Hi guys
I wanted to talk with you about a platform where you can look at the Mitre mapping of the QRadar content with another view. The platform I am talking about is Tidal (Tidal website).
What Tidal allows you to do is to pivot in the att&ck matrix in many ways, highlighting where you might want to increase your detection coverage for specific threats.
As an example, you can select the specific threats you want to monitor and they will be highlighted with a colour coding that makes it easy to understand the techniques you should focus on in priority to be efficient.
In the example below, you can instantly see that "Data Encrypted for Impact" is a technique common to 4 out of the 6 threats I selected. In this case, this technique and the techniques leading to it should probably be higher in the list of priorities for detection / prevention implementation.
All the information available on the Mitre website is also available in Tidal UI, avoiding back and forth while trying to understand what each technique is about and how to detect it.
You might have noticed an information that doesn't appear on the Mitre website... The vendors list !
A really cool feature of Tidal is that you can filter on a vendor to see all the techniques that are covered, and compare it to the techniques used by a specific threat !
#Highlights-home
#Highlights