MITRE ATT&CK Defender™ ATT&CK® SOC Assessments Training-Recommendations & Review

Mark Ernest
3 min readDec 2, 2022

ATT&CK® SOC Assessments

For an overview of the MITRE ATT&CK Defender™ (MAD) training program, revisit the story: MITRE ATT&CK DEFENDER™ Cyber Threat Intelligence Training — Leadership Recommendations & Review.

The ATT&CK® SOC Assessments training path includes instructor-led videos, with exams for subscribers looking to obtain a certification badge, and the learning objectives include:

Provide tips on how to analyze SOC technologies like tools and data sources.

Share best practices for performing interviews and leading discussions on ATT&CK with SOC personnel.

Educate on how to recommend changes based on assessment results.

The ATT&CK® SOC Assessments training is covered in three modules and requires a time investment of about 3 hours and 15 minutes.

Approx. Total time: 3h 16m

MODULE 1
Overview of ATT&CK®-based SOC Assessments - 35m

1.1 Introduction: Bringing ATT&CK® into the SOC - 8m
1.2 A Methodology for Assessments - 9m
1.3 Framing an Assessment - 10m
1.4 Scoping an Assessment - 6m

MODULE 2
Analyzing SOC Components with ATT&CK® - 58m

2.1 Setting a Coverage Rubric - 12m
2.2 Working with Data Sources Part 1 - 10m
2.3 Working with Data…

--

--

Mark Ernest

Dad, husband, cybersecurity researcher & practitioner, developer.