dashboard radar bug_report school newspaper sensors

Learning Hub › Deep Dives › Threat Intel & MITRE

Deep Dive 02 · Interactive guide

Threat Intelligence & MITRE ATT&CK

"Know your adversary." Cyber threat intelligence (CTI) turns raw security data into decisions: what to patch first, what to detect, what to tell the board. MITRE ATT&CK gives everyone a shared map of how attackers actually behave. This guide covers both, then lets you map a realistic intrusion onto the ATT&CK v19 matrix yourself.

01

Data is not intelligence

A log line is data. Context makes it information. Intelligence answers "so what, and what do we do?" for a specific reader. Click each stage.

Four levels, four audiences

The same threat produces different intelligence for different readers.

02

The intelligence lifecycle

Good CTI is a loop, not a feed. It starts with a question from the business and ends with feedback that sharpens the next question. Follow one worked example through all six phases.

Worked example · The CFO asks: "A ransomware crew is hitting manufacturers like us. Are we exposed?" (The crew in this example is fictional.)
03

The Pyramid of Pain

David Bianco's pyramid (2013) ranks indicators by how much pain you cause the attacker when you detect and block them. Blocking a file hash costs them seconds. Detecting their behaviour forces them to retrain. Click a level.

IOC

Indicator of Compromise

Evidence something bad already happened: a hash, an IP, a domain. Fast to share and match, quick to go stale. Bottom of the pyramid.

IOA

Indicator of Attack

Behaviour that shows an attack in progress: Word spawning PowerShell, a process reading LSASS. Harder to build, much harder to dodge. Top of the pyramid.

04

Sharing intelligence: TLP 2.0 and STIX

Intel is worth more when shared, but the source decides how far it may travel. The Traffic Light Protocol (FIRST, version 2.0) is the label that says so. Pick a label and an audience.

TLP label

Can I share it with…

STIX 2.1 is the JSON language for describing threat intel so machines can exchange it; TAXII 2.1 is the HTTPS API that carries STIX between organisations. Hover or focus a field in this sample Indicator.


                

Hover a highlighted field.

05

The MITRE ATT&CK Enterprise matrix (v19)

Tactics (columns) are the attacker's goals: the "why". Techniques (cells) are how they achieve them. Version 19 (2026) split the old Defense Evasion tactic into Stealth (hiding) and Defense Impairment (breaking your security tools), giving 15 tactics. A few representative techniques are shown per tactic; the full matrix has hundreds. Click any technique.

Layer

Pick a technique to see what it is, how to detect it and how to mitigate it.

06

Exercise: map the intrusion

Here is a realistic ransomware intrusion, step by step, based on patterns common in public incident reports. For each step, pick the ATT&CK tactic: what was the attacker trying to achieve? When you finish, the path lights up in the matrix above.

Scenario · fictional victim
    07

    The Diamond Model and putting intel to work

    The Diamond Model (Caltagirone, Pendergast & Betz, 2013) says every intrusion event has four corners. Find one, and you can pivot to the others. Click a corner: the examples come from the intrusion you just mapped.

    From feed to detection: the operational pipeline

    Intel only matters when it changes what your tools see. Click each stage.

    08

    Sources & further reading

    Want the live view? Active Threats tracks current advisories, and the Zero Trust deep dive shows how to shrink the blast radius when an intrusion like the one above starts.