Anyone experienced with MITRE Attack framework? Need someone who has real hands-on experience! TIA

like
Posting as :
works at
You are currently posting as works at

So they are using it as a way of mapping their existing controls to see what coverage they have against attack paths?

like

Yea, what D1 said — tons of people are familiar with it or have used it hands on — but it’s a framework and “hands on” can mean a variety of things. What are you trying to do?

like

What are you trying to do with it?

like

Trying to interview for a job where my role would be GRC, risk assessment and this framework is used heavily. Im trying to find someone who does or has done it from that lens to walk me through real scenarios of how they thought through this and came up with risks/controls. I understand the framework has this but want to go a few layers deeper and understand better

I have found in GRC people just speak to it, but never actually perform any analysis to determine how the organization's security or IT team is using the framework. From a GRC perspective, for your interview you can speak to it as "if I were to evaluate the organization's Security Operations Center (SOC), I would look to see how the team tests for privilege escalation, how did they use the framework to detect and prevent the privilege escalation" Get on the Youtubes and search for MITRE Attack Framework explained.

like

Related Posts

Looking for motivation to get me to my first Alcohol rehab appointment.

like

I got 3 offers. Compensation is pretty similar for an experienced audit role. Any tips on making a decision? RSM, CLA, and Moss Adams

like

Hi Fishes,

Have interview with UBS in Tech Software Engineer in Test role what can we expect my stack is CoreJava,Selenium,API testing.

Exp-8 years.

Thanks in Advance !

How did you get good at golf? How long did it take

like

Hearing rumors that you pwc folks won’t be able to use robinhood anymore.

like

How realistic is getting a dog as a junior associate?

like

Berger Singerman? Culture, salary, bonus, work, hours, partnership prospects? Any insight appreciated. Thx!

like

What about Italy? Anyone working there?

like

Hi, iam joining ID firm and am very new to the billing world. What are some helpful tips that you can share with me? Also, in general, what are some things that you wish you knew when you first started. TIa

like

Java vs Nodejs vs GO

Which is best for market opportunities for Backend Developers?

Should someone switch from Java to NodeJs or GO having total 4 years of experience in IT Industry?

like
like

Can you take and drive leased car from US in Canada?

like

What is the comparision between Infosys band 6B and Band 8 of IBM? Any pointers please!

like

Hi Fishes am about to join Eli Lilly next month. Can anyone tell me when are the appraisal cycle as i wad told that i would be eligible for current year appraisal and would get the increment in March. Is it true if anyone can please highlight.

like
like

Hello everyone, can someone please help me with preparing for a case study for BA role in Eli Lilly? Any references or topics to cover would be very helpful!

I recently had a specialist partner send me a fairly nasty email after I (a transactional first year) was told to ask them to review something ASAP that had clearly been on my partner’s radar for over a week. Why am I taking the (honestly justified) blame for this? Surely it should be obvious that I’m just the messenger here.

like

More than halfway through a 90 in 90 and I’m so grateful for NY AA and that there are so many meetings! Also 90 in 90 is actually kinda great

like

Additional Posts in Cyber Security Bowl

Any tips or tricks for CSX certification?

like

Anyone do cyber strategy work at EY and available for questions? 😊

like

Looking to get back into cyber security. About to finish my masters in cyber security and would love to go to an early or mid start up for some alliances, channel, or sales work. Anyone have any solid leads ?

like

Anyone got insights on IBM Security? Areas of expertise? QoL? Pay, etc.

Would you expense a speeding ticket on your way to an IR?

funnylike

Anyone heard of the online CISSP bootcamp conducted by New Horizons? Any reviews? Planning to attend in October and wanted to know if they are actually helpful for getting the cert.

like

For those who have passed the CIPM exam, what is it like (and how does it compare to the CIPP/US exam)?

What is max EY manager salary range for IAM/Cyber role? Tier 1 city? Any leads will be helpful

like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

Anyone have experience moving from Canada to US? Looking for new opportunities and aiming to learn more about sponsorship and such. 3.5 YOE primarily in risk/maturity assessments and Enterprise security architecture.

Everything I look at requires to be already eligible to work in the states.

like

If anyone is looking for a job in Cyber Security, EY is hiring for senior consultant and Manager positions. Feel free to reach out for any questions or referral.

like

Tell me it’s not true.

Post Photo
funnylike

Does PWC and Deloitte have dedicated application security pen-testing team? How much percentage of the time you guys travel? Do you work from home or based out of any particular location?

like

Anyone had success with CISSP audiobooks to study? I got a long commute!

Got a verbal offer from Grant Thornton. The recruiter told me that they would get the paperwork over by Thursday or Friday. I mentioned that I am strongly considering the firm however I have other companies that I am also considering so I will be making my decision based on that. The recruiter then mentioned that I’ll likely have 3 days to respond after the offer is given. Is this normal? What should I do? Can I ask for an extension?

like

Accenture or Deloitte for cyber security strategy? Who’s on top?

like

I have a dual citizenship (recently got my US citizenship). What are the odds I could ever get a clearance to work in federal branches (i.e., NSA, Cyber Command, etc.)? And what would be the career best path towards those areas?

like

What are some of the hot skills in cyber security which we can acquire?

like

When it comes to network segmentation (e.g. segmenting users from servers), would you segment the networks logically (VLANs, VRFs, VDOMs..etc) or physically (security gateway, NGFW...etc)? And why?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal