January 2020
Intermediate to advanced
448 pages
11h 42m
English
A useful construct for describing the various types of IOCs and IOAs that an adversary can leverage and their ability to modify them during an attack is the pyramid of pain. This construct, developed by David Bianco, describes the relationship between the IOCs, IOAs, and TTPs that an attacker makes available through observations by the defender and the attacker's ability to change those indicators. The following diagram shows the relationship to the various indicators and the work effort necessary to modify them in order to bypass security controls:

For example, an attacker may have crafted a piece of malware that spreads through ...
Read now
Unlock full access