Preface
If someone is able to show me that what I think or do is not right, I will happily change, for I seek the truth, by which no one was ever truly harmed. It is the person who continues in his self-deception and ignorance who is harmed.
Marcus Aurelius, Meditations
In the past decade, we have seen a rapid proliferation of cyberattacks and the weaponization of digital platforms by various threat actors. Therefore, it is imperative for nations, states, businesses, and other organizations to evaluate their security posture. Unfortunately, the people who perform these evaluations often present unrealistic results because they are too focused on satisfying compliance or other regulatory requirements.
To establish a realistic assessment, many cybersecurity experts have proposed to observe and leverage tactics, techniques, and procedures (TTPs) that adversaries use in the real world. This approach is known as adversary emulation (AE), and it incorporates cyber threat intelligence (CTI) to define what actions and behaviors are vital for a successful activity. In addition, AE attempts to minimize the distance between red and blue teams, empowering communication and collaboration.
This comprehensive guide showcases AE for offensive operators and defenders and provides practical examples and exercises for actively modeling adversary behavior. This book also uses the MITRE ATT&CK® knowledge base as a foundation to describe TTP and provide a common language that is standardized and ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access