{"id":23076,"date":"2023-10-06T08:11:34","date_gmt":"2023-10-06T16:11:34","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/10\/06\/news-16806\/"},"modified":"2023-10-06T08:11:34","modified_gmt":"2023-10-06T16:11:34","slug":"news-16806","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/10\/06\/news-16806\/","title":{"rendered":"2023 MITRE ATT&#038;CK\u00ae Evaluation results: Malwarebytes earns high marks for detection, blocks initial malware executions"},"content":{"rendered":"<p>MITRE Engenuity released its 2023 ATT&amp;CK Evaluation results, with Malwarebytes blocking&nbsp;initial&nbsp;malware executions and earning high marks for detection.<\/p>\n<p>The evaluation tested 30 vendor solutions against Turla, a sophisticated Russia-based advanced persistent threat (APT) group with victims in over 45 countries.<\/p>\n<p>MITRE Engenuity&rsquo;s researchers recorded how well products could analyze and prevent techniques associated with the group, evaluating vendors&rsquo; ability to detect &ldquo;step&rdquo; of an attack, provide quality alerts with robust information to the end-user, and so on.<\/p>\n<p>Let&rsquo;s take a closer look at the results and how organizations should use them.<\/p>\n<h2>2023 MITRE ATT&amp;CK&reg; Evaluation Results<\/h2>\n<p>MITRE executed two attack scenarios throughout the course of the evaluation: Attack Scenario 1 (&ldquo;Carbon&rdquo;) and Attack Scenario 2 (&ldquo;Snake&rdquo;). With the &ldquo;Carbon&rdquo; attack scenario consisting of 10 steps and &ldquo;Snake&rdquo; consisting of 9, MITRE Engenuity executed a total of 19 steps during the evaluation.<\/p>\n<p>Malwarebytes alerted on 19\/19 steps with no configuration changes, meaning our EDR tool was able to convert telemetry into actionable threat detections &ldquo;out of the box&rdquo; for parts of each step.<\/p>\n<p>The MITRE Engenuity red team also tested cybersecurity solution providers on their protection capabilities&mdash;what malicious actions can a solution prevent. For the Protections scenario, there were 129 substeps organized into 13 major steps.<\/p>\n<p>Malwarebytes broke the Turla attack kill chain at the initial phase and 6 subsequent steps, including initial malware execution, subsequent malware execution on Domain Controller and other machines, lateral movement, and credential dumping.<\/p>\n<h2>Analyzing The MITRE ATT&amp;CK&reg; Evaluation Results<\/h2>\n<p>The MITRE ATT&amp;CK&reg; Evaluation is a valuable independent security test, though its relevance will likely vary on the size of your security team.<\/p>\n<p>Larger organizations with more advanced security teams, for example, might find the test particularly&nbsp;useful given its focus on nation-state level actors. The opposite might be true for smaller security teams, who are less affected by threats like Turla.<\/p>\n<p>As organizations go through the data available in MITRE Engenuity&rsquo;s evaluation portal, keep in mind several other important questions such as: Who will be using the tool MITRE is evaluating? Is it easy to use? Does it have too many unnecessary features for&nbsp;my security goals?<\/p>\n<p>Additional questions to consider asking include:<\/p>\n<ul>\n<li>Would the attack have been stopped at step 1 in a real-world scenario?<\/li>\n<li>Does the APT attack apply to my business?<\/li>\n<li>Do I need to detect 100% of these substeps to be 100% protected?<\/li>\n<\/ul>\n<p>In sum, while the MITRE ATT&amp;CK Evaluation is undoubtedly important, its results are best considered alongside other independent tests such as <a href=\"https:\/\/www.malwarebytes.com\/blog\/business\/2023\/06\/malwarebytes-only-vendor-to-win-every-mrg-effitas-certification-award-in-2022\">MRG Effitas 360&deg; Assessment &amp; Certification<\/a>, <a href=\"https:\/\/www.malwarebytes.com\/blog\/business\/2023\/09\/malwarebytes-mdr-wins-g2-awards-for-best-roi-easiest-to-use-and-more\">G2 peer-to-peer evaluations<\/a>, <a href=\"https:\/\/www.malwarebytes.com\/blog\/business\/2023\/07\/malwarebytes-stops-100-of-advanced-threats-in-latest-av-test-assessment\">AV-Test<\/a>, and more.<\/p>\n<h2>Try Malwarebytes for Business Today<\/h2>\n<p>We invite organizations to check out the full 2023 ATT&amp;CK Evaluation results on MITRE&rsquo;s official website here: <a href=\"https:\/\/attackevals.mitre-engenuity.org\/results\/enterprise?evaluation=turla&amp;scenario=1\">https:\/\/attackevals.mitre-engenuity.org\/results\/enterprise?evaluation=turla&amp;scenario=1<\/a><\/p>\n<p>Ready to try award-winning endpoint security today? Get a free trial of Malwarebytes EDR:&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/business\/request_trial\">https:\/\/www.malwarebytes.com\/business\/request_trial<\/a><\/p>\n<p style=\"text-align: center;\"><span class=\"blue-cta-bttn\" style=\"color: #ffffff;\"><a href=\"Endpoint Detection &amp; Response Free Trial\" style=\"color: #ffffff;\">Malwarebytes EDR free trial<\/a><\/span><\/p>\n<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/business\/2023\/10\/2023-mitre-attck-evaluation-results-malwarebytes-blocks-all-malicious-executions-earns-high-marks-for-detection\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding=\"10\">\n<tr>\n<td valign=\"top\" align=\"left\">\n<p>Categories: <a href=\"https:\/\/www.malwarebytes.com\/blog\/category\/business\" rel=\"category tag\">Business<\/a><\/p>\n<p>MITRE Engenuity released its 2023 ATT&#038;CK Evaluation results, with Malwarebytes blocking initial malware execution and earning high marks for detection.<\/p>\n<table width=\"100%\">\n<tr>\n<td align=\"right\">\n<p><b>(<a href=\"https:\/\/www.malwarebytes.com\/blog\/business\/2023\/10\/2023-mitre-attck-evaluation-results-malwarebytes-blocks-all-malicious-executions-earns-high-marks-for-detection\" title=\"2023 MITRE ATT&#038;CK\u00ae Evaluation results: Malwarebytes earns high marks for detection, blocks initial malware executions\">Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\/blog\/business\/2023\/10\/2023-mitre-attck-evaluation-results-malwarebytes-blocks-all-malicious-executions-earns-high-marks-for-detection\">2023 MITRE ATT&#038;CK\u00ae Evaluation results: Malwarebytes earns high marks for detection, blocks initial malware executions<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[1001],"class_list":["post-23076","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-business"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23076","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23076"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23076\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23076"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23076"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23076"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}