30:38Lighting it Up – Building Playbook Heat Maps
Download resourcesAbout this session
Derek Manky, chief of security insights at Fortinet's FortiGuard Labs, describes how his team turns adversary research into MITRE ATT&CK-based playbooks and then into heat maps that help executives prioritise defence. He starts with FortiGuard Labs itself, a worldwide operation blending automation, machine learning and human analysts, and with the scale of the threat landscape (intrusion attempts he cites having doubled to around 18 million per minute in one quarter). Citing the Pyramid of Pain, he argues that chasing hashes and IPs has little impact, so the team works top-down on tools, techniques, tactics and procedures. He explains a multi-step process for building red-team adversary playbooks (candidate criteria, collection, analysis, an investigation phase into motive and attribution, then release via STIX version 2 and a public playbook viewer), using the Silence group's ATM jackpotting campaigns as a worked example. A blue-team defensive playbook layers on top like a sports game plan, and a real-time MITRE ATT&CK sightings heat map lets a CISO focus response on the most relevant, early-stage techniques. He closes on the Cyber Threat Alliance and its Magellan sharing platform.
This talk will discuss the process of building an adversarial playbook using the MITRE ATT&CK framework, based off years of experience through FortiGuard Labs. By understanding the TTPs (Techniques, Tactics, Procedures), the way attackers move, a better defensive (Blue Team) playbook can be built to mitigate threats. This talk will examine how to take this approach one step further to light up campaign tactics using real time data of popular techniques (sightings) to help CxO’s prioritize their Blue Team playbooks.
Key takeaways
- Work threat intelligence top-down: chasing hashes, IPs and domains (the base of the Pyramid of Pain) has little lasting impact, so focus analysts on tools, techniques, tactics and procedures.
- Build red-team adversary playbooks in the MITRE ATT&CK framework and share them as STIX version 2 so detail survives from analysts up to executives without 80-page white papers.
- Include an investigation phase for motive and attribution, using criteria like roughly two years of data broken into campaigns before attributing activity to a group.
- Layer a blue-team defensive playbook on top of the adversary playbook like a sports game plan, blocking each stage of movement from left to right in the kill chain.
- Use a real-time ATT&CK sightings heat map to prioritise response on the most relevant early-stage techniques rather than reacting once command-and-control is reached.