
The Azure Security Podcast · 2026-02-27 · 35 min
Key moments - from our scoring
Substance score
64 / 100
Five dimensions, 20 points each
Blake Strom brings firsthand knowledge of ATT&CK's creation as an answer to the limitations of indicator-based defense. Rather than tracking IOCs (malware hashes, IPs, domains), MITRE's Fort Meade Experiment sought to detect and catalog actual adversary behaviors through red team operations against a live corporate network. The resulting framework organizes attacker TTPs into tactics (reconnaissance, initial access, persistence, etc.) with increasingly specific techniques and sub-techniques, grounded in observed real-world activity rather than theoretical vulnerabilities. Strom explains why sub-techniques were essential for managing framework scope, details the controversial ATT&CK evaluations program that ranks EDR vendors, and candidly discusses where the framework could have evolved differently. For security leaders deciding whether and how to operationalize ATT&CK, this episode clarifies the distinction between attacker-centric frameworks and traditional vulnerability databases like CVE, and why that mindset shift matters for defense prioritization.
ATT&CK is a knowledge base of adversary tactics, techniques, and procedures grounded in observed real-world attacker behavior. It organizes into tactics (the purpose of actions like reconnaissance or exfiltration), techniques (medium-level methods), and sub-techniques (specific implementation details), with procedure examples from real threat actors, detection methods, and mitigation strategies for each entry.
ATT&CK began as the Fort Meade Experiment around 2010-2011 when MITRE realized that IOC-based defense was insufficient. They conducted red team operations against a live corporate network to identify and catalog recurring adversary behaviors and patterns rather than one-off indicators, then published the framework publicly in May 2015 after internal reviews.
MITRE's legal team requested the stylization (ATT&CK instead of ATTACK) because they believed it would be easier to trademark and help identify legitimate uses of the framework, which proved beneficial for tracking adoption and detecting unauthorized reproductions.
CVE and CWE catalog what is theoretically possible (vulnerabilities and weaknesses), while ATT&CK focuses specifically on what adversaries actually do and have been observed doing, which better reflects real-world threat prioritization.
Strom wishes sub-techniques had been implemented earlier rather than late in the framework's evolution, as the original technique layer became unwieldy and difficult for practitioners to navigate as the framework scaled to hundreds of entries.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode provides solid contextual information about ATT&CK's origins and philosophy, but much of it is historical narrative rather than immediately actionable insights. Blake explains the Fort Meade experiment, the shift from IOCs to TTPs, and the evolution of the framework, but there are few novel operational takeaways for a practicing security professional beyond 'use ATT&CK as a process, not a checklist.' The content is informative but not densely packed with non-obvious claims.
ATT&CK is basically a knowledge base of cyber threat actor TTPs... there's a big difference between what can be done and what is actually done... that makes a really big difference when you talk about how to prioritize defenses
I think the biggest misconception of attack is that it's like a checkbox... it's more about the process of getting your network and up to a point where you can defend against these attacks and then continuing to evolve it
Blake covers ATT&CK's origin story with genuine historical detail (Fort Meade experiment, the shift from IOCs to TTPs, working with red teams internally), which is somewhat fresh perspective. However, the core framework thinking - that defenders should understand attacker methods and tactics rather than just chase indicators - is not a new or contrarian insight anymore. The discussion of 'attackers think in graphs, defenders think in lists' is attributed to John Lambert and reflects existing industry thinking rather than Blake's original contribution.
there is quite a purpose behind how it was developed... attackers will always find a way in... the typical process of discovering iocs wasn't really working
the attacker mindset that it was centered around... the fact that we were focused on was this actually observes attacker activity
Blake Strom is highly credible: he spent 7 years at MITRE building ATT&CK from inception, worked at the NSA for 3 years in cyber threat intel and operations, and is now leading XDR/SIEM R&D at Microsoft. He's a practitioner-researcher who has actually built and shaped major industry infrastructure, not a career podcast guest. His firsthand experience architecting ATT&CK from the Fort Meade experiment forward makes him directly relevant to the topic.
I was at MITRE for about seven years... Started the ATT&CK project
before I came to Microsoft, though, I was at MITRE for about seven years... my background before MITRE was actually at the National Security Agency
The episode provides specific historical details (Fort Meade experiment, May 2015 publication date, 64 initial techniques, McAfee HVSS mentioned) and names real people (Adam Pennington as successor, Todd Whitbold as mentor), but it lacks concrete examples of how to apply ATT&CK. There are no case studies showing specific organizations using it, no metrics on adoption, and no detailed walkthroughs of actual defensive implementations. The discussion remains at a conceptual level rather than providing numbered examples or measurable outcomes.
I think it was May 2015 is when we first published it
from its earliest state, which was I think 64 techniques to a point where it was, across multiple platforms and had hundreds of techniques
The hosts ask reasonable foundational questions (what is ATT&CK, how did it come about, how should it be used) but mostly allow Blake to deliver prepared narratives rather than pushing back or drilling into nuance. There's little productive disagreement or challenging of assumptions. Mark's observation about 'attackers vs defenders mindset' is good, but the hosts don't follow up to explore its operational implications deeply. The conversation is friendly but somewhat surface-level, missing opportunities to press on the ATT&CK evaluations critique or the real-world gaps Blake hints at.
Can you kind of baseline us on what is MITRE ATT&CK and kind of how did it come about... just tell us the story of how this thing came to be
How do you move on to do something else? Because a long time ago, I was like the PKI guy
Computed from the transcript - who did the talking, and the words that came up most.
In this episode Michael and Mark talk with guest Blake Strom about the origins of the MITRE ATT&CK framework, how it was developed, and how it has evolved over time. We also discuss how the framework is used in the industry and its impact on cybersecurity. We also discuss Azure Security news about Azure Monitor, Azure Application Gateway, AKS, Azure Front Door, AMD v6 Confidential VMs, and xxx
Transcribed and scored by The B2B Podcast Index.
Welcome to the Azure Security Podcast, where we discuss topics relating to security, privacy, reliability, and compliance on the Microsoft Cloud Platform. Hey everybody, welcome to episode 125. This week it's myself, Michael, and Mark. And our guest this week is Blake Strom, who's here to talk to us about MITRE ATT &CK.
But before we get to our guest, why don't we take a little lap around the news. Mark, why don't you kick things off? A couple of different things I wanted to highlight. I've been working on this data security diagram to add to the Microsoft Cybersecurity Reference Architecture, or MCRA.
And so I shared that out with the LinkedIn kind of socials world. So I'd love to get feedback on it, get your thoughts on it. And if it looks good or, hey, you forgot this or you didn't think about that, I'd love to get feedback on that. So that'll be going out in the next release, which does not have a date yet, but we'll leave it at soon.
Now, there are a couple of things that sort of caught my eye is there was a great thing. It's like an eight or nine minute video on zero trust on Microsoft Mechanics. And it did a really good job, especially by Michael Magical. And it did a really good job of hovering sort of here's the theoretical concept, the architectural in a nice, quick, concise way.
And then here's some technology and some demos. And here's how it actually becomes real. and kind of showing how that sort of concept of zero trust applies effectively to the new world of agents and AI and all that kind of stuff. So it's a really nice one to check out while worth it.
And I also did an AI security talk, I don't know, sometime around a month or so ago, give or take. And so I released the slides for that. So I will pop a link in the news for that one so you can take advantage of that and sort of the way I'm thinking about that from an architecture strategy perspective. And I will be doing a fun talk in the not too distant future, besides in Tampa, on security as a team sport.
But we're not playing like a team. So you can have a little bit of fun with that. Talk about roles, responsibilities, accountabilities, and some stuff for people to kind of manage their careers effectively and get more done as a team. So that's what I got.
Back to you, Michael. All right, I've got a few items. First one for Azure Kubernetes Service, AKS, for node auto -provisioning now allows support for encryption host and disk encryption sets. I didn't even know that it didn't do this, but apparently it didn't do it, but now it does.
Again, I do wish Sarah was here because this is her baby, AKS, but anyway, I'm covering it today. So yeah, so node auto -provisioning now supports encryption at host and disk encryption sets, and that is generally available. Next one in public preview, Azure Front Door Premium now supports Azure Private Link Origins in UAE North. So I want to spend just a couple of seconds on Azure Front Door.
At Microsoft, we've been adding more front door support. in front of many services that you know and love within Azure to provide a very strong level of defense in front of these various services. If you have an application of your own that's at global scale, it's really worthwhile seriously considering Azure Front Door as literally the front door to your application because it provides so much benefit at a global scale. So that's in public preview, Azure Front Door Premium, and Azure Private Link in UAE North.
Generally available, there is now support for AMD version 6 confidential VMs in more regions. I'm not going to rattle them all off, but a couple that come to mind are Canada Central, Norway East, France South, Australia East, and a few more. There will be more coming on stream as well, but this is great to see. Huge fan of confidential VMs, so it's great to see more coverage.
Next, we have generally available the default rule set 2 .2 in WAF for Azure Application Gateway. This is basically just an incremental improvement. It uses the OWASP core rule set 3 .
3 .4 and allows protection from things like SQL injection, cross -site scripting, and so on and so forth. This actually... Again, it's just really a fine tuning of the current rule set.
And it ships by default to what's called paranoia level number one, just to help reduce the chance that legitimate traffic is actually blocked. So look at that. It's good to see, nice to see just small improvements being made. Even small improvements can make a big difference over time.
Still on the topic of WAF, Web Application Firewall, there's now Azure Application Gateway WAF Insights. This is now in preview. Essentially, it's just a better pane of glass looking at what is going on in the WAF when you're using it with Azure Application Gateway. And the last one is we now have in public preview some new security capabilities in Azure Monitor Pipeline.
Most notably, and this is the one that I really sort of piqued my interest, was secure ingestion with TLS and mutual TLS. This is so important. It's incredibly important that you always authenticate both ends of a communication, whether that's a user, whether it's a process, whatever. It's so important that you actually authenticate both ends.
So with mutual TLS, you're not just authenticating the server because normally TLS is used to do server authentication. But a lot of people don't realize that TLS can also do client authentication as well. And that's often referred to as mutual TLS. So now secure ingestion with Azure Monitor Pipelines now supports mutual TLS.
So good to see. Great little roundup of sort of, you know, a big smattering of security improvements across the board. Always a good thing to see. All right.
Now that we have the news out of the way, let's turn our attention to our guest. As I mentioned at the top, our guest this week is Blake Strom, who's here to talk to us about MITRE ATT &CK. Blake, welcome to the podcast. Would you like to take a moment and introduce yourself to our listeners?
Yeah, thanks for having me. So I'm Blake Strom. I've been at Microsoft for almost six years now, mostly working in the XDR and SIEM cybersecurity research and development space, so building new capabilities and getting them to customers. So before I came to Microsoft, though, I was at MITRE for about seven years.
Started the ATT &CK project, was working in a bunch of different areas related to ATT &CK at MITRE. And then my background before MITRE was actually at the National Security Agency. So I was there for about three years in cyber threat intel and defensive operations. To go into a little bit more detail, since a lot of people may not know.
what MITRE is. So it's a nonprofit that was established back in 1958. So MITRE has been around for a very long time. But it's basically an organization that manages several federally funded research and development centers on behalf of the federal government.
So these are entities that are set up for various reasons around the defensive sector. Homeland Security, several different other areas to basically focus research and developments in sort of an unbiased way that sort of a nonprofit is best suited for. So a lot of people recognize them, at least in the cybersecurity space, for CVE, Common Vulnerabilities and Exposures, CWE, Around Weaknesses, Enumeration, Sticks and Taxi. But they do a whole lot more actual developments and research on behalf of the governments.
even to source selections of contracts across the defense industrial base. So they have quite a wide and expansive array of work that they do and capabilities across the federal government. So let's start with the basics because we've got a lot of listeners on our podcast, everyone from CISOs with lots of scars to people that are just entering the industry and trying to figure things out. Can you kind of baseline us on what is MITRE ATT &CK and kind of how did it come about?
What was it intended for, if it was intended for anything? And just tell us the story of how this thing came to be and how it's evolved. Yeah, so ATT &CK as it is today is basically a knowledge base of cyber threat actor TTPs. And it's mostly focused on what...
actors have actually been observed doing. So there's a big difference between what can be done and what is actually done. And I think that makes a really big difference when you talk about how to prioritize defenses against certain threats. Because you can go look at CVE or CWE and see a whole sort of enumeration of things that are possible, but they may not be things that attackers are actually using day to day.
And a TTP is a tactic, technique, or procedure, correct? Correct. Yeah, attack techniques and procedures. And so the background of ATT &CK is kind of an interesting and long story.
So there is quite a purpose behind how it was developed. So back in, I think it was 2010, 2011, MITRE had started a research program under the premise that attackers will always find a way in. and so the the typical uh process of discovering iocs like malwares ips domains wasn't really working um and mitre being part of the defense industrial base working on behalf of the government of course they often get targeted by you know advanced threat actors and very persistent threats so they have sort of a vested interest in protecting themselves but also given mitre's charter to work in the public interest on behalf of the government, they also took this as an opportunity to figure out, okay, so what else can we do beyond IOCs to defend ourselves and defend the customers?
Yeah, and IOCs being indicators of compromise, right? Right, yep. Yeah, so in the red team, you talked about TTPs. So TTPs, whenever we're doing a readout of an operation that the red team has performed, we always enumerate.
the TTPs, like what things we actually did to actually go along the breach path until we got to our final objective. And a big part of what I do is learning from those TTPs, like how did that particular TTP eventuate, like how did it happen? And more importantly, what can we do moving forward to reduce the chance that that particular TTP will be used? So this project was called FMX.
It was called the Fort Meade experiment because of the MITRE location that it was being conducted in. But basically, they were trying to figure out ways of sensing an internal network to discover the behaviors of the actors rather than the IOCs that were being left behind. And this is sort of at the very early days of the evolution of EDR and sort of like process monitoring and behavioral monitoring on networks. So things like Sysmon had not been developed yet.
Companies like CrowdStrike were still in their infancy. And so there was a lot of internal developments of tools. So very Sysmon -like tool was developed to do process monitoring. We tried to use the most common host -based security systems at the time that were being used by our government sponsors.
Was there something more that we can do and inform them to do with these systems? I think it was McAfee HVSS at the time. So we sensed this, or they set up this network to do the sensing and decided to do red team operations using some of the skills for the red team operators that were at the site from MITRE. So in a way it was like...
trying to shift from, hey, we've got footprints of the last attack, look for guys with these footprints, which is kind of what an IOC is, to let's figure out their methods and the things that they do, their patterns over and over again kind of thing. Right. Yeah, that's a really good way to look at how the industry was starting to evolve at the time. And so I had actually joined MITRE at the beginning of 2012.
So this project had already started. And they had already done one sort of red team test where the red team sort of came up with their own plan, operated within this network, which was the actual MITRE environment. It was a live corporate network that we were allowed to operate in to sort of test the research hypothesis and ideas. And the blue team sort of came in and tried to discover the actions.
And my first sort of assignment when I joined MITRE was, okay, try to figure out how to connect these two things together, like what the red team did and what the blue team found. And that was a very interesting process because one of the first things that I discovered was, hey, the red team isn't really using TTPs that are similar to known actors. And so that was, you know, in the reports, the very first version of this report was, you know, very device centric, trying to figure out exactly the right way to talk about what the right team did in sequence and how to relate that to the Splunk analytics and data that was being discovered by the blue team.
It's fascinating to hear you say that because I've seen the same thing of like, it's such a different thought process of, you know, attacker and a red team side. versus the defenders frequently. And I know John Lambert has a famous quote around attackers think in graphs and defenders think in lists, right? And there's just so many other different elements to it of just that thought process of it's just a different set of objectives, right?
As a defender, because there's a complexity in architecture and this and that, it often gets boiled down to just a checklist of compliance. And on the attacker side, it's just get the job done. Yeah, exactly. And it's really hard to bridge those two different mindsets.
So I have two questions. The first question is, can you give us an overview of what actually is in MITRE ATT &CK? Like how it's broken up, what sort of data is in there? And the second one, which is really just the follow on, is if I was, you know, Jane or John security person in an organization, I mean, how would I use MITRE ATT &CK?
yeah yeah so at the top level um when you go to the attack website you'll see basically what's considered the the attack matrix and so that's the organization of tactics which are Basically, the purpose of an adversary sort of conducting a technique, so that spans reconnaissance, initial access, persistence, defense evasion, credential access, and it goes all the way to impact or exfiltration. And in each row within those tactics are the various techniques. And those tend to be high level or sort of medium term buckets for how to organize the sub techniques.
And so those are very specific ways that an actor would perform a technique to accomplish a tactic. And so what this provides is basically a common language or lingua franca between what an attacker would do, why they would do it. And then when you drill into the technique or sub technique level, the very detailed information on. how they're doing it, down to the specific platforms that they would use these techniques against, what procedure examples for real threat actors that have done this and have been reported out in the wild, and then any mitigation or detection strategies that one could imply to actually employ to do some sort of detection or mitigation against those techniques.
So you had this internal research, and then it became... a essentially not quite a standard, but kind of a, just a de facto standard that everyone refers to and uses. Yeah. I'd love to hear like, you know, how that journey kind of went.
Was it something that was just like an instant hit? Was it something that y 'all had to promote? I'm just kind of curious, you know, about that journey and, and, and how that, how that went. Yeah.
So like many things, when they first get started, there's a lot of internal convincing. that this is something new and useful. So there was quite a bit of that in the early days within MITRE as we started to socialize it a bit. So a lot of people would sort of come out of the woodwork and say like, okay, this is already done in CWE.
This is already sort of done in CVE. So we had to get really good about the story as to why we were doing these things. Really the big differentiator was sort of the attacker mindset that it was centered around. And the fact that we were focused on was this actually observes attacker activity.
And so as it grew internally over time, as we were using ATT &CK for these red and blue team evaluations internally, I think it finally dawned on some of the research leaders and, of course, the CISO at the time within MITRE that this was something that was actually kind of unique and special and very much in line with what MITRE's mission was. So much so that it was something that they wanted to share with the world, basically, because it was so useful for us internally to test and evaluate our internal defenses that it didn't make sense to sort of keep this in -house.
And so that started off the process of basically the internal reviews that had to happen, the pre -publication reviews that had to happen with sponsors, and then finally publishing it about two or three years after. We had started ATT &CK internally, and I think it was May 2015 is when we first published it. Wow, it's only been 10 years. It's funny, like you get used to something and it just feels like it's been around forever.
It's interesting because it's one of the few frameworks that directly addresses the attacker side, the red team side of the equation. So always been a big fan of that and kind of like, you know, we need to explore and define that space a lot better than we have. Love it. So this is just kind of like a curiosity question because like, you know, Michael and I have both, you know, are both history buffs and like love these origin story kind of things.
I'm curious, like, is there anything that you kind of wish you did differently? Are you happy the way it works? Or is there some stuff that didn't, you know, land like the way you expected or thought it might? I'm just kind of curious on that one.
And of course, you know, hindsight's 20 -20 and you always see things that you never saw in the moment. So I'm just, you know, more of a curiosity thing. Yeah, that's a good one. So I think one of the, you always have to start somewhere and there's never going to be a perfect solution right out of the gate.
But I think one of the things that I feel like we should have done much earlier was to implement the sub technique concept because there was, as attack had evolved from its earliest state, which was I think 64 techniques to a point where it was, across multiple platforms and had hundreds of techniques. It became very difficult for somebody to figure out even where to start with it just because it was so big. So the sub -technique layer added a necessary sort of like evenness across how we would define things at a technique and sub -technique level that was missing.
There's either too much detail or not enough detail in a lot of spaces. So I think that was the piece that was sorely needed for a long time. that we managed to implement right before I left MITRE. And that was one of the things I know we'll probably get to more of these questions, more of this type of question, maybe a little bit later, but that was one of the things that I absolutely had to do before I left was to get ATT &CK in a more stable state.
You feel like an accountability to your baby. Yeah. Yes. Yeah, of course.
I know that feeling well. I have a really stupid question. I have a really stupid question. It's talking about origins.
Why is the second letter A in the word attack not a letter A? Why is it an N symbol? Oh my gosh. This always goes back to lawyers.
That was a stylization. that was done basically because MITRE didn't want to try to copyright ATT &CK with the letter A in it just for reasons they thought it would be too difficult. So they asked us to stylize it a bit. And it was actually very helpful that they decided to push us to do that because it became very easy to figure out when people were using ATT &CK.
And of course there's a lot of funny things that happen after that too because I've seen so many different like uh special characters that people have put i don't know on purpose or by accident like basically hold shift and hit any number of the the keys up there from like dollar signs uh asterisk or whatever like i've seen it all like it's it's pretty funny when people try to do attack that's like a whole gamut of things that show up there yeah but there is one other thing that i wanted to mention um that's sort of in the same realm of like what would you do differently i i don't think we can really answer that question without also mentioning the ATT &CK evaluations.
That was one of sort of the offshoots that MITRE had done related to ATT &CK, but it's more MITRE being a third party sort of unbiased evaluator of endpoint detection and response systems using ATT &CK as sort of the benchmark. And so do you guys mind if I sort of go into a little bit of the story? Yeah, I'd love to hear it. We're history busted.
MITRE had started using ATT &CK -based evaluations, like constructing an adversary -based plan from ATT &CK to evaluate EDR tools for several of the government sponsors across the defense and dark of. And so this became basically a program in and of itself because a lot of the... security vendors that we were working with basically saw this as the next sort of gen testing because there's like AV tests out there. I think there was SE labs at the time and the industry didn't really feel like they were capturing the essence of what an EDR product would use and tend to be more focused on antivirus detection.
So we ended up doing something that MITRE had never done before because they typically only do these sorts of unbiased evaluations on behalf of sponsors to actually do this for the industry and create a whole program around it. And part of what was special with the earlier days of that program was we would actually work very closely with the vendors themselves. Because we were sort of operating under the mindset that we want to help them understand where their gaps are. And it isn't just something that they would contribute to and we would publish for sort of the industries to see and make more informed decisions about products.
It was really helping the vendors themselves sort of raise the tide a bit on the products in the industry. And so that was really special at the time. And as the sort of evaluations evolved, so to speak, over time, I kind of feel like it lost some of that luster a little bit. And I don't want to be too hard on MITRE.
Like there's very smart people that are driving this program still. They have really good ideas to bring a lot of the innovation back to it. But I think if you go talk to basically anybody who's been involved in this test from the vendor space. They've been very frustrated with the past few iterations of tests.
And so I don't think that would be necessarily something that I would change, but it was something that very much sort of like weighs on me as one of the... people who started this whole process. I really want to see it evolve over time and get back to something that's more innovative, more special that people are getting value out of rather than just being sort of a marketing stunt that I think it's turned into. Yeah, it's a tough space because there's so much money on the line of how well did you do in this or that that the salespeople love and customers love to get to justify whatever their favorite tool is or whatever.
It's a tough space because it's just there's so many competing interests that have so much power, right? I couldn't even imagine running a program like that. I'd have to have a very different style of personality to engage with people. I wanted to ask a couple more questions I wanted to cover here while we got you.
You kind of hinted at it a little bit. I'm curious, how do you see people misinterpret or misuse it? Like I said, it's the only thing in that red team space that covers the attacker side, whether it's simulated or real. Do you see people stretching it into use cases where you're just like, no, it doesn't do that?
I'm very curious about some of those elements. I think the biggest misconception of attack is that it's like a checkbox. It's more about the process of getting your network and up to a point where you can defend against these attacks and then continuing to evolve it because attackers are not static these techniques are not static they're always going to change over time and if you treat this as okay like i'm covered with attack i'm done like you're never going to be done you make it into a steady state where you have the the processes in place and you're understanding the updates to attack and understanding threats where you can uh better protect and better secure your environment but it's it's never going to be done and i think that's one of the misconceptions that a lot of people have especially when they first get started uh with attack that they treat it like a checkbox like okay i'm good now like i can tell my sees a little covered and then some catastrophic things happens uh like three months later and you know somebody's in the hot seat for uh for saying the wrong thing when they weren't actually covered And ATT &CK doesn't cover absolutely everything.
So there's no sort of like guarantee that MITRE has covered all known techniques for everything. And so that's why it's more about the process of protecting yourself with something like ATT &CK rather than just checking all the boxes. Yeah, and there's a lot of nuance again between the difference in the way the red and blue teams think is, you know, the red team, this is a thing and there could be 17 variations of how I could execute it. And congratulations, you detected one of them.
or your vendor says they detect one of them. What about the other 16 ways of doing it? Oh, those just slip past. What?
It's just like that tricky area between the two. Yeah, definitely. We've definitely seen a lot of people take some creative ways of interpreting what attack means. Did you expect it to be this successful?
Oh, no way. Yeah. No. And so one of our, I guess he was my manager at MITRE at the time, but he was sort of a really good thought leader in cyber within MITRE.
His name was Todd Whitbold. And I don't think ATT &CK could have happened without his guidance, but actually really early on in the process of defining ATT &CK and getting sort of like the internal buy -in on it. He said something to me that I didn't believe at the time. He said, a few years down the road, I think MITRE is going to be known for one main thing, and that's going to be ATT &CK.
And sure enough, he was right. Because when a lot of companies talk about ATT &CK, they refer to it as MITRE instead and not ATT &CK. So I think we were all a little bit shocked that it has gotten that much brand recognition. MITRE itself has gotten that much brand recognition just from this one.
when MITRE has been around for so many years and has done so many things that this is the one that it's mostly recognized for. Yeah, you don't really hear about MITRE CVE or MITRE CWE, but MITRE ATT &CK just falls off the tongue. Yeah, for sure. So that kind of leads me to my last question.
And it's more about you as a person because you spent seven years on it, as you mentioned. How do you move on to do something else? Because a long time ago, I was like the PKI guy in Microsoft support, and I kind of stopped that with Windows 2003. Yes, I'm that old.
And so I'm curious, your experience from like, okay, now that I'm done with this, and now that I'm moving on, and I've closed out all the things I really wanted to do. Has it been challenging? How did you think about that? How did you go through that?
Yeah, this is a really good question. So I am the type of person, for better or for worse, that needs to, at some point, move on to something else. So I don't know if it's like a sense of boredom per se, or just like, I need something new to learn about, to dive into. And I definitely started feeling that maybe about five years into ATT &CK.
And so the attack certainly wasn't the only thing that I did at Miner. So I started this other project called Caldera, which is an automated adversary emulation system that was largely based on attack to try to give defenders a more realistic way of testing their network against the techniques when they may not have a red team or have the resources to do the red team. And I was really... more interested in in that project for a long time um but it got to a point where i just couldn't split my time between the two and i ended up giving like caldera to another person to lead so that i can focus on attack because that was sort of the more important thing to work on over over time so i made these series of sacrifices for for attack but it finally gets to a point where i needed to to move on to something else to get closer to operations again.
And that's basically why I decided to come to Microsoft because of all the various like large amounts of data that we can leverage and all the interesting things that we can do to build new capabilities to actually counter these threats. So I got a little bit tired of talking about the threats and wanted to actually do something about them again. But it is really hard to step away from something like ATT &CK. because I had contacts out throughout the industry, was doing talks all the time, and I needed ATT &CK to be in a good spot before I could leave it.
Hence the discussion a little bit earlier about the sub -techniques there. So that was one of the things that I knew I needed to do before I could feel comfortable stepping away. And then the second one was I needed to make sure that there was a lead capable of driving ATT &CK in the future. and still maintaining the same sort of principles that we had started when it began.
And so Adam Pennington is the lead now. He was sort of, you know, he sat in the same room with me as ATT &CK was getting started. And so he was there along the way and then ended up playing a significant role. All right.
So as Mark kind of alluded to, let's bring this episode to an end. So one of the questions, there's two questions we asked. So the first one is, what does a typical day in the life of Blake look like? Lots of meetings.
So I've got a pretty large team. We engage with a lot of internal research stakeholders and product teams and engineering teams. So unfortunately, my day -to -day isn't really that interesting. It tends to be a lot of meetings, level setting, planning, check -ins for various projects and efforts that we're working on.
But there are some exciting moments, especially when one of our research proof of concepts starts producing really good results and we start getting really good customer feedback and generating a lot of good interest around. and being able to celebrate that with the team tends to be the highlights of the days. Mostly it's just meetings. All right, so let's really bring this episode to an end.
So if you had one thought to leave our listeners with, what would it be? Basically, you know, check out ATT &CK. If you have a role, whether it's offense, defense, or compliance, you just want to understand the threats of today a little bit better. There's lots of reasons to check it out and understand it and see how it applies to your day -to -day sort of work.
Yeah, I guess ultimately, if you don't look at it, you don't know what's in there. And if you don't know what's in there, you don't know if it's going to be of use to you. So take a look. All right, so let's bring this episode finally to an end.
Blake, thank you so much for joining us this week. Don't want to keep you away from your meetings. And to all our listeners, we hope you found this episode useful. Stay safe and we'll see you next time.
Thanks for listening to the Azure Security Podcast. You can find show notes and other resources at our website, azsecuritypodcast .net. If you have any questions, please find us on Twitter at AzureSecPod.
Background music is from ccmixter .com and licensed under the Creative Commons License.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.