mitreattckttp
MDstable
NoteSnippetChecklistPlaybook
MITRE ATT&CK — Matrice & Détection
Framework MITRE ATT&CK : 14 tactiques, techniques clés, mapping vers règles Sigma/SIEM et ATT&CK Navigator
noteintermediate 2026-05-30 5 min read
mitreattckttpdetectionsigmasocthreat-intel
Vue d'ensemble
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) est une base de connaissances des comportements adversariaux observés dans des attaques réelles.
URL https//attack.mitre.orgNavigator https//mitre-attack.github.io/attack-navigator/
Structure
Tactique POURQUOI Technique COMMENT Sous-technique dtailProcdure exemple rel
Les 14 Tactiques (Enterprise)
| ID | Tactique | Objectif attaquant |
|---|---|---|
| TA0043 | Reconnaissance | Collecter infos sur la cible |
| TA0042 | Resource Development | Acquérir infra/comptes/outils |
| TA0001 | Initial Access | Entrer dans le réseau |
| TA0002 | Execution | Exécuter du code malveillant |
| TA0003 | Persistence | Maintenir l'accès |
| TA0004 | Privilege Escalation | Obtenir plus de droits |
| TA0005 | Defense Evasion | Éviter la détection |
| TA0006 | Credential Access | Voler des credentials |
| TA0007 | Discovery | Cartographier l'environnement |
| TA0008 | Lateral Movement | Se déplacer dans le réseau |
| TA0009 | Collection | Collecter données d'intérêt |
| TA0011 | Command and Control | Communiquer avec les implants |
| TA0010 | Exfiltration | Exporter les données volées |
| TA0040 | Impact | Détruire, chiffrer, saboter |
Techniques clés par tactique
Initial Access (TA0001)
| Technique | ID | Description |
|---|---|---|
| Phishing | T1566 | Email malveillant avec pièce jointe/lien |
| Valid Accounts | T1078 | Utiliser des credentials légitimes volés |
| Exploit Public-Facing App | T1190 | CVE sur service exposé |
| Trusted Relationship | T1199 | Compromission d'un partenaire/fournisseur |
Execution (TA0002)
| Technique | ID | Description |
|---|---|---|
| PowerShell | T1059.001 | Scripts PowerShell malveillants |
| Windows Command Shell | T1059.003 | cmd.exe |
| Scheduled Task | T1053.005 | Tâches planifiées |
| WMI | T1047 | Windows Management Instrumentation |
Persistence (TA0003)
| Technique | ID | Description |
|---|---|---|
| Registry Run Keys | T1547.001 | Clés Run/RunOnce |
| Scheduled Task | T1053.005 | Persistance via tâche |
| Create Account | T1136 | Nouveau compte backdoor |
| Boot/Logon Script | T1037 | Script exécuté au démarrage |
Privilege Escalation (TA0004)
| Technique | ID | Description |
|---|---|---|
| Sudo/Sudo Caching | T1548.003 | Abus de sudo Linux |
| Token Impersonation | T1134 | Usurpation de token Windows |
| DLL Hijacking | T1574.001 | Charger DLL malveillante |
| Kerberoasting | T1558.003 | Attaque tickets Kerberos |
Defense Evasion (TA0005)
| Technique | ID | Description |
|---|---|---|
| Obfuscated Files | T1027 | Obfuscation de payload |
| Indicator Removal | T1070 | Effacement de logs |
| LOLBAS | T1218 | Living off the Land |
| Disable Security Tools | T1562 | Désactiver AV/EDR |
Credential Access (TA0006)
| Technique | ID | Description |
|---|---|---|
| OS Credential Dumping | T1003 | LSASS, SAM, NTDS.dit |
| Brute Force | T1110 | Password spraying |
| Keylogging | T1056.001 | Capture clavier |
| Pass the Hash | T1550.002 | Réutilisation de hash NTLM |
Lateral Movement (TA0008)
| Technique | ID | Description |
|---|---|---|
| Pass the Hash | T1550.002 | Mouvement avec hash |
| Remote Services (SMB) | T1021.002 | PsExec, SMB exec |
| Remote Desktop | T1021.001 | RDP |
| WMI | T1047 | Exécution distante via WMI |
Mapping vers règles Sigma
yaml
# Exemple : détection Kerberoasting (T1558.003)title: Kerberoasting - SPN Requestid: 18a21fc4-a72b-11ed-a8fc-0242ac120002status: stabledescription: Detects Kerberoasting via TGS-REQ with RC4 encryptionreferences:- https://attack.mitre.org/techniques/T1558/003/tags:- attack.credential_access- attack.t1558.003logsource:product: windowsservice: securitydetection:selection:EventID: 4769TicketOptions: '0x40810000'TicketEncryptionType: '0x17' # RC4 — signe de Kerberoastingfilter:ServiceName|endswith: '$' # Exclure comptes machinecondition: selection and not filterfalsepositives:- Applications legacy utilisant RC4level: high
yaml
# Détection PowerShell encodé (T1059.001)title: Suspicious PowerShell Encoded Commandtags:- attack.execution- attack.t1059.001logsource:product: windowscategory: process_creationdetection:selection:CommandLine|contains:- ' -EncodedCommand '- ' -enc '- ' -ec 'Image|endswith: '\powershell.exe'condition: selectionlevel: medium
ATT&CK Navigator — Utilisation
# Créer une couverture de détection1 Ouvrir navigatormitreorg2 New Layer > Enterprise ATT&CK3 Colorer les techniques selon le statutVert Dtecte rgle SIEM en placeJaune Partielle log disponible pas de rgleRouge Non couverte4 Exporter en SVG/PNG/JSON pour reporting# Cas d'usagevaluer la couverture dtection de votre SOCMapper les TTP dun APT spcifiquePlanifier les exercices Red TeamPrioriser les investissements dfensifs
Groupes APT et leurs TTP
| Groupe | ID | TTP principaux |
|---|---|---|
| APT28 (Fancy Bear) | G0007 | T1566, T1078, T1059 |
| Lazarus | G0032 | T1189, T1190, T1071 |
| FIN7 | G0046 | T1566.001, T1059.001, T1055 |
| Cozy Bear (APT29) | G0016 | T1078, T1021, T1003 |
bash
# Récupérer les TTP d'un groupe via APIcurl https//attack.mitre.org/api/groups/G0007 | jq '.techniques'
Intégration SIEM — Tableau de bord
# Champs recommandés dans les logsmitre_tacticmitre_technique_idmitre_technique_name# Règle ELK (Kibana Alerting)Chaque alerte Sigma mappe tag mitreDashboard rpartition des alertes par tactique MITREvisualiser instantanment les gaps de couverture
OPS·BRAIN v1.090 notes · Securitylocal