No Result
View All Result
  • Login
Friday, January 23, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Market Analysis

MITRE ATT&CK Evaluations Return: More Coverage, More Nuance

by FeeOnlyNews.com
1 month ago
in Market Analysis
Reading Time: 4 mins read
A A
0
MITRE ATT&CK Evaluations Return: More Coverage, More Nuance
Share on FacebookShare on TwitterShare on LInkedIn


MITRE released a new round of MITRE ATT&CK enterprise evaluations today. This round had a lot of big changes – first off, only 11 vendors participated, which is a drop off from the 19 that participated in 2024. Some of the most notable missing vendors include SentinelOne, Microsoft, and Palo Alto Networks. Overall, it seems as though some vendors prioritized their own internal product efforts over the evaluation, likely due to investment in other areas, market and economic dynamics, and changes in the landscape.

Forrester strongly believes in the power of unbiased, third-party evaluations, especially of security products. Security products can sometimes be a black box. Evaluations like these, especially when the data used is shared, make capabilities a little less opaque.

Round 7: Breaking New Ground

This round emulated Scattered Spider, a financially motivated cybercriminal collective, and Mustang Panda, a PRC espionage group.

The MITRE ATT&CK team made big changes to the infrastructure in the evaluation to make it more realistic to a real-world scenario. The environment had more endpoints and subnets which were built out into a more realistic and complex network topology. Much like last round when they introduced expanded coverage with macOS, this year they expanded coverage to the cloud in addition to Windows and Linux devices.

The evaluations also expanded the scope to additional telemetry sources like identity, email, and cloud. For example, some of the emulations included identity compromise through SSO and MFA as well as abuse of cloud services.

MITRE included unmanaged devices in the evaluation, which demonstrated a blind spot for many providers.  Unmanaged devices emulates real-world environments where organizations have BYO devices without managed agents, 3rd party contractors accessing on-premises or remotely, or test networks where endpoints won’t run standard protections.

A nuance worth noting is that the vendor tools used in this round are disparate. In past years, most vendors tested their EDR tool, but in this round, there were a variety of modules used together. For example, Trend Micro used modules from its Vision One platform, including: endpoint security, network security, cloud security, and exposure management. WithSecure used its EPP, XDR, and exposure management capabilities. Cyberani used a combination of SIEM, XDR, TIP, sandbox analysis, and XDR, all part of its MDR service.

Detections Tests: why are we still dealing with hundreds of alerts?

There were two detection tests emulating Scattered Spider and Mustang Panda. Both leveraged an array of LOLBins, tool downloads, and many different devices across the network. Within the detections tests, they included the Reconnaissance tactic to expand the detection window, specifically phishing, which is new for this round.

Importantly, there’s a clear distinction between the vendors that provided multiple alerts and those that provided very few alerts, correlated with all context. Vendors like CrowdStrike, Cybereason, and ESET only generated a handful of detections for each scenario. Those that provided very few were not necessarily seeing less – instead, as is a theme across the industry, vendors are more effectively consolidating related alerts into single cases instead of inundating users with a disparate barrage of alerts. Others, like Sophos and Trend Micro, generated hundreds of alerts. Some of those may be suppressed in the console, as many fall into the medium or low categories. Even still, the market is moving towards the consolidation of alerts into cases and all vendors in this evaluation should be also.

Protections Tests

There were seven tests, one for each stage: credential theft, identity providers, unmanaged to managed devices, initial access malware execution, malware execution and lateral movement, false positives, and AWS compromise.

The goal of the protection tests wasn’t just to show a “stopping of the threat,” but to measure the impact; was the attack stopped before the threat actor had a chance to gain persistence or steal credentials? This shows the importance of not only detecting an attack in progress but stopping it before it exposes the environment.

The MITRE ATT&CK team also included a protection test that incorporated false positives. In this test, every single activity that took place was considered non malicious and was supposed to be reported on as such. If the vendor blocked a particular action, it was a false positive. Ideally, zero security alerts should be generated off that test. Of all the vendors, Cybereason, Cynet, and Sophos all blocked activity during that test, which were false positives.

Test 2, which focused on an adversary manipulating IdP trust relationships was dropped due to difficulty distinguishing legitimate administrative activities from malicious actions. This is why you’ll see no responses for that test if you’re looking at results.

The Need For Third-Party Testing

Given the many market conversations and the lower-than-average turnout in this round of testing, it’s worth addressing the future of third-party testing like this and its impact on the security community. Many practitioners Forrester speaks with struggle to interpret and understand the results of these evaluations, and for good reason: there’s a lot of data, and the MITRE ATT&CK team hasn’t made a judgment call on which outcomes signal better performance. Even still, tests like these are important – especially when they are given room to evolve.

MITRE ATT&CK made many changes in this round for the better: incorporating cloud, building a more realistic environment to test in, continuing to incorporate noise/false positive tests, and expanding coverage to reconnaissance. Forrester still sees a lot of value in these tests. While every practitioner may not have the time or resources to dig through the data, the testing is still important to push the detection and response vendors forward. The evaluation offers a critical lens into where visibility and prevention fall short – and where they each perform most effectively.

If you’re a Forrester client, book an inquiry or guidance session with either of us if you have questions about the results.



Source link

Tags: ATTCKcoverageEvaluationsMITREnuancereturn
ShareTweetShare
Previous Post

Palantir Stock: Software Maker Wins U.S. Navy Contract For Nuclear Submarine Fleet

Next Post

Home sales in Israel continue to slump

Related Posts

Top takeaways for digital workplace leaders

Top takeaways for digital workplace leaders

by FeeOnlyNews.com
January 22, 2026
0

I kicked off 2026 by attending CES for the first time, and I can confirm everything you’ve heard about this...

Michael Burry, Cathie Wood Are Betting Big on These Undervalued Names

Michael Burry, Cathie Wood Are Betting Big on These Undervalued Names

by FeeOnlyNews.com
January 22, 2026
0

As markets continue to rotate away from crowded themes, several well-known investors are taking sharply different paths in how they...

8 Undervalued Tech Stocks That Could Rip Higher After Q4 Results

8 Undervalued Tech Stocks That Could Rip Higher After Q4 Results

by FeeOnlyNews.com
January 22, 2026
0

The US President Donald Trump helped calm markets on Wednesday by announcing a framework agreement on Greenland and dropping the...

Trends, Regional Analysis, & Opportunities

Trends, Regional Analysis, & Opportunities

by FeeOnlyNews.com
January 22, 2026
0

The global Low-Carbon Aluminum Market is gaining momentum as industries prioritize sustainability and decarbonization. Driven by regulatory pressure and demand...

The State Of Business Buying, 2026

The State Of Business Buying, 2026

by FeeOnlyNews.com
January 21, 2026
0

As economic and geopolitical volatility continues to ripple through global markets, business buyers are feeling the strain. Elevated interest rates,...

distributor rebate program

distributor rebate program

by FeeOnlyNews.com
January 21, 2026
0

Computer Market Research (CMR): The Ultimate Channel Management Compendium PART 1 Table of Contents for Part 1 Introduction to Channel...

Next Post
Home sales in Israel continue to slump

Home sales in Israel continue to slump

New York Retirees Are Seeing Big Changes to Senior Housing Waitlists

New York Retirees Are Seeing Big Changes to Senior Housing Waitlists

  • Trending
  • Comments
  • Latest
Student Beans made him a millionaire, a heart condition made this millennial founder rethink life

Student Beans made him a millionaire, a heart condition made this millennial founder rethink life

December 11, 2025
Episode 242. “Our couples therapist couldn’t fix this. Please help.”

Episode 242. “Our couples therapist couldn’t fix this. Please help.”

January 6, 2026
Want to Retire Comfortably Without Cutting Fun? Here’s the Trick Few People Use

Want to Retire Comfortably Without Cutting Fun? Here’s the Trick Few People Use

November 1, 2025
Raymond James swoops in on Merrill team

Raymond James swoops in on Merrill team

January 16, 2026
Costco Will Give You Free Groceries for Your Old Electronics

Costco Will Give You Free Groceries for Your Old Electronics

January 18, 2026
The Mattering Instinct (with Rebecca Newberger Goldstein)

The Mattering Instinct (with Rebecca Newberger Goldstein)

January 12, 2026
Realty weakness overdone, midcap correction throws up long-term opportunities: Sandip Sabharwal

Realty weakness overdone, midcap correction throws up long-term opportunities: Sandip Sabharwal

0
8 Steps to Day Trade Like a Pro

8 Steps to Day Trade Like a Pro

0
U.S. oil producers ‘slighted’ by Trump’s international focus on crude in Venezuela and Greenland

U.S. oil producers ‘slighted’ by Trump’s international focus on crude in Venezuela and Greenland

0
Trump withdraws ‘Board of Peace’ invitation to Carney in widening rift with Canada

Trump withdraws ‘Board of Peace’ invitation to Carney in widening rift with Canada

0
Top White Label Crypto Exchange Providers of 2026

Top White Label Crypto Exchange Providers of 2026

0
25 Associate Degree Jobs That Pay Well — and 10 Companies Hiring

25 Associate Degree Jobs That Pay Well — and 10 Companies Hiring

0
U.S. oil producers ‘slighted’ by Trump’s international focus on crude in Venezuela and Greenland

U.S. oil producers ‘slighted’ by Trump’s international focus on crude in Venezuela and Greenland

January 23, 2026
Realty weakness overdone, midcap correction throws up long-term opportunities: Sandip Sabharwal

Realty weakness overdone, midcap correction throws up long-term opportunities: Sandip Sabharwal

January 23, 2026
Bitwise Says Crypto Has Likely Bottomed, Echoing Q1 2023 Setup

Bitwise Says Crypto Has Likely Bottomed, Echoing Q1 2023 Setup

January 23, 2026
Insurance reforms could unlock vast growth opportunity: Dinesh Kumar Khara

Insurance reforms could unlock vast growth opportunity: Dinesh Kumar Khara

January 23, 2026
Trump withdraws ‘Board of Peace’ invitation to Carney in widening rift with Canada

Trump withdraws ‘Board of Peace’ invitation to Carney in widening rift with Canada

January 23, 2026
If you’ve ever felt invisible because you don’t fit beauty standards, you possess these 8 qualities that shallow people completely miss

If you’ve ever felt invisible because you don’t fit beauty standards, you possess these 8 qualities that shallow people completely miss

January 22, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • U.S. oil producers ‘slighted’ by Trump’s international focus on crude in Venezuela and Greenland
  • Realty weakness overdone, midcap correction throws up long-term opportunities: Sandip Sabharwal
  • Bitwise Says Crypto Has Likely Bottomed, Echoing Q1 2023 Setup
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.