Just what are "tactics"? Introduction MITRE ATT&CK is a great resource, but something about it has bothered me since I first heard about it several years ago. It's a minor point, but I wanted to document it in case it confuses anyone else. The MITRE ATT&CK Design and Philosophy document from March 2020 says the following: At a high-level, ATT&CK is a behavioral model that consists of the following core components: • Tactics, denoting short-term, tactical adversary goals during an attack; • Techniques, describing the means by which adversaries achieve tactical goals; • Sub-techniques, describing more specific means by which adversaries achieve tactical goals at a lower level than techniques; and • Documented adversary usage of techniques, their procedures, and other metadata. My concern is with MITRE's definition of "tactics" as "short-term, tactical adversary goals during an attack," which is oddly recursive. The key word in the tacti
Comments
http://www.vmware.com/community/message.jspa?messageID=371562
AFAIK you can't currently turn a physical NIC on the host box into a vswitch tap, maybe that'll be part of it. I suspect the primary driver for this will be the "usual" stuff on managed switches that you can't get on a vswitch. Things like some L3 functionality, 802.1X maybe, and other means of allowing better control over ports on vswitches.
I'm definitely looking forward to hearing details about Cisco's plans. Should be interesting.