Skip to content

Commit

Permalink
Update whatistid.rst
Browse files Browse the repository at this point in the history
M3TID final v1.0 changes, as of 13 Feb 2024.
  • Loading branch information
forrestcarver authored Feb 13, 2024
1 parent 7543703 commit 1b2622e
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/whatistid.rst
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ There are many types of threat information and many sources from which to learn

ATT&CK Framework

David Bianco famously depicted this potential with his “Pyramid of Pain, which illustrates how difficult it is for an adversary to evade a defense that is informed by, and effective against, different levels of information about adversary tradecraft. In the Pyramid of Pain, indicators such as IP addresses, hash values, and domain names are shown to be easy for an adversary to alter and thus evade defenses that are dependent on them. However, TTPs are positioned at the top of the pyramid, reflecting the difficulty an adversary would have if a defender was effectively detecting and mitigating at that level.
David Bianco famously depicted this potential with his “Pyramid of Pain” [#f2]_, which illustrates how difficult it is for an adversary to evade a defense that is informed by, and effective against, different levels of information about adversary tradecraft. In the Pyramid of Pain, indicators such as IP addresses, hash values, and domain names are shown to be easy for an adversary to alter and thus evade defenses that are dependent on them. However, TTPs are positioned at the top of the pyramid, reflecting the difficulty an adversary would have if a defender was effectively detecting and mitigating at that level.

.. figure:: _static/pyramidofpain.png
:alt: Pyramid of Pain
Expand Down

0 comments on commit 1b2622e

Please sign in to comment.