Combined MITRE ATT&CK® and ATLAS Training Workshop by Tonex

This 2-day intensive workshop is designed to provide participants with a comprehensive understanding of both the MITRE ATT&CK® Framework and the ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems). The MITRE ATT&CK® Framework is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s attack lifecycle and the platforms they target. ATLAS is a globally accessible, living knowledge base of adversary tactics and techniques against AI-enabled systems. This workshop will equip participants with the skills to utilize both frameworks for developing robust cybersecurity strategies, threat models, and mitigation techniques.
Learning Objectives:
By the end of this workshop, participants will be able to:
- Understand the structure and purpose of both the MITRE ATT&CK® and ATLAS frameworks.
- Identify and analyze common adversary tactics and techniques targeting general and AI-specific systems.
- Apply knowledge from real-world attack scenarios to improve system security.
- Develop and implement threat models using both frameworks.
- Conduct effective red teaming and blue teaming exercises.
- Integrate these frameworks into cybersecurity operations and strategies.
Target Audience:
- AI and Machine Learning Engineers
- Cybersecurity Professionals
- Security Analysts
- IT Risk Managers
- Threat Intelligence Analysts
- SOC Teams
- Incident Responders
- Researchers and Academics in Cybersecurity and AI Security
- Anyone interested in enhancing their understanding of adversary tactics and techniques
Workshop Modules:
Day 1: Understanding the Frameworks
Module 1: Introduction to MITRE ATT&CK®
- Overview of the ATT&CK Framework: Purpose and Scope
- History and Development of ATT&CK
- Key Components and Structure of ATT&CK
Module 2: Introduction to ATLAS
- Overview of ATLAS: Purpose and Scope
- Navigating the ATLAS Knowledge Base
- Key Components and Structure of ATLAS
Module 3: Adversary Tactics and Techniques
- Overview of Tactics, Techniques, and Procedures (TTPs)
- Detailed Analysis of Common Adversary Techniques in ATT&CK
- Techniques Used in Real-world AI Attacks (ATLAS)
Module 4: Real-world Attack Observations
- Insights from Documented Attack Scenarios (ATT&CK and ATLAS)
- Learning from Red Team and Blue Team Exercises
- Understanding the Adversarial Mindset
Module 5: Hands-on Exercise: Navigating ATT&CK and ATLAS
- Practical Session on Using Both Knowledge Bases
- Identifying Relevant Tactics and Techniques
- Mapping Observations to ATT&CK and ATLAS Entries
Day 2: Applying the Frameworks in Cybersecurity Operations
Module 6: Developing Threat Models
- Building Threat Models Using ATT&CK
- Practical Examples of Threat Model Development
- Case Study: Effective Threat Modeling
Module 7: Mitigating Adversarial Threats in AI Systems
- Developing Defense Strategies for AI Systems (ATLAS)
- Implementing Mitigation Techniques
- Case Study: Successful Mitigation Strategies
Module 8: Threat Detection and Response
- Leveraging ATT&CK for Threat Detection
- Integrating ATT&CK and ATLAS into Incident Response
- Tools and Techniques for Effective Response
Module 9: Practical Session: Red Teaming and Blue Teaming with ATT&CK and ATLAS
- Conducting Red Team Exercises Using Both Frameworks
- Blue Team Strategies for Detection and Mitigation
- Analyzing and Interpreting Exercise Results
Module 10: Integrating the Frameworks into Cybersecurity Strategy
- Building ATT&CK and ATLAS into Security Operations Centers (SOC)
- Continuous Improvement and Adaptation with Both Frameworks
- Resources for Ongoing Learning and Development
Conclusion and Q&A
- Recap of Key Takeaways
- Open Floor for Questions and Discussions
- Networking Opportunity for Participants
Participants will receive a certificate of completion and access to additional resources to continue their learning journey in cybersecurity using the MITRE ATT&CK® and ATLAS frameworks.