Attack frameworks
MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations. The Diamond Model focuses on adversary, capability, infrastructure, and victim.
CYSA+ study area.
Attack frameworks, Diamond Model, Kill Chain, CVSS, risk, and threat modeling.
Notes
Present me looking out for future me. Future me loses handwritten notes.
MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations. The Diamond Model focuses on adversary, capability, infrastructure, and victim.
The Kill Chain describes stages of an intrusion. It gives defenders a way to think about where an attacker is and where disruption may still work.
Risk management rates vulnerabilities by likelihood and impact. Threat modeling helps identify threats and attacks before the architecture has already made them expensive.