News Releases3 min read

Carbon Black Delivers MITRE ATT&CK™ Coverage with Zero Delayed Detections & Zero Tainted Detections

ATT&CK assessment from the MITRE Corporation measured CB Response’s effectiveness in detecting a range of adversary tactics and techniques

Carbon Black also adds MITRE ATT&CK threat intelligence feeds to CB Response and CB ThreatHunter to advance behavior-based threat hunting across endpoints

WALTHAM, Mass. — November 30, 2018 ––Carbon Black (NASDAQ: CBLK), a leader in next-generation endpoint security delivered via the cloud, today announced that it delivered zero delayed detections and zero tainted detections in the MITRE Corporation’s Adversarial Tactics, Techniques and Common Knowledge (ATT&CK) assessment. The MITRE assessment tests the ability to quickly detect specific adversary tactics and techniques as captured in the ATT&CK knowledgebase.

_________

Tweet this: .@CarbonBlack_Inc delivers @MITREattack coverage with zero delayed detections & zero tainted detections – http://ow.ly/FEr230mOD07

_________

The evaluations for this initial testing period used a MITRE-developed APT3 emulation plan on behavior detection, telemetry and enrichment, among other elements. In the assessment, CB Response demonstrated it could automatically detect and display adversarial behaviors without humans-in-the-loop across the entire MITRE ATT&CK Matrix, which includes: initial access, execution, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, exfiltration, and command and control.

“We’re proud to be among the initial vendors evaluated by MITRE and we’re extremely proud of these results. We attribute our very strong showing to our philosophy of building products the right way for the long haul,” said Scott Lundgren, Carbon Black’s Chief Technology Officer. “Objective, transparent and open testing is critical as a means of driving the industry forward, and the MITRE ATT&CK framework offers a critical look at how real-world attacks play out. We believe MITRE has set an excellent standard for how testing should be conducted in an open, rigorous, and sophisticated way. We thank MITRE for its leadership.”

“We’re very pleased with the participation in our first round of ATT&CK-based evaluations,” said Frank Duff, MITRE lead engineer for the evaluations program. “Effective cybersecurity can’t be done alone. We look forward to continued collaboration with the industry to help vendors understand their capabilities against known adversary behaviors, and empower customers to more effectively buy and deploy these security solutions.”

MITRE ATT&CK Threat Intelligence Feeds for CB Response & CB ThreatHunter

In conjunction with the assessment results, Carbon Black announced it has added MITRE ATT&CK threat intelligence feeds to CB Response and CB ThreatHunter to deliver new behavior-based threat intelligence to customers.

Carbon Black’s MITRE ATT&CK feeds combine the power of Carbon Black’s unfiltered endpoint data collection and a robust collection of adversary techniques to simplify threat detection and threat hunting. The new threat feeds map directly to the various attack tactics outlined by MITRE.

“By adding ATT&CK threat intelligence feeds to CB Response and CB ThreatHunter, organizations now have an unfiltered view into all endpoint activity viewed through the lens of attack building blocks and behaviors noted by MITRE. We believe this results in more comprehensive and advanced threat hunting capabilities for security professionals,” said Lundgren. “The ATT&CK threat intelligence feeds directly integrate detection of ATT&CK tactics and techniques into the CB Response and CB ThreatHunter products, underscoring Carbon Black’s commitment to ATT&CK and other open standards and frameworks.”
_________

Tweet this: .@CarbonBlack_Inc adds @MITREattack threat feeds to CB Response and CB ThreatHunter to advance behavior-based threat hunting across endpoints – http://ow.ly/FEr230mOD07

_________

Resources

About Carbon Black

Carbon Black (NASDAQ: CBLK) is a leading provider of next-generation endpoint security delivered via the cloud. Leveraging its big data and analytics cloud platform – the CB Predictive Security Cloud – Carbon Black consolidates prevention, detection, response, threat hunting and managed services into a single platform with a single agent and single console, making it easier for organizations to consolidate security stacks and achieve better protection. As a cybersecurity innovator, Carbon Black has pioneered multiple endpoint security categories, including application control, endpoint detection and response (EDR), and next-generation antivirus (NGAV) enabling customers to defend against the most advanced threats. More than 4,600 global customers, including one-third of the Fortune 100, trust Carbon Black to keep their organizations safe.

Carbon Black and CB Predictive Security Cloud are registered trademarks or trademarks of Carbon Black, Inc. in the United States and/or other jurisdictions.