-

New Round of MITRE Engenuity’s ATT&CK® Evaluations Calls for Participation for Enterprise Cybersecurity Solutions

ATT&CK Evaluations to examine behaviors across ransomware with an introduction to macOS

MCLEAN, Va. & BEDFORD, Mass.--(BUSINESS WIRE)--MITRE Engenuity opened its call for participation in ATT&CK® Evaluations, an independent and objective assessment of enterprise cybersecurity solutions. This sixth round of evaluations will examine common behaviors that are prevalent across prolific ransomware campaigns and feature an introduction into macOS, specifically focusing on macOS targeting by the Democratic People’s Republic of Korea (DPRK).

Through the lens of the MITRE ATT&CK knowledge base, this round of evaluations will focus on key adversary behaviors inspired by ransomware.

Share

“We're thrilled to broaden the scope of ATT&CK Evaluations to include macOS, emphasizing our commitment to comprehensive, platform-diverse assessments,” said William Booth, general manager, ATT&CK Evals. “This round will feature new insights, with a particular focus on efficiency, including true positive and false positive rates, which more accurately reflect the real-world performance of a tool.”

Through the lens of the MITRE ATT&CK knowledge base, this round of evaluations will focus on key adversary behaviors inspired by ransomware, such as the abuse of legitimate tools and efforts to evade defenses. The macOS emulation will delve into adversary behavior inspired by the DPRK’s shift into developing sophisticated, multi-stage malware.

“We chose to emulate ransomware, as it continues to be one of the most significant cybercriminal threats across industry verticals – one that can lead to devastating outcomes and widespread damage,” said Amy Robertson, principal, cyber threat intelligence analyst, ATT&CK Evals. “The DPRK has emerged as a formidable cyber threat, and they have progressively been expanding their focus to macOS as they work to evade international sanctions. This round will also incorporate multiple smaller emulations, introducing a more nuanced and targeted evaluation of defensive capabilities.”

These open and fair evaluations are part of MITRE Engenuity’s portfolio of programs to help government and industry combat cybersecurity attacks through threat-informed defense practices. The evaluations do not rank vendors and their solutions; however, organizations can use the results to determine which vendors and solutions may best address their own cybersecurity gaps and fit their particular business needs.

Participants must sign up for the evaluations by April 30, 2024. Results of the evaluations will be posted in the fourth quarter of 2024. For results of previous evaluations, visit https://attackevals.mitre-engenuity.org

ABOUT MITRE ENGENUITY

MITRE Engenuity, a subsidiary of MITRE, is a tech foundation for public good. MITRE’s mission-driven teams are dedicated to solving problems for a safer world. Through our public-private partnerships and federally funded R&D centers, we work across government and in partnership with industry to tackle challenges to the safety, stability, and well-being of our nation.

MITRE Engenuity brings MITRE’s deep technical know-how and systems thinking to the private sector to solve complex challenges that government alone cannot solve. MITRE Engenuity catalyzes the collective R&D strength of the broader U.S. federal government, academia, and private sector to tackle national and global challenges, such as protecting critical infrastructure, creating a resilient semiconductor ecosystem, building a genomics center for public good, accelerating use case innovation in 5G, and democratizing threat-informed cyber defense. www.mitre-engenuity.org

ABOUT MITRE ENGENUITY ATT&CK® EVALUATIONS

ATT&CK® Evaluations is built on the backbone of MITRE’s objective insight and conflict-free perspective. Cybersecurity vendors turn to the Evals program to improve their offerings and to provide defenders with insights into their product’s capabilities and performance. Evals enables defenders to make better informed decisions on how to leverage the products that secure their networks. The program follows a rigorous, transparent methodology, using a collaborative, threat-informed, purple-teaming approach that brings together vendors and MITRE experts to evaluate solutions within the context of ATT&CK. In line with MITRE Engenuity’s commitment to serve the public good, Evals results and threat emulation plans are freely accessible. https://attackevals.mitre-engenuity.org/

Contacts

Media Contact: Lisa Fasold, media@mitre.org

MITRE


Release Versions

Contacts

Media Contact: Lisa Fasold, media@mitre.org

Social Media Profiles
More News From MITRE

MITRE and FAA Introduce Novel Aerospace Large Language Model Evaluation Benchmark

MCLEAN, Va.--(BUSINESS WIRE)--The Federal Aviation Administration (FAA) and MITRE are introducing a new benchmark to enable the evaluation and assessment of large language models (LLMs) for aerospace tasks. Given the safety-critical nature of aerospace, it is imperative that LLMs undergo thorough evaluation prior to their integration into systems. The Aerospace Language Understanding Evaluation (ALUE) benchmark provides a crucial tool for guiding the assurance of LLMs tailored to the unique dem...

New Defense Acquisition Framework to Accelerate Technology Transition to Warfighters

MCLEAN, Va., & BEDFORD, Mass.--(BUSINESS WIRE)--The National Security Engineering Center (NSEC), a federally funded research and development center (FFRDC) operated by MITRE, unveiled the Transition Maturity Framework (TMaF) today. TMaF is a comprehensive defense acquisition framework developed to streamline the transition of innovative technologies from research labs to active deployment with U.S. warfighters. The framework addresses persistent challenges by providing a structured acquisition...

Lloyds Banking Group Becomes First U.K. Financial Services Benefactor of MITRE ATT&CK®

MCLEAN, Va. & LONDON--(BUSINESS WIRE)--Lloyds Banking Group has become the first U.K. financial services benefactor of MITRE ATT&CK® to help globally advance threat-informed defense. The MITRE ATT&CK open-source framework enables organizations to understand how adversaries operate so they can better manage cyber risks and strengthen defenses. MITRE ATT&CK is a cornerstone of Lloyds Banking Group’s cyber defense strategy, providing a unified language to describe and analyze adversary...
Back to Newsroom