001)

| Technique | ID | Description | |-----------|-----|-------------| | Phishing | T1566 | Email malveillant avec pièce jointe/lien | | Valid Accounts | T1078 | Utiliser des credentials légitimes volés | | Exploit Public-Facing App | T1190 | CVE sur service exposé | | Trusted Relationship | T1199 | Compromission d'un partenaire/fournisseur |

Execution (TA0002)

| Technique | ID | Description | |-----------|-----|-------------| | PowerShell | T1059.001 | Scripts PowerShell malveillants | | Windows Command Shell | T1059.003 | cmd.exe | | Scheduled Task | T1053.005 | Tâches planifiées | | WMI | T1047 | Windows Management Instrumentation |

Persistence (TA0003)

| Technique | ID | Description | |-----------|-----|-------------| | Registry Run Keys | T1547.001 | Clés Run/RunOnce | | Scheduled Task | T1053.005 | Persistance via tâche | | Create Account | T1136 | Nouveau compte backdoor | | Boot/Logon Script | T1037 | Script exécuté au démarrage |

Privilege Escalation (TA0004)

| Technique | ID | Description | |-----------|-----|-------------| | Sudo/Sudo Caching | T1548.003 | Abus de sudo Linux | | Token Impersonation | T1134 | Usurpation de token Windows | | DLL Hijacking | T1574.001 | Charger DLL malveillante | | Kerberoasting | T1558.003 | Attaque tickets Kerberos |

Defense Evasion (TA0005)

| Technique | ID | Description | |-----------|-----|-------------| | Obfuscated Files | T1027 | Obfuscation de payload | | Indicator Removal | T1070 | Effacement de logs | | LOLBAS | T1218 | Living off the Land | | Disable Security Tools | T1562 | Désactiver AV/EDR |

Credential Access (TA0006)

| Technique | ID | Description | |-----------|-----|-------------| | OS Credential Dumping | T1003 | LSASS, SAM, NTDS.dit | | Brute Force | T1110 | Password spraying | | Keylogging | T1056.001 | Capture clavier | | Pass the Hash | T1550.002 | Réutilisation de hash NTLM |

Lateral Movement (TA0008)

| Technique | ID | Description | |-----------|-----|-------------| | Pass the Hash | T1550.002 | Mouvement avec hash | | Remote Services (SMB) | T1021.002 | PsExec, SMB exec | | Remote Desktop | T1021.001 | RDP | | WMI | T1047 | Exécution distante via WMI |


Mapping vers règles Sigma

yaml
# Exemple : détection Kerberoasting (T1558.003)
title: Kerberoasting - SPN Request
id: 18a21fc4-a72b-11ed-a8fc-0242ac120002
status: stable
description: Detects Kerberoasting via TGS-REQ with RC4 encryption
references:
- https://attack.mitre.org/techniques/T1558/003/
tags:
- attack.credential_access
- attack.t1558.003
logsource:
product: windows
service: security
detection:
selection:
EventID: 4769
TicketOptions: '0x40810000'
TicketEncryptionType: '0x17' # RC4 — signe de Kerberoasting
filter:
ServiceName|endswith: '$' # Exclure comptes machine
condition: selection and not filter
falsepositives:
- Applications legacy utilisant RC4
level: high
yaml
# Détection PowerShell encodé (T1059.001)
title: Suspicious PowerShell Encoded Command
tags:
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- ' -EncodedCommand '
- ' -enc '
- ' -ec '
Image|endswith: '\powershell.exe'
condition: selection
level: medium

ATT&CK Navigator — Utilisation

# Créer une couverture de détection
1 Ouvrir navigatormitreorg
2 New Layer > Enterprise ATT&CK
3 Colorer les techniques selon le statut
Vert Dtecte rgle SIEM en place
Jaune Partielle log disponible pas de rgle
Rouge Non couverte
4 Exporter en SVG/PNG/JSON pour reporting
# Cas d'usage
valuer la couverture dtection de votre SOC
Mapper les TTP dun APT spcifique
Planifier les exercices Red Team
Prioriser les investissements dfensifs

Groupes APT et leurs TTP

| Groupe | ID | TTP principaux | |--------|-----|----------------| | APT28 (Fancy Bear) | G0007 | T1566, T1078, T1059 | | Lazarus | G0032 | T1189, T1190, T1071 | | FIN7 | G0046 | T1566.001, T1059.001, T1055 | | Cozy Bear (APT29) | G0016 | T1078, T1021, T1003 |

bash
# Récupérer les TTP d'un groupe via API
curl https//attack.mitre.org/api/groups/G0007 | jq '.techniques'

Intégration SIEM — Tableau de bord

# Champs recommandés dans les logs
mitre_tactic
mitre_technique_id
mitre_technique_name
# Règle ELK (Kibana Alerting)
Chaque alerte Sigma mappe tag mitre
Dashboard rpartition des alertes par tactique MITRE
visualiser instantanment les gaps de couverture
OPS·BRAIN v1.092 notes · Securitylocal