No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Tuesday, May 12, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

MITRE ATT&CK Evaluations Return: More Coverage, More Nuance

by TheAdviserMagazine
5 months ago
in Market Analysis
Reading Time: 4 mins read
A A
MITRE ATT&CK Evaluations Return: More Coverage, More Nuance
Share on FacebookShare on TwitterShare on LInkedIn


MITRE released a new round of MITRE ATT&CK enterprise evaluations today. This round had a lot of big changes — first off, only 11 vendors participated, which is a drop off from the 19 that participated in 2024. Some of the most notable missing vendors include SentinelOne, Microsoft, and Palo Alto Networks. Overall, it seems like some vendors prioritized their own internal product efforts over the evaluation, likely due to investment in other areas, market and economic dynamics, and changes in the landscape.

Forrester strongly believes in the power of unbiased, third-party evaluations, especially of security products. Security products can sometimes be a black box. Evaluations like these, especially when the data is shared, make capabilities a little less opaque.

Round Seven: Breaking New Ground

This round emulated Scattered Spider, a financially motivated cybercriminal collective, and Mustang Panda, a PRC-based espionage group.

The MITRE ATT&CK team made big changes to the infrastructure in the evaluation to make it closely resemble a real-world scenario. The environment had more endpoints and subnets, which were built out into a realistic and complex network topology. Much like last round, when it introduced expanded coverage with macOS, this year, it expanded coverage to the cloud in addition to Windows and Linux devices.

The evaluations also expanded the scope to additional telemetry sources like identity, email, and cloud. For example, some of the emulations included identity compromise through single sign-on and multifactor authentication as well as the abuse of cloud services.

MITRE included unmanaged devices in the evaluation, which demonstrated a blind spot for many providers. Unmanaged devices emulate real-world environments where organizations have bring-your-own devices without managed agents, third-party contractors accessing on-premises or remotely, or test networks where endpoints won’t run standard protections.

A nuance worth noting is that the vendor tools used in this round are disparate. In past years, most vendors tested their EDR tool, but in this round, there were a variety of modules used together. For example, Trend Micro used modules from its Vision One platform, including endpoint security, network security, cloud security, and exposure management. WithSecure used its EPP, XDR, and exposure management capabilities. Cyberani used a combination of SIEM, XDR, TIP, sandbox analysis, and XDR — all part of its MDR service.

Detection Tests: Why Are We Still Dealing With Hundreds Of Alerts?

There were two detection tests that emulated Scattered Spider and Mustang Panda. Both leveraged an array of LOLBins, tool downloads, and many different devices across the network. Within the detections tests, MITRE included the reconnaissance tactic to expand the detection window, specifically phishing, which is new for this round.

Importantly, there’s a clear distinction between the vendors that provided multiple alerts and those that provided very few alerts, correlated with all context. Vendors like CrowdStrike, Cybereason, and ESET only generated a handful of detections for each scenario. Those that provided very few were not necessarily seeing less — instead, as is a theme across the industry, vendors are more effectively consolidating related alerts into single cases instead of inundating users with a disparate barrage of alerts. Others, such as Sophos and Trend Micro, generated hundreds of alerts. Some of those may be suppressed in the console, as many fall into the medium or low categories. Even still, the market is moving toward the consolidation of alerts into cases, and all vendors in this evaluation should be, as well.

Protection Tests

There were seven protection tests, one for each stage: credential theft, identity providers, unmanaged to managed devices, initial access malware execution, malware execution and lateral movement, false positives, and AWS compromise.

The goal of the protection tests wasn’t just to show an instance of “stopping of the threat” but to measure its impact. Was the attack stopped before the threat actor had a chance to gain persistence or steal credentials? This shows the importance of not only detecting an attack in progress but stopping it before it exposes the environment.

The MITRE ATT&CK team also included a protection test that incorporated false positives. In this test, every single activity that took place was considered non-malicious and was supposed to be reported on as such. If the vendor blocked a particular action, it was a false positive. Ideally, zero security alerts should be generated off that test. Of all the vendors, Cybereason, Cynet, and Sophos all blocked activity during that test, which were false positives.

Test two, which focused on an adversary manipulating IdP trust relationships, was dropped due to difficulty distinguishing legitimate administrative activities from malicious actions. This is why you’ll see no responses for that test if you’re looking at the results.

The Need For Third-Party Testing

Given the many market conversations and lower-than-average turnout in this round of testing, it’s worth addressing the future of third-party testing like this and its impact on the security community. Many practitioners Forrester speaks with struggle to interpret and understand the results of these evaluations, and for good reason: There’s a lot of data, and the MITRE ATT&CK team hasn’t made a judgment call on which outcomes signal better performance. Even still, tests like these are important — especially when they are given room to evolve.

MITRE ATT&CK made many changes in this round for the better: incorporating cloud, building a more realistic environment, continuing to incorporate noise/false positive tests, and expanding coverage to reconnaissance. Although not every practitioner will have the time or resources to dig through the data, the testing is still important to push the detection and response vendors forward. The evaluation offers a critical lens into where visibility and prevention fall short — and where vendors each perform most effectively.

If you’re a Forrester client, book an inquiry or guidance session with either of us if you have questions about the results.



Source link

Tags: ATTCKcoverageEvaluationsMITREnuancereturn
ShareTweetShare
Previous Post

Nationwide Banking Glitches Are Delaying Some Seniors’ Deposits

Next Post

7 Prescription Assistance Programs Opening Up After New Year’s

Related Posts

edit post
How To Build A Premium Airline In The Sky Of Sameness

How To Build A Premium Airline In The Sky Of Sameness

by TheAdviserMagazine
May 11, 2026
0

Budget Is Dead. Long Live Premium? The demise of Spirit Airlines has provided endless fodder for late-night comedy that pokes...

edit post
US Dollar Coils in a Tight Range as Markets Watch CPI, Fed Signals This Week

US Dollar Coils in a Tight Range as Markets Watch CPI, Fed Signals This Week

by TheAdviserMagazine
May 11, 2026
0

Rising Middle East tensions and continue supporting safe-haven demand for the US dollar. Inflation, Fed leadership changes, and retail sales...

edit post
US Dollar Jumps on Iran Headlines as Oil Rebound Faces Resistance

US Dollar Jumps on Iran Headlines as Oil Rebound Faces Resistance

by TheAdviserMagazine
May 11, 2026
0

Good morning everyone, I hope you had a wonderful weekend.As you know, in the last 24 hours Trump received a...

edit post
APAC Algae Biofuel Market Analysis and Emerging Opportunities

APAC Algae Biofuel Market Analysis and Emerging Opportunities

by TheAdviserMagazine
May 11, 2026
0

The Asia-Pacific algae biofuel market is gaining momentum as countries across the region focus on reducing carbon emissions and expanding...

edit post
Outsourcing Channel Data Processing: The Strategic Guide for Manufacturers in 2026

Outsourcing Channel Data Processing: The Strategic Guide for Manufacturers in 2026

by TheAdviserMagazine
May 10, 2026
0

The $1 trillion global outsourcing market in 2026 isn’t being driven by simple cost-cutting. It’s fueled by a need for...

edit post
1 Stock to Buy, 1 Stock to Sell This Week: Applied Materials, Alibaba

1 Stock to Buy, 1 Stock to Sell This Week: Applied Materials, Alibaba

by TheAdviserMagazine
May 10, 2026
0

U.S. inflation data, retail sales, U.S.-Iran developments and the Trump-Xi summit could dominate the coming week. Applied Materials stands out...

Next Post
edit post
7 Prescription Assistance Programs Opening Up After New Year’s

7 Prescription Assistance Programs Opening Up After New Year’s

edit post
Home sales in Israel continue to slump

Home sales in Israel continue to slump

  • Trending
  • Comments
  • Latest
edit post
Gavin Newsom issues ‘final warning’ amid California’s dire housing crisis — what’s at stake for millions of residents

Gavin Newsom issues ‘final warning’ amid California’s dire housing crisis — what’s at stake for millions of residents

May 3, 2026
edit post
Florida Warning: With Senior SNAP Benefits Averaging 8/Month, Thousands Risk Losing Assistance in 2026

Florida Warning: With Senior SNAP Benefits Averaging $188/Month, Thousands Risk Losing Assistance in 2026

April 27, 2026
edit post
Minnesota Wealth Tax | Intangible Personal Property Tax

Minnesota Wealth Tax | Intangible Personal Property Tax

May 6, 2026
edit post
10 Cheapest High Dividend Stocks With P/E Ratios Under 10

10 Cheapest High Dividend Stocks With P/E Ratios Under 10

April 13, 2026
edit post
Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

April 29, 2026
edit post
NYC Mayor Mamdani knocked Ken Griffin in pied-a-terre tax promo. His firm calls the move ‘shameful’

NYC Mayor Mamdani knocked Ken Griffin in pied-a-terre tax promo. His firm calls the move ‘shameful’

April 23, 2026
edit post
Clarity Act: US Senate Banking Committee Releases Draft Crypto Market Structure Bill

Clarity Act: US Senate Banking Committee Releases Draft Crypto Market Structure Bill

0
edit post
Exagen reaffirms M-M 2026 revenue guidance as it targets 0-0 ASP over time (NASDAQ:XGN)

Exagen reaffirms $70M-$73M 2026 revenue guidance as it targets $600-$650 ASP over time (NASDAQ:XGN)

0
edit post
How To Build A Premium Airline In The Sky Of Sameness

How To Build A Premium Airline In The Sky Of Sameness

0
edit post
NASAA asks states to eliminate conflicts with SEC’s new marketing rule

NASAA asks states to eliminate conflicts with SEC’s new marketing rule

0
edit post
After taking 0 deposits, Trump Mobile changes its terms to say the Trump phone may never be made

After taking $100 deposits, Trump Mobile changes its terms to say the Trump phone may never be made

0
edit post
Certara Falls Short on Q1 2026: alt=

Certara Falls Short on Q1 2026: $0.09 EPS vs $0.11 Expected

0
edit post
Clarity Act: US Senate Banking Committee Releases Draft Crypto Market Structure Bill

Clarity Act: US Senate Banking Committee Releases Draft Crypto Market Structure Bill

May 12, 2026
edit post
Exagen reaffirms M-M 2026 revenue guidance as it targets 0-0 ASP over time (NASDAQ:XGN)

Exagen reaffirms $70M-$73M 2026 revenue guidance as it targets $600-$650 ASP over time (NASDAQ:XGN)

May 12, 2026
edit post
Conversations with Frank Fabozzi, CFA, Featuring Sue Brake

Conversations with Frank Fabozzi, CFA, Featuring Sue Brake

May 11, 2026
edit post
Global Market Today: Asian stocks advance, oil gains on Iran deadlock

Global Market Today: Asian stocks advance, oil gains on Iran deadlock

May 11, 2026
edit post
Navy plans to buy 15 costly Trump-class battleships by 2055

Navy plans to buy 15 costly Trump-class battleships by 2055

May 11, 2026
edit post
Michigan Auto Insurance Change: Why Personal Injury Coverage Adjustments Are Raising Premiums This Month

Michigan Auto Insurance Change: Why Personal Injury Coverage Adjustments Are Raising Premiums This Month

May 11, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Clarity Act: US Senate Banking Committee Releases Draft Crypto Market Structure Bill
  • Exagen reaffirms $70M-$73M 2026 revenue guidance as it targets $600-$650 ASP over time (NASDAQ:XGN)
  • Conversations with Frank Fabozzi, CFA, Featuring Sue Brake
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.