Skip to content

Commit

Permalink
update to v16.0
Browse files Browse the repository at this point in the history
  • Loading branch information
adpare committed Oct 31, 2024
2 parents a7b1995 + 9237fc3 commit 9ecedc5
Show file tree
Hide file tree
Showing 7 changed files with 38 additions and 16 deletions.
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,10 @@
# v4.2.0 (2024-10-31)

## Features

* Release ATT&CK content version 16.0.
See detailed changes [here](https://github.com/mitre/cti/releases/tag/ATT%26CK-v16.0).

# v4.1.6 (2024-08-15)

## Docs
Expand Down
8 changes: 4 additions & 4 deletions attack-theme/templates/general/attack-index.html
Original file line number Diff line number Diff line change
Expand Up @@ -59,13 +59,13 @@
<a class="twitter-timeline" href="https://twitter.com/MITREattack?ref_src=twsrc%5Etfw" data-theme="light" data-height="388">Tweets by MITREattack</a>
<script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
</div> -->
<!-- </div> Comment this line for attack box -->
<!-- <div class="col"> Comment this line for attack box -->
</div> <!-- Comment this line for attack box -->
<div class="col"> <!-- Comment this line for attack box -->
<p class="text-justify">MITRE ATT&CK<sup>&reg;</sup> is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.</p>
<p class="text-justify">With the creation of ATT&CK, MITRE is fulfilling its mission to solve problems for a safer world &mdash; by bringing communities together to develop more effective cybersecurity. ATT&CK is open and available to any person or organization for use at no charge.</p>
</div>
<!-- Uncomment below lines for attack box -->
<div class="col">
<!-- <div class="col">
<div class="attack-box">
<img width="100%" height="52%" src="/theme/images/ATTACKCon-5.png" alt="ATT&CKcon 5.0">
<center>
Expand All @@ -76,7 +76,7 @@ <h2 class="attack-box-heading">
</h2>
</center>
</div>
</div>
</div> -->
{% else %}
<p class="text-justify">
MITRE ATT&CK<sup>&reg;</sup> is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community.
Expand Down
16 changes: 11 additions & 5 deletions data/attackcon.json
Original file line number Diff line number Diff line change
Expand Up @@ -158,7 +158,8 @@
}
],
"description": "You have had a pen test, a red team or a threat intelligence report and drawn up a plan for remediation. You have been told you have 15 mins in front of the CFO in 48 hours! How do you show ,on one page, the connection between the techniques you are exposed and vulnerable to, the path of least resistance and the focused control changes required right now?<br><br>How will the CFO get the picture so the result is \"I get it, what do you need?\"<br><br>Understanding ATT&CK as a practitioner is great with the current matrix but it is inaccessible to the CFO. But it doesn't have to be that way.<br><br>Phil will chart the journey to improved visualization of ATT&CK techniques. He will show how the DNA of ATT&CK doesn’t just make ATT&CK accessible for all but that it can be beautiful!",
"video": "https://www.youtube.com/watch?v=FJ8FdgEgYXw&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=13"
"video": "https://www.youtube.com/watch?v=FJ8FdgEgYXw&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=13",
"slides": "https://www.slideshare.net/slideshow/the-art-of-communicating-attck-to-the-cfo/262859524"
},
{
"title": "Navigating the Attention Economy – Using MITRE ATT&CK to Communicate to Stakeholders at all Levels",
Expand Down Expand Up @@ -232,7 +233,8 @@
}
],
"description": "KC7 uses an experiential learning pedagogy to teach cybersecurity analysis to students of all levels, from elementary school all the way to industry professionals. In the KC7 experience, students analyze realistic cybersecurity data and answer a series of CTF-style questions that guide them through an investigative journey. <br><br>In order to generate authentic intrusion data, we create a fictional company that is attacked by cyber threat actors. The attributes and behaviors of these actors are defined via yaml configurations that are modeled based on MITRE ATT&CK categories and techniques. For example, we can granularly define what techniques an attacker uses for initial access or lateral movement, and how the actor explicitly uses those techniques.<br><br>Students that effectively analyze KC7 intrusion data can map the observed activity to the various stages of the MITRE ATT&CK framework. Organizing actor definitions around the ATT&CK framework allows KC7 to create a rich set of intrusion data in various permutations - and ensure that students are exposed to a diverse array of scenarios. A pleasant byproduct of this methodology is that students of MITRE ATT&CK can now study techniques contextually in data rather than just reading about them in reports.",
"video": "https://www.youtube.com/watch?v=I2shZqo_k2Y&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=19"
"video": "https://www.youtube.com/watch?v=I2shZqo_k2Y&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=19",
"slides": "https://www.slideshare.net/slideshow/using-attck-to-created-wicked-actors-in-real-data/262859770"
},
{
"title": "MITRE ATT&CK Updates: New Ideas in Enterprise - Pushing the boundaries of ATT&CK's long-established scope",
Expand Down Expand Up @@ -279,6 +281,7 @@
}
],
"description": "",
"video": "https://www.youtube.com/watch?v=m2HZgOYxcic&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=26",
"slides": "https://www.slideshare.net/MITREATTACK/mitre-attck-updates-state-of-the-cloud"
},
{
Expand Down Expand Up @@ -326,7 +329,8 @@
}
],
"description": "The purpose of this session will be to look at how the linux-malware repo came to take shape and how we've used it to inform our view on adversarial behaviour over the last couple of years. Since the original reason for staring this project was to look at Linux coverage in ATT&CK, we'll play back some of the interesting points and reflect on how they've affected ATT&CK itself.",
"video": "https://www.youtube.com/watch?v=PCw3Wa9GBP4&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=28"
"video": "https://www.youtube.com/watch?v=PCw3Wa9GBP4&list=PLkTApXQou_8If8_fwdCKVnwHr0WaEnfSH&index=28",
"slides": "https://www.slideshare.net/slideshow/i-can-haz-cake-benefits-of-working-with-mitre-on-attck/262860255"
},
{
"title": "Updates from the Center for Threat-Informed Defense",
Expand Down Expand Up @@ -407,7 +411,8 @@
}
],
"description": "Many use the ATT&CK matrix to map tool coverage across the environment. This blanket coverage is a good baseline but it can miss certain aspects of the enterprise's context like risk levels, organisational priorities, and industry specific threat intelligence. I want to discuss ways to layer these lenses on top of an enterprise mapping to make ATT&CK more relevant to the specific enterprise. If done right this can lead to more actionable metrics and reporting on improvements.",
"video": "https://youtu.be/TsrOYObSMO4?si=pkg565FUFuOh_f7X&t=1507"
"video": "https://youtu.be/TsrOYObSMO4?si=pkg565FUFuOh_f7X&t=1507",
"slides": "https://www.slideshare.net/slideshow/or-lenses-and-layers-adding-business-context-to-enterprise-mappings/262859506"
},
{
"title": "Lightning Talk: ATT&CK’s Adoption in CTI: A Great Success (with Room to Grow!)",
Expand All @@ -418,7 +423,8 @@
}
],
"description": "This metrics- and meme-based lightning session spotlights the success story that is the CTI industry’s impressive (and expanding) adoption of ATT&CK in their products. Using nearly 6 years’ worth of ATT&CK-mapped, public threat reports collected from government, vendor, & independent sources, we’ll show how the rate (and detail) of mapping has increased considerably, while showcasing (anonymized) examples of high-quality end-products, with the aim of inspiring further ATT&CK adoption in this important corner of the field.",
"video": "https://youtu.be/TsrOYObSMO4?si=iqw3wjOGyPIMtApY&t=1794"
"video": "https://youtu.be/TsrOYObSMO4?si=iqw3wjOGyPIMtApY&t=1794",
"slides": "https://www.slideshare.net/slideshow/attcks-adoption-in-cti-a-great-success-with-room-to-grow/262860181"
},
{
"title": "Lightning Talk: Automating testing by implementing ATT&CK using the Blackboard Architecture",
Expand Down
17 changes: 13 additions & 4 deletions data/versions.json
Original file line number Diff line number Diff line change
@@ -1,11 +1,20 @@
{
"current": {
"name": "v15.1",
"date_start": "April 23, 2024",
"changelog": "updates-april-2024",
"cti_url": "https://github.com/mitre/cti/releases/tag/ATT%26CK-v15.1"
"name": "v16.0",
"date_start": "October 31, 2024",
"changelog": "updates-october-2024",
"cti_url": "https://github.com/mitre/cti/releases/tag/ATT%26CK-v16.0"
},
"previous": [
{
"name": "v15.1",
"aliases": [],
"date_start": "April 23, 2024",
"date_end": "October 30, 2024",
"changelog": "updates-april-2024",
"cti_url": "https://github.com/mitre/cti/releases/tag/ATT%26CK-v15.1",
"commit": "8912d0ec2d68f4ea38b1020eb0507e6933a0f017"
},
{
"name": "v14.1",
"aliases": [],
Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ profile = "black"

[tool.towncrier]
name = "ATT&CK website"
version = "4.1.6"
version = "4.2.0"
filename = "CHANGELOG.md"
issue_format = "[#{issue}](https://github.com/mitre-attack/attack-website/issues/{issue})"
template = ".towncrier.template.md"
Expand Down
2 changes: 1 addition & 1 deletion requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ bleach==6.1.0
colorama==0.4.6
future==1.0.0
loguru==0.7.2
mitreattack-python==3.0.6
mitreattack-python==3.0.7
pelican==4.8.0
pyScss==1.4.0
python-dotenv==1.0.1
Expand Down
2 changes: 1 addition & 1 deletion website-banner.production
Original file line number Diff line number Diff line change
@@ -1 +1 @@
ATT&CKcon 5.0 returns October 22-23, 2024 in McLean, VA. Register for in-person participation <a href='https://na.eventscloud.com/website/76470/'>here</a> and virtual participation <a href='https://mitre.brandlive.com/ATTACKCon-5-0/en/registration'>here</a>
ATT&CK v16 has been released! Check out the <a href='https://medium.com/mitre-attack/attack-v16-561c76af94cf'>blog post</a> for more information.

0 comments on commit 9ecedc5

Please sign in to comment.