MITRE ATT&CK-based continuous validation, attack simulation, and threat intel partnership roadmap
Acquisition of domains for phishing/C2
Module: DNS Filter (NRD/NOD)Adversary sends targeted email with malicious attachment
Module: ATP Engine + SWGAdversary sends email with malicious URL
Module: DNS Filter + Web FilterAbuse of PowerShell for execution and scripting
Module: ATP Engine (UEBA)Compromise of valid credentials for access
Module: UEBA + Identity ProviderEncoding/encryption of payloads to evade detection
Module: ATP Engine + AI/MLAitM attacks to intercept credentials
Module: AegisRoute™ SCION + SSLLateral movement via RDP sessions
Module: Microsegmentation + ZTNAC2 communication over HTTP/HTTPS
Module: SWG + SSL InspectionUse of proxy to mask C2 traffic origin
Module: SWG + AegisRoute™Data exfiltration through existing C2 channel
Module: DLP + SWG + SSLRansomware encryption of victim data
Module: ATP Engine + DLP