TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

Breaking Down the NIST Cybersecurity Framework

2022-04-14 · Read original ↗

ATT&CK techniques detected

2 predictions
T1098.007Additional Local or Domain Groups
36%
“but if there are multiple ( tens, hundreds, or possibly thousands ) of login attempts for a user account and then a successful login, it ’ s probably a good idea to assume compromise. event id 4720 – user account created often, attackers will create a new user account. this is do…”
T1078.003Local Accounts
32%
“but if there are multiple ( tens, hundreds, or possibly thousands ) of login attempts for a user account and then a successful login, it ’ s probably a good idea to assume compromise. event id 4720 – user account created often, attackers will create a new user account. this is do…”

Summary

A comprehensive guide to the NIST cybersecurity framework, its five main functions and how you can use the NIST framework to improve your cybersecurity posture.