SlideShare a Scribd company logo
Building an Atomic
Testing Program
Test. Measure. Improve.
What is
“atomic testing”?
Think this
Not this
An atomic test is
1. Small (one ATT&CK technique)
2. Easy to execute
https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1007/T1007.md
Why test
atomically?
Testing your coverage is fundamental to
improving your security outcomes.
Testing should be fast and easy.
Defenders need to keep learning how
adversaries are operating.
Another red team suggestion (hat tip: Tim McG —
https://www.twitter.com/NotMedic) is to use ATT&CK
before you even plan your next red team campaign.
Roll the dice and randomly select 2–3 TTPs from
each column and that becomes the fake adversary
that you are emulating.
https://medium.com/@malcomvetter/red-team-use-of-mitre-att-ck-f9ceac6b3be2
“
MITRE ATT&CKcon 2018: Building an Atomic Testing Program, Brian Beyer, Red Canary
“Probably useful”
Now what?
https://atomicredteam.io
https://github.com/redcanaryco/atomic-red-team/find/master
MITRE ATT&CKcon 2018: Building an Atomic Testing Program, Brian Beyer, Red Canary
MITRE ATT&CKcon 2018: Building an Atomic Testing Program, Brian Beyer, Red Canary
How can I use
Atomic Tests?
Ways to use Atomic Tests:
1) Create a recurring calendar invite
2) Know thy gaps
3) Hold your team accountable
4) Hold your partners/vendors accountable
http://atomicredteam.io
/roll-the-dice
Subscribe to the
Red Canary blog:
redcanary.com/blog
Contribute tests to
Atomic Red Team:
atomicredteam.io

More Related Content

PDF
Knowledge for the masses: Storytelling with ATT&CK
PPTX
Purple Teaming with ATT&CK - x33fcon 2018
PDF
ATT&CK Updates- Defensive ATT&CK
PDF
Adversary Emulation - Red Team Village - Mayhem 2020
PDF
Exploring how Students Map Social Engineering Techniques to the ATT&CK Framew...
PDF
Adversary Emulation Workshop
PPTX
Adversary Emulation using CALDERA
PDF
State of the ATT&CK
Knowledge for the masses: Storytelling with ATT&CK
Purple Teaming with ATT&CK - x33fcon 2018
ATT&CK Updates- Defensive ATT&CK
Adversary Emulation - Red Team Village - Mayhem 2020
Exploring how Students Map Social Engineering Techniques to the ATT&CK Framew...
Adversary Emulation Workshop
Adversary Emulation using CALDERA
State of the ATT&CK

What's hot (20)

PDF
ATT&CKcon Intro
PDF
MITRE ATT&CKcon 2.0: Using Threat Intelligence to Focus ATT&CK Activities; Da...
PDF
It's just a jump to the left (of boom): Prioritizing detection implementation...
PDF
ATT&CKing the Red/Blue Divide
PPTX
ATT&CKing with Threat Intelligence
PPTX
Using IOCs to Design and Control Threat Activities During a Red Team Engagement
PDF
Purple Team Exercise Framework Workshop #PTEF
PDF
Purple Team Exercises - GRIMMCon
PDF
Threat Modelling - It's not just for developers
PDF
Intelligence Failures of Lincolns Top Spies: What CTI Analysts Can Learn Fro...
PDF
Adversary Emulation and Red Team Exercises - EDUCAUSE
PDF
ATT&CK Updates- ATT&CK for ICS
PDF
Threat-Based Adversary Emulation with MITRE ATT&CK
PDF
Fantastic Red Team Attacks and How to Find Them
PDF
FIRST CTI Symposium: Turning intelligence into action with MITRE ATT&CK™
PDF
Managing & Showing Value during Red Team Engagements & Purple Team Exercises ...
PDF
Measure What Matters: How to Use MITRE ATTACK to do the Right Things in the R...
PPTX
Putting MITRE ATT&CK into Action with What You Have, Where You Are
PDF
MITRE ATT&CK Framework
PPTX
Introduction to Malware Detection and Reverse Engineering
ATT&CKcon Intro
MITRE ATT&CKcon 2.0: Using Threat Intelligence to Focus ATT&CK Activities; Da...
It's just a jump to the left (of boom): Prioritizing detection implementation...
ATT&CKing the Red/Blue Divide
ATT&CKing with Threat Intelligence
Using IOCs to Design and Control Threat Activities During a Red Team Engagement
Purple Team Exercise Framework Workshop #PTEF
Purple Team Exercises - GRIMMCon
Threat Modelling - It's not just for developers
Intelligence Failures of Lincolns Top Spies: What CTI Analysts Can Learn Fro...
Adversary Emulation and Red Team Exercises - EDUCAUSE
ATT&CK Updates- ATT&CK for ICS
Threat-Based Adversary Emulation with MITRE ATT&CK
Fantastic Red Team Attacks and How to Find Them
FIRST CTI Symposium: Turning intelligence into action with MITRE ATT&CK™
Managing & Showing Value during Red Team Engagements & Purple Team Exercises ...
Measure What Matters: How to Use MITRE ATTACK to do the Right Things in the R...
Putting MITRE ATT&CK into Action with What You Have, Where You Are
MITRE ATT&CK Framework
Introduction to Malware Detection and Reverse Engineering
Ad

More from MITRE - ATT&CKcon (20)

PDF
ATTACKers Think in Graphs: Building Graphs for Threat Intelligence
PDF
State of the ATTACK
PDF
ATTACK-Onomics: Attacking the Economics Behind Techniques Used by Adversaries
PDF
MITRE ATTACKcon Power Hour - January
PDF
Using ATTACK to Create Cyber DBTS for Nuclear Power Plants
PDF
Sharpening your Threat-Hunting Program with ATTACK Framework
PDF
Helping Small Companies Leverage CTI with an Open Source Threat Mapping
PDF
What's New with ATTACK for ICS?
PDF
From Theory to Practice: How My ATTACK Perspectives Have Changed
PDF
Putting the PRE into ATTACK
PDF
What's a MITRE with your Security?
PDF
ATTACKing the Cloud: Hopping Between the Matrices
PDF
Mapping the EventBot Mobile Banking Trojan with MITRE ATTACK for Mobile
PDF
Transforming Adversary Emulation Into a Data Analysis Question
PDF
TA505: A Study of High End Big Game Hunting in 2020
PDF
Using MITRE PRE-ATTACK and ATTACK in Cybercrime Education and Research
PDF
What's New with ATTACK for Cloud?
PDF
Starting Over with Sub-Techniques
PDF
MITRE ATTACKCon Power Hour - December
PDF
MITRE ATT&CKcon Power Hour - November
ATTACKers Think in Graphs: Building Graphs for Threat Intelligence
State of the ATTACK
ATTACK-Onomics: Attacking the Economics Behind Techniques Used by Adversaries
MITRE ATTACKcon Power Hour - January
Using ATTACK to Create Cyber DBTS for Nuclear Power Plants
Sharpening your Threat-Hunting Program with ATTACK Framework
Helping Small Companies Leverage CTI with an Open Source Threat Mapping
What's New with ATTACK for ICS?
From Theory to Practice: How My ATTACK Perspectives Have Changed
Putting the PRE into ATTACK
What's a MITRE with your Security?
ATTACKing the Cloud: Hopping Between the Matrices
Mapping the EventBot Mobile Banking Trojan with MITRE ATTACK for Mobile
Transforming Adversary Emulation Into a Data Analysis Question
TA505: A Study of High End Big Game Hunting in 2020
Using MITRE PRE-ATTACK and ATTACK in Cybercrime Education and Research
What's New with ATTACK for Cloud?
Starting Over with Sub-Techniques
MITRE ATTACKCon Power Hour - December
MITRE ATT&CKcon Power Hour - November
Ad

Recently uploaded (20)

PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Electronic commerce courselecture one. Pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Encapsulation theory and applications.pdf
PPTX
sap open course for s4hana steps from ECC to s4
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
Advanced methodologies resolving dimensionality complications for autism neur...
Electronic commerce courselecture one. Pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Understanding_Digital_Forensics_Presentation.pptx
Machine learning based COVID-19 study performance prediction
Review of recent advances in non-invasive hemoglobin estimation
Encapsulation theory and applications.pdf
sap open course for s4hana steps from ECC to s4
Digital-Transformation-Roadmap-for-Companies.pptx
The AUB Centre for AI in Media Proposal.docx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Network Security Unit 5.pdf for BCA BBA.
NewMind AI Weekly Chronicles - August'25 Week I
Dropbox Q2 2025 Financial Results & Investor Presentation

MITRE ATT&CKcon 2018: Building an Atomic Testing Program, Brian Beyer, Red Canary