As far as embedding the TTPs in every marketing white paper out there, yeah, agree that’s dumb.
I don't think cataloguing things is intrinsically a waste of time.
I do think that a unified theory of how networks and computers are compromised is a pipe dream that doesn't reward the effort put into building or studying it.
Mostly, I think ATT&CK has done far more good for vendors as the basis for feature/function/benefit breakdowns than it has for practitioners.
Like I said, there are no "good" lists.
You have another that you send to read about cached credentials in a textbook.
You’re telling me the former does not come out ahead of the latter?
This (my) view is orthogonal to Windows vs Everything Else. When you're working at a medium-cap manufacturer of widgets, software has already eaten your business, but you're not going to attract employees like taviso, right? So you give your people ATT&CK and it's better than nothing.
But really all I wanted to chip in with here is that ATT&CK is also an eye-roll topic, even for people working in the specializations where ATT&CK applies. Not all the things in ATT&CK, many of which are important, but ATT&CK itself. I'm making a descriptive statement, not a normative one.
Suffice it to say, I'm an appsec person, by way of an earlier career in vulnerability research, and ATT&CK is not a meaningful part of my field.
Because they're not listening when we tell them to not roll their own crypto!
Or in a more serious tone: organisations often ignore best current practices, even after they spent a lot of money to have us look at their work and we told them what mistakes we found. Maybe we should indeed work more on making it easier to do things right, rather than just telling them how to do it right. It feels a bit like how you can at least distribute free needles to avoid infectious diseases when you can't stop people from being addicted to drugs.
Although if you look at pure research (not just advice not being followed), the gap indeed gets even bigger. Things like formal verification is great for academics but what would really help organisations is robust append-only, easy-to-restore backups to recover without paying after their stuff got encrypted again. But that's not sexy clever research, that's just some plumbing. While that sort of plumbing is not typically considered our job as security testers, it would be a solution that can make a real difference when looking at the attacks being done. (Criminals can still try blackmailing, but that seems to be much less lucrative on average, and good backups are also useful for accidental data destruction.)
> I don't know, [...] I work primarily in software security and vulnerability research, and not IT security. [52m ago, parent post]
Umm, so do you think IT security (I'd say pentests fall well within IT security, let me know if that's where you disagree) is within your competency or not?
As soon as you move into prod servers you're typically talking about cloud/infrasec people, who are distinct from IT security people. Infrasec: IAM; IT Security: Active Directory.
As soon as you move to actual code that the corporation writes/maintains, you're in appsec. If your IT security group owns appsec, you're not doing appsec.
Aren't Windows shops the primary audience for ATT&CK?
Based on what data?