The Monkey maps its actions to the MITRE ATT&CK knowledge base: It provides a new report with the utilized techniques and recommended mitigations, to help you simulate an APT attack on your network and mitigate real attack paths intelligently.
Watch an overview video:
The MITRE ATT&CK report is centred around the ATT&CK matrix:
The Monkey rates your network on the attack techniques it attempted. For each technique, you can get
Then, you can see exactly HOW the technique was used in this attack, and also what you should do to mitigate it, by clicking on the technique and seeing the details. For example, let’s look at the Brute Force technique that’s a part of employing the Credentials Access tactic:
In this example, you can see how the Monkey was able to use one old
root password to access all machines in the network. When scrolling to the bottom of this list, you can also see the mitigation recommended, including Account Use Policies and implementing Multiple Factor Authentication.