Length: 2 Days

Combined MITRE ATT&CK® and ATLAS Training Workshop by Tonex

AI for Cybersecurity Certification Course by Tonex

This 2-day intensive workshop is designed to provide participants with a comprehensive understanding of both the MITRE ATT&CK® Framework and the ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems). The MITRE ATT&CK® Framework is a curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s attack lifecycle and the platforms they target. ATLAS is a globally accessible, living knowledge base of adversary tactics and techniques against AI-enabled systems. This workshop will equip participants with the skills to utilize both frameworks for developing robust cybersecurity strategies, threat models, and mitigation techniques.

Learning Objectives:

By the end of this workshop, participants will be able to:

  • Understand the structure and purpose of both the MITRE ATT&CK® and ATLAS frameworks.
  • Identify and analyze common adversary tactics and techniques targeting general and AI-specific systems.
  • Apply knowledge from real-world attack scenarios to improve system security.
  • Develop and implement threat models using both frameworks.
  • Conduct effective red teaming and blue teaming exercises.
  • Integrate these frameworks into cybersecurity operations and strategies.

Target Audience:

  • AI and Machine Learning Engineers
  • Cybersecurity Professionals
  • Security Analysts
  • IT Risk Managers
  • Threat Intelligence Analysts
  • SOC Teams
  • Incident Responders
  • Researchers and Academics in Cybersecurity and AI Security
  • Anyone interested in enhancing their understanding of adversary tactics and techniques

Workshop Modules:

Day 1: Understanding the Frameworks

Module 1: Introduction to MITRE ATT&CK®

  • Overview of the ATT&CK Framework: Purpose and Scope
  • History and Development of ATT&CK
  • Key Components and Structure of ATT&CK

Module 2: Introduction to ATLAS

  • Overview of ATLAS: Purpose and Scope
  • Navigating the ATLAS Knowledge Base
  • Key Components and Structure of ATLAS

Module 3: Adversary Tactics and Techniques

  • Overview of Tactics, Techniques, and Procedures (TTPs)
  • Detailed Analysis of Common Adversary Techniques in ATT&CK
  • Techniques Used in Real-world AI Attacks (ATLAS)

Module 4: Real-world Attack Observations

  • Insights from Documented Attack Scenarios (ATT&CK and ATLAS)
  • Learning from Red Team and Blue Team Exercises
  • Understanding the Adversarial Mindset

Module 5: Hands-on Exercise: Navigating ATT&CK and ATLAS

  • Practical Session on Using Both Knowledge Bases
  • Identifying Relevant Tactics and Techniques
  • Mapping Observations to ATT&CK and ATLAS Entries

Day 2: Applying the Frameworks in Cybersecurity Operations

Module 6: Developing Threat Models

  • Building Threat Models Using ATT&CK
  • Practical Examples of Threat Model Development
  • Case Study: Effective Threat Modeling

Module 7: Mitigating Adversarial Threats in AI Systems

  • Developing Defense Strategies for AI Systems (ATLAS)
  • Implementing Mitigation Techniques
  • Case Study: Successful Mitigation Strategies

Module 8: Threat Detection and Response

  • Leveraging ATT&CK for Threat Detection
  • Integrating ATT&CK and ATLAS into Incident Response
  • Tools and Techniques for Effective Response

Module 9: Practical Session: Red Teaming and Blue Teaming with ATT&CK and ATLAS

  • Conducting Red Team Exercises Using Both Frameworks
  • Blue Team Strategies for Detection and Mitigation
  • Analyzing and Interpreting Exercise Results

Module 10: Integrating the Frameworks into Cybersecurity Strategy

  • Building ATT&CK and ATLAS into Security Operations Centers (SOC)
  • Continuous Improvement and Adaptation with Both Frameworks
  • Resources for Ongoing Learning and Development

Conclusion and Q&A

  • Recap of Key Takeaways
  • Open Floor for Questions and Discussions
  • Networking Opportunity for Participants

Participants will receive a certificate of completion and access to additional resources to continue their learning journey in cybersecurity using the MITRE ATT&CK® and ATLAS frameworks.

Request More Information