This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The Art of Threat Modeling with Mitre ATT&CK

Download resources

About this session

Troy Vennon, Director of Service Innovation at GoSecure, argues that most security programs cannot answer whether their tools actually defend against the threats they claim to care about. He traces the evolution from the Lockheed Martin kill chain to MITRE ATT&CK's technique-level detail, then presents a continuous defense improvement methodology: use ATT&CK as a translation layer between governance frameworks such as NIST 800-53, CSF and CIS, technical controls, and known threat actors. Controls are scored for maturity, tools are weighted by defensive function since blocking outranks merely alerting, and threat actors such as ransomware groups and the FIN gangs are mapped to the techniques they use, producing probabilistic, Monte Carlo-driven effectiveness scores per technique. The model outputs a prioritized remediation list, validated with security-validation tools or penetration testing, which then feeds budget requests inside a repeating assess-model-validate-remediate loop. Visualizations such as the unified kill chain help communicate where defenses are weakest across getting in, through, or out of the environment. The closing Q&A covers technique overlap between threat actors, sourcing effectiveness data from MITRE Ingenuity evaluations and vendor self-assessment, and the lack of any off-the-shelf framework for documenting tool capabilities.

As cyber threats and threat actors continue to mature and improve their attacks and techniques, security programs are more inundated with vendors, tools and technologies purporting to be the silver bullet to solve these technical challenges. In reality, many security toolsets are complex to configure, maintain and fully understand the defensive capabilities they provide. By operationalizing Mitre ATT&CK in your security program, CISO’s and security leaders can take a leap forward in understanding and communicating the effectiveness of their tools at defending against threats, and expose potential gaps in coverage that need to be addressed quickly. Threat modeling with the Mitre ATT&CK framework can be a powerful strategic tool to guide security spend in your upcoming budget cycles.

Key takeaways

  • Map each control in your governance framework (NIST 800-53, CSF, CIS) to the MITRE ATT&CK techniques it defends against, then score its maturity from 1 to 5.
  • Weight tools by defensive function, not mere presence: a control that blocks should score higher than one that only alerts or logs.
  • Enumerate the specific threat actors and ransomware groups that target your industry, not a generic 'ransomware' category, and model your controls against their actual techniques.
  • Use security validation tools or targeted penetration testing to confirm coverage gaps a model predicts before spending remediation budget.
  • Treat the process as a loop: model, validate, remediate, update the model as threats and tools change, and rerun it regularly.

Speakers

Troy Vennon
Troy Vennon
Director of Service Innovation · GoSecure
Troy Vennon, GoSecure ISAO Principle, Information Security Expert, Threat Intelligence and Mitre Att&ck Evangelist. Former United States Marine. Real Estate Investor. Firearms Instructor. Wrestling Coach. Ohio State Football and Wrestling Fanatic… Read moreRead less

Troy Vennon, GoSecure ISAO Principle, Information Security Expert, Threat Intelligence and Mitre Att&ck Evangelist. Former United States Marine. Real Estate Investor. Firearms Instructor. Wrestling Coach. Ohio State Football and Wrestling Fanatic. Troy Vennon’s career spans 24 years and focused entirely on Information Security roles across every security domain, beginning in 1998 with the United States Marine Corps as SNCOIC of the Marine Corps Network Operations & Security Center’s (MCNOSC) Marine Computer Emergency Response Team (MarCERT), until he joined the private sector in 2006. As a Certified Chief Information Security Officer, Troy focuses on coaching CISO’s and security teams in their efforts in building security programs that can rapidly identify effective control coverage strategies for risk identification, risk treatment, and security investment.

Resources

Tags

More from GoSec 2024

Also from Troy Vennon

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.