The MITRE ATT&CK™ framework is an ambitious initiative that is working to bring clarity to how we talk about cyberattacks. CrowdStrike® is proud to support MITRE’s efforts to bring standardization to attack modeling and attack terminology, and using it to deliver more actionable information to security experts.
For any technical discipline to transition from “folkcraft” to “science,” it’s critical that practitioners agree on common terminology and language. As an example, over the last two centuries an estimated one billion people have died from “consumption,” “phthisis,” and the “White Plague.” Today, we commonly know these diseases as tuberculosis. Having a common term allows doctors, researchers and other medical professionals to communicate clearly and concisely about this disease and how to treat it.
Few technical disciplines are as full of jargon and as reliant on tribal knowledge as the field of cybersecurity. Think for a moment on the simple sentence, “We’ve been hacked.” What is the proper response when you hear these words? Depending on the context, you might need to clean up malware, lock down compromised accounts, restore data from backup or call the authorities. This kind of imprecise language creates ambiguity and inefficiency in our industry and makes it especially difficult for practitioners to communicate clearly with stakeholders outside of the security operations center (SOC). CrowdStrike and other major players across the security industry are lining up behind ATT&CK to help bring order and precision to discussions about cyber threats.