Blog Posts

Center for Threat-Informed Defense

CIS Controls for Threat Mitigation

Explore how CIS Safeguards map to MITRE ATT&CK techniques to assess defensive coverage, identify gaps, and support threat-informed security control implementation.

Continue reading

Putting Detection Coverage to the Test: A Windows Security Case Study

A case study of 144 Sigma analytics using Windows Security log sources shows why ATT&CK mappings alone do not reveal the depth or quality of detection coverage.

Continue reading

Beyond the Heatmap: A New Way to Measure Detection Coverage

Summiting the Pyramid introduces implementation coverage and detection quality to help defenders measure the depth and effectiveness of detection coverage beyond an ATT&CK heatmap.

Continue reading

Attack Flow: From Diagrams to Decisions

Attack Flow v4 helps defenders turn incident evidence into connected flows, add the context needed for action, and communicate decisions across technical and executive audiences.

Continue reading

MITRE ATLAS Grows through Collaboration with CTID and Industry

Secure AI expanded MITRE ATLAS™ with new techniques, mitigations, case studies, a Technique Maturity filter, and rapid-response and emulation capabilities to strengthen defense of AI-enabled systems.

Continue reading

Fraud Fighters United with MITRE F3

MITRE Fight Fraud Framework (F3) is a behavior-based model of fraud actor tactics and techniques that gives fraud and cyber defenders a shared structure to describe incidents, relate events, and disrupt fraud outcomes.

Continue reading

Context to Confidence: The Next Phase of Ambiguous Techniques Research

MITRE CTID’s latest ambiguous techniques research turns context into confidence with minimum telemetry requirements and a confidence scoring model that helps detection engineers pick the right log sources for robust, low-noise detections.

Continue reading

A Threat-Informed Community is Necessary for Defense to Function

Threat-informed defense changes the game on the adversary. Threat-informed defenders read their adversaries’ playbooks and then orchestrate a defense based on that knowledge. MITRE ATT&CK® is the core of threat-informed defense as our framework of adversary tactics, techniques, and procedures …

Continue reading

MITRE ATLAS OpenClaw Investigation Discovers New and Likeliest Techniques

MITRE ATLAS™ analyzed OpenClaw incidents that showcase how AI-first ecosystems introduce new exploit execution paths. OpenClaw is unique because it can independently make decisions, take actions, and complete tasks without continuous human oversight. By mapping the patterns and behaviors to ATLAS …

Continue reading

Cloud Security Built with ATT&CK

Threats to cloud computing span multiple security domains, objectives, and layers of technology. Defenders must protect dynamic, shared environments while adversaries actively exploit misconfigurations, weak controls, and gaps between responsibility boundaries. To keep up, security cannot just focus …

Continue reading