Frameworks and methodologies

Frameworks give cyber threat intelligence a common structure. They provide shared vocabulary, repeatable process, and a way to organize observations so that different analysts and teams can describe the same activity in compatible terms. Rather than treating every intrusion as a unique story, frameworks let practitioners map events onto established models, compare campaigns over time, and hand findings to detection and response teams in a form they can use. No single framework is complete on its own, so analysts tend to apply several in combination, using one to describe adversary behavior and another to structure the workflow around it.

The frameworks and methodologies described in this area include the following.

  • The intelligence cycle: the iterative process of direction, collection, processing, analysis, and dissemination that organizes intelligence work.
  • The Diamond Model: a model that relates adversary, capability, infrastructure, and victim to characterize intrusion events.
  • The Cyber Kill Chain: a sequence of stages describing how an intrusion progresses from reconnaissance to action on objectives.
  • MITRE ATT&CK: a knowledge base of adversary tactics, techniques, and procedures observed in real operations.
  • F3EAD: the find, fix, finish, exploit, analyze, and disseminate cycle that links intelligence with operations.

References#

  • MITRE ATT&CK, attack.mitre.org
  • Lockheed Martin, Intelligence Driven Defense and the Cyber Kill Chain

Cookie Consent

We use cookies to enhance your experience. Learn more