Palo Alto Networks Blog 2024年07月04日
Palo Alto Networks Excels in MITRE Managed Services Evaluation
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Palo Alto Networks的Unit 42 MDR部门在MITRE Engenuity的第二届ATT&CK管理服务评估中表现出色,其平均检测时间(MTTD)是参与者平均水平的两倍。该部门利用了Palo Alto Networks的行业领先产品Cortex XDR,该产品在上一轮MITRE企业评估中实现了100%的保护和100%的检测覆盖率。

😁 **MITRE Engenuity的ATT&CK管理服务评估:menuPass+ALPHV BlackCat**:评估是一个为期5天的严格测试,旨在模拟现实世界中高度复杂的威胁,测试中,供应商无法事先获得有关攻击者或技术的信息,并以与向客户提供报告相同的格式提供分析。

😊 **Unit 42 MDR的出色表现**:Unit 42 MDR团队利用Cortex XDR、高保真威胁情报和AI驱动的分析准确地识别出两个攻击者为APT10(又名menuPass)和BlackCat(又名ALPHV),并映射了评估中可疑活动的关键细节,识别了攻击者的行动和意图,帮助客户了解攻击者的战术和工具,从而更好地针对防御策略并提高网络弹性。

😉 **与Cortex XDR的无缝集成**:Unit 42 MDR与Cortex XDR无缝集成,所有Unit 42 MDR客户都可以立即访问Cortex XDR控制台中的所有警报。通常,在识别到经验证的威胁后,我们会立即通知客户并启动修复措施。但是,由于MITRE在本次测试中不允许进行修复,因此我们提供了修复和姿势加固的建议。

😎 **行业领先的XDR支持**:Unit 42 MDR服务是行业领先的扩展检测和响应技术(Cortex XDR)与世界知名的Unit 42专业知识和威胁情报的强大组合。Unit 42 MDR包括主动威胁狩猎,以帮助客户检测最具规避性和最复杂的威胁。

🤩 **MITRE评估中的MTTD定义**:MITRE Engenuity在本次评估中以独特的方式定义了MTTD:“MTTD是攻击运行时间与管理服务提供商触发针对此攻击的警报之间的时间差。使用与相关步骤相关的第一封电子邮件的时间戳。”

Palo Alto Networks Unit 42 is a leader in MDR, delivering MTTD twice as fast as the average participant and leveraging the industry’s best XDR technology.

Today, MITRE Engenuity unveiled the results of its second-ever ATT&CK Evaluations for Managed Services. For the second consecutive year, Unit 42 Managed Detection and Response (MDR) excelled in the evaluation, delivering MTTD twice as fast as the average participant. We leveraged Palo Alto Networks industry-leading Cortex XDR, the only product that achieved 100% protection and 100% detection coverage during the previous round of the MITRE Enterprise Evaluations. With Cortex XDR behind Unit 42 MDR, we deliver the industry’s best detection and response to sophisticated cyberthreats.

Unit 42 MDR sent 37 email alerts during the evaluation. Other vendors sent more than 300 email alertsnearly 10x the amount we sent.

We deliver the most important and actionable information as quickly as possible in order to enable accurate, efficient and confident decisions about next steps. With Unit 42 MDR, customers receive a balanced combination of high-quality information, granularity and speed.

As part of the evaluation, we delivered a detailed threat report highlighting crucial information for response and remediation. Our executive summary quickly identifies answers to the most important questions facing an organization under attack:

Background on the test — MITRE ATT&CK Evaluation Managed Services: menuPass + ALPHV BlackCat.

Third-party evaluations like MITRE’s shed light on how vendors would realistically perform against real-world, highly sophisticated threats in a customer environment.

This year’s evaluation was a rigorous 5-day test, named MITRE ATT&CK Evaluation Managed Services: menuPass + ALPHV BlackCat. The evaluation is closed book; vendors are not given prior information on the adversary or techniques. Vendors provide analysis in the same format they deliver reports to their customers. MITRE Engenuity’s evaluation prohibits prevention or remediation, unlike in real-world scenarios.

According to MITRE, this test included sophisticated techniques, including multi-subsidiary compromise with overlapping operations focusing on defense evasion, exploiting trusted relationships, data encryption and inhibiting system recovery.

Our Results

Our Unit 42 MDR team leveraged Cortex XDR, high fidelity threat-intelligence and AI-powered analytics to accurately identify/attribute the two adversaries as APT10 (aka menuPass) and BlackCat (aka ALPHV).

We mapped key details of the suspicious activity in the evaluation to MITRE ATT&CK TTPs and identified the threat actors’ maneuvers and intentions. By helping our customers understand adversary tactics and tools, they can better target their defense strategies and improve cyber resilience.

In the first few pages of our threat report, we included a threat brief that accurately identified the impacted hosts and usernames on the attack chain. Our report accompanied messages to the customer, delivered via Cortex XDR. Unit 42 MDR is natively integrated into Cortex XDR and all Unit 42 MDR customers have immediate access to all alerts in the Cortex XDR console.

Normally, we would immediately inform the customer upon identifying a verified threat and start remediation actions. However, remediation was not permitted by MITRE in this test, so we provided recommendations for remediation and posture hardening.

We’re the Only Vendor Backed by the Best XDR on the Market

Our Unit 42 MDR service is a powerful combination of the industry’s best extended detection and response technology – Cortex XDR – and world-renowned Unit 42 expertise and threat intelligence. Unit 42 MDR includes proactive threat hunting to help customers detect the most evasive and sophisticated threats.

Organizations partner with MDR providers to help them more quickly, accurately and effectively address threats 24/7/365. According to the Unit 42 Incident Response Report, attacks are happening in just hours, and time to exfiltration is often less than a day. Read our MDR threat report and see how Unit 42 can help your organization accurately and quickly understand the most important information related to a threat with actionable, clear recommendations.

We want to thank the MITRE Engenuity team for the effort they put into running this evaluation.

Learn more about Unit 42 Managed Services and how we can help your organization better defend against today’s threats.

A Note About MTTD

Importantly, in this evaluation MITRE Engenuity defined MTTD in a unique way: “MTTD is the average time between when an attack is run and when the managed service provider triggers an alert on this attack. The timestamp on the first email relevant to the step in question was used.” You may be confused as usually MTTD is defined as the average time of alert detection within the product. MITRE Engenuity advised they use email timestamps as they’re immutable and cannot be manipulated on the backend.

These results continue a trend of industry-leading validation for Cortex XDR and Unit 42 MDR in independent, third-party security assessments, including the MITRE Enterprise ATT&CK Evaluations, Forrester XDR Wave and Frost Radar: Global MDR.

MITRE does not rank or rate participants in the evaluation

This blog refers to MITRE Engenuity’s Managed Services Evaluation, which is different to MITRE Engenuity Enterprise Evaluations.
Read our Threat Report
here.

The post Palo Alto Networks Excels in MITRE Managed Services Evaluation appeared first on Palo Alto Networks Blog.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

MITRE ATT&CK 管理服务 Unit 42 MDR Cortex XDR
相关文章