-

ExtraHop Experts Contribute Network Detection and Response Expertise to MITRE ATT&CK Framework

Cybersecurity knowledge base expands to support evolving security landscape

SEATTLE--(BUSINESS WIRE)--ExtraHop, the leader in cloud-native network detection and response (NDR), today announced that ExtraHop researchers consulted with MITRE in the development of the new network detection and response methodologies included in the latest version of the ATT&CK framework. This key contribution from ExtraHop provides new guidance for organizations as they integrate NDR into their security operations. It also builds on the company’s leadership around the MITRE ATT&CK framework, which is natively integrated into the ExtraHop Reveal(x) 360 interface.

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, government, and the cybersecurity product and service community. The growing body of network attack behaviors in the MITRE ATT&CK framework serves as both a useful resource and a strong signal for organizations that NDR is a vital tool for detecting and responding to advanced threats.

“ExtraHop was one of the companies that contributed to our development of ATT&CK for Containers,” said Justin Roberts, cloud/containers lead for the MITRE ATT&CK team. “As we all work to help companies stay protected against attacks using knowledge bases like ATT&CK as a common language, contributors like ExtraHop, with expertise and experience with real-world attacks, help us support the security community in reaching that goal.”

“ExtraHop has admired the work the MITRE team has been doing for years, and we’re honored to have been able to contribute to the latest version of the ATT&CK framework,” said Jeff Costlow, CISO, ExtraHop. “But the work isn’t over. Cyber attacks are only growing more sophisticated, and we must remain proactive and vigilant. That’s why we’re committed to continuing to work alongside MITRE, as well as our customers and partners, to continue identifying new attack techniques and developing ways to detect, investigate, and respond to them quickly.”

To learn more about how ExtraHop and MITRE work together, check out the blog here.

To try ExtraHop Reveal(x) for yourself, check out the live interactive online demo.

About ExtraHop

ExtraHop is on a mission to arm security teams to confront active threats and stop breaches. Our Reveal(x) 360 platform, powered by cloud-scale AI, covertly decrypts and analyzes all cloud and network traffic in real time to eliminate blind spots and detect threats that other tools miss. Sophisticated machine learning models are applied to petabytes of telemetry collected continuously, helping ExtraHop customers to identify suspicious behavior and secure over 15 million IT assets, 2 million POS systems, and 50 million patient records. ExtraHop is a market share leader in network detection and response with 30 recent industry awards including Forbes AI 50, Cybercrime Ransomware 25, and SC Media Security Innovator.

Stop Breaches 84% Faster. Get Started at www.extrahop.com/demo

© 2021 ExtraHop Networks, Inc., Reveal(x), Reveal(x) 360, Reveal(x) Enterprise, and ExtraHop are registered trademarks or marks of ExtraHop Networks, Inc.

Contacts

Mentha Benek
ExtraHop
206-787-8417
pr@extrahop.com

ExtraHop

Details
Headquarters: Seattle, Washington
CEO: Greg Clark
Employees: 700
Organization: PRI

Release Summary
ExtraHop Contributes Network Security Expertise to MITRE ATT&CK Framework
Release Versions

Contacts

Mentha Benek
ExtraHop
206-787-8417
pr@extrahop.com

More News From ExtraHop

ExtraHop® Unveils Advanced Network Detection Capabilities to Stop Malicious PowerShell Attacks

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today announced powerful new capabilities to detect the malicious use of PowerShell. These enhancements deliver the critical visibility needed to dismantle the attack kill chain, providing essential insight to stop lateral movement in its tracks. Remote management tools like PowerShell have become a notable weapon for attackers, like the Qilin Ransomware-as-a-Service (RaaS) operation, which has hit man...

ExtraHop® Expands Presence in EMEA to Meet Enterprise Demand for NDR

SEATTLE & LONDON--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today announced its expansion into the Nordics and Benelux markets. This strategic move strengthens the company's European footprint on the heels of a period of significant enterprise growth. Following a strong 2024, in which ExtraHop more than doubled its sales to Global 2000 customers in EMEA, the company is bringing its proven momentum to two of the continent's most dynamic markets housing...

ExtraHop® Report Finds Ransomware Payouts Hit Record Highs as Attackers Adapt

SEATTLE--(BUSINESS WIRE)--ExtraHop®, a leader in modern network detection and response (NDR), today released the 2025 ExtraHop Global Threat Landscape Report, which offers a comprehensive analysis of the ever-shifting cybersecurity landscape. The report examines the ever-expanding attack surface, detailing the evolving tactics threat actors are leveraging to exploit organizations and carry out lucrative attacks. According to the findings, threat actors are shifting away from broad, indiscrimina...
Back to Newsroom