Why Cato Uses MITRE ATT&CK (And Why You Should Too)
ID: fa27b1e6-ce04-56eb-a844-673b3a211064
STIX ID: report--fa27b1e6-ce04-56eb-a844-673b3a211064
Feed Name: Cato Networks
This blog post advocates shifting from IoC-based detection to TTP-based detection using the MITRE ATT&CK framework, describes how Cato Cloud maps security events to ATT&CK via tagging, and reports that while most signatures are IoC-based, the majority of observed events (94%) were identified by TTP-based signatures, concluding TTPs provide broader and higher-quality coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
