MITRE announced last week that the latest update to the popular ATT&CK framework introduces techniques related to containers and the Google Workspace platform.
ATT&CK is a knowledge base of adversary tactics and techniques that is based on real-world observations. ATT&CK v9 adds container-related attack techniques, which is the result of a project conducted by MITRE’s Center for Threat-Informed Defense and sponsored by Microsoft, Citigroup and JPMorgan Chase.
There has been a debate on whether or not container techniques should be added considering that in a vast majority of cases they lead to cryptomining. However, containers have also been used by malicious actors for other purposes, including data harvesting and exfiltration. It has been determined that these incidents are “publicly under reported,” which is why developers of the ATT&CK framework have decided to include container-related techniques.
As for the addition of Google Workspace, MITRE explained, “Since ATT&CK already covers Office 365, we wanted to ensure that users of Google’s productivity tools were also able to map similar applicable adversary behaviors to ATT&CK.”
Another significant change in ATT&CK v9 is related to cloud platforms — AWS, Azure and Google Cloud Platform have been consolidated into a single infrastructure-as-a-service (IaaS) platform.
The latest version also includes some updates to macOS techniques and some changes in how data sources are described.
ATT&CK v9 covers 14 tactics, 185 techniques, and 367 sub-techniques, as well as 16 new threat groups and 67 new pieces of software. All new elements and updates are detailed on MITRE’s website. The next major update for the framework is scheduled for October.
Last year, MITRE announced the release of an ATT&CK knowledge base for industrial control systems (ICS), and introduced a knowledge base of techniques and tactics that defenders can use to secure their networks and assets.
Related: MITRE Uses ATT&CK Framework to Evaluate Enterprise Security Products
Related: MITRE ATT&CK Used for Cybersecurity Skills Development
Related: FireEye Proposes Converged Enterprise and ICS ATT&CK Matrix
Related: Where To Begin With MITRE ATT&CK Matrix

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
- Russia Blames US Intelligence for iOS Zero-Click Attacks
- Cisco Acquiring Armorblox for Predictive and Generative AI Technology
- Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks
- Organizations Warned of Salesforce ‘Ghost Sites’ Exposing Sensitive Information
- Organizations Warned of Backdoor Feature in Hundreds of Gigabyte Motherboards
- Barracuda Zero-Day Exploited to Deliver Malware for Months Before Discovery
- Industrial Giant ABB Confirms Ransomware Attack, Data Theft
- Zyxel Firewalls Hacked by Mirai Botnet
Latest News
- Google Temporarily Offering $180,000 for Full Chain Chrome Exploit
- Russia Blames US Intelligence for iOS Zero-Click Attacks
- Toyota Discloses New Data Breach Involving Vehicle, Customer Information
- Cisco Acquiring Armorblox for Predictive and Generative AI Technology
- Moxa Patches MXsecurity Vulnerabilities That Could Be Exploited in OT Attacks
- Amazon Settles Ring Customer Spying Complaint
- Organizations Warned of Salesforce ‘Ghost Sites’ Exposing Sensitive Information
- Adobe Inviting Researchers to Private Bug Bounty Program
