▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

MITRE Posts Latest Findings of ATT&CK® Evaluations for Cybersecurity Solutions Against Ransomware

#ATTCK--MITRE posted the latest findings of its ATT&CK® Evaluations (ATT&CK Evals), an independent and objective assessment of enterprise cybersecurity solutions. Through the lens of the MITR...

Business Wire

MCLEAN, Va. & BEDFORD, Mass.: #ATTCK--MITRE posted the latest findings of its ATT&CK® Evaluations (ATT&CK Evals), an independent and objective assessment of enterprise cybersecurity solutions. Through the lens of the MITRE ATT&CK knowledge base, the ATT&CK Evaluations Enterprise Round 6 focused on two distinct threat areas for a more targeted evaluation of defensive capabilities:

  • Windows (featuring Linux) emulations featuring common ransomware behaviors leveraged by cybercriminal groups.
  • macOS emulation featuring adversary behavior reflecting North Korea’s (DPRK) evolving tactics, including the development of advanced, multistage malware.

“The evidence-based results of the evaluations are a valuable resource for organizations in determining which cybersecurity solutions best address their needs,” said William Booth, general manager, ATT&CK Evals, MITRE. “In this round of our evaluations, we broadened the scope to include macOS and focused on new insights regarding efficiency and false positive rates to more accurately reflect the real-world performance of the solutions.”

Ransomware continues to be one of the most significant global cybercriminal threats across government and industry. Enterprise Round 6 focused on two ransomware variants, LockBit and CL0P, to emulate common behaviors prevalent across the ransomware ecosystem. LockBit, which law enforcement agencies have described as the “most deployed ransomware variant across the world,” is known for its use of sophisticated tools and dual targeting of Windows and Linux systems. CL0P is a ransomware family associated with the TA505 criminal group and leverages the “steal, encrypt, and leak” strategy across a variety of regions and sectors.

North Korea poses a significant cyber threat, targeting the global financial, defense, and technology sectors to fund the advancement of its nuclear capabilities. North Korea has increasingly expanded its targeting of macOS systems, gaining the ability to infiltrate additional high-value systems. The Enterprise Round 6 macOS-focused emulation featured multistage and modular malware that executed operations involving abusing legitimate macOS utilities and collecting and exfiltrating sensitive data.

Round 6 also includes Protection micro emulations. These emulations assess how enterprise cybersecurity solutions can protect against malicious behaviors in a post-compromise environment. Micro emulations involve short sequences of ATT&CK techniques that are frequently used together in real-world attacks.

The participants in this evaluation included:

The evaluations do not rank vendors and their solutions, but instead they provide insights and results that organizations can use to determine which vendors and solutions may best address their cybersecurity gaps and fit their particular business needs. Results are posted at https://evals.mitre.org/.

ABOUT MITRE

MITRE’s mission-driven teams are dedicated to solving problems for a safer world. Through our public-private partnerships and federally funded R&D centers, we work across government and in partnership with industry to tackle challenges to the safety, stability, and well-being of our nation. www.mitre.org

ABOUT MITRE ATT&CK® EVALUATIONS

ATT&CK® Evaluations is built on the backbone of MITRE’s objective insight and conflict-free perspective. Cybersecurity vendors turn to the Evals program to improve their offerings and to provide defenders with insights into their product’s capabilities and performance. Evals enables defenders to make better informed decisions on how to leverage the products that secure their networks. The program follows a rigorous, transparent methodology, using a collaborative, threat-informed, purple-teaming approach that brings together vendors and MITRE experts to evaluate solutions within the context of ATT&CK. All Evals results are public. https://evals.mitre.org/

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

AI Solutions for Visually Impaired, AI Search and AI Agents Win ISG Startup…

#AI--AI-powered solutions for addressing visual impairments, optimizing brands for AI search and creating AI agents won the ISG Startup Challenges at…

Keysight Launches All-In-One Solution for Network Visibility and Security

#AI--Keysight Technologies, Inc. (NYSE: KEYS) launched AppFusion, a network visibility partner program that integrates third-party security and monitoring…

Realbotix Unveils New Robotic Technology At CES 2025

Realbotix Corp. (TSX-V: XBOT) (Frankfurt Stock Exchange: 76M0.F) (OTC: XBOTF) (“Realbotix” or the “Company”), a leading creator of humanoid robots and…

MultiPlan and J2 Health Announce Strategic Agreement to Enhance Network…

$MPLN #MPLN--MultiPlan Corporation (“MultiPlan” or the “Company”) (NYSE: MPLN), a leading provider of technology and data solutions that improve affordability,…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!