{"id":50870,"date":"2023-03-02T23:06:00","date_gmt":"2023-03-02T23:06:00","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/cisa-mitre-look-to-takeattack-framework-out-of-the-weeds"},"modified":"2023-03-02T23:06:00","modified_gmt":"2023-03-02T23:06:00","slug":"cisa-mitre-look-to-take-attck-framework-out-of-the-weeds","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/","title":{"rendered":"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds"},"content":{"rendered":"<p>The US Cybersecurity and Infrastructure Security Agency (CISA) has launched Decider, a free tool to help the cybersecurity community more easily map threat actor behavior to the MITRE ATT&amp;CK framework.<\/p>\n<p>Created in partnership with the US Homeland Security Systems Engineering and Development Institute (HSSEDI) and MITRE, Decider is a Web application that organizations can download and host within their own infrastructure, thus making it available to a range of users via the cloud. It&#8217;s meant to simplify the often onerous process of using the framework accurately and effectively, as well as open up its use to analysts at every level in a given cybersecurity organization.<\/p>\n<h2 class=\"regular-text\">ATT&amp;CK: A Complex Framework<\/h2>\n<p>ATT&amp;CK is designed to <a href=\"https:\/\/www.darkreading.com\/edge-ask-the-experts\/how-should-my-security-analyst-use-the-mitre-att-ck-framework-\" target=\"_blank\" rel=\"noopener\">help security analysts<\/a> determine what attackers are trying to achieve and how far along they are in the process (i.e., are they establishing initial access? Moving laterally? Exfiltrating data?) It does this via a set of known cyberattack techniques and sub-techniques determined and refreshed periodically by MITRE, that analysts can map on top of what they might be seeing in their own environments.<\/p>\n<p>The goal is to anticipate the bad guys&#8217; next moves and shut down attacks as quickly as possible. The framework can also be incorporated into a variety of security tools, and it provides a standard language for communicating with peers and stakeholders during incident response and forensic investigations.<\/p>\n<p>That&#8217;s all well and good, but the problem is that the framework is notoriously&nbsp;complex, often requiring a high level of training and expertise to select the correct mappings, for instance. It also <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/mitre-adds-macos-linux-more-data-types-to-att-ck-framework\" target=\"_blank\" rel=\"noopener\">continually expands<\/a>, including&nbsp;beyond enterprise attacks to incorporate threats to industrial control systems (ICS) and <a href=\"https:\/\/www.darkreading.com\/dr-tech\/mitre-rolls-out-fight-to-protect-5g-networks\" target=\"_blank\" rel=\"noopener\">the mobile landscape<\/a>, adding to the complexity. In all, it&#8217;s a sprawling data set to navigate \u2014 and cyber defenders often end up in the weeds when trying to use it.<\/p>\n<p>&#8220;There are a lot of techniques and sub-techniques that are available and that can get very involved and very technical, and oftentimes analysts are overwhelmed, or it slows them down quite a bit, because they don&#8217;t necessarily know if the sub-technique they&#8217;re picking is the right one,&#8221; James Stanley, section chief at CISA, says, noting that complaints about mis-mappings using the tool&nbsp;are common.<\/p>\n<p>&#8220;When you go to the website, there&#8217;s a lot of information in front of you and it gets daunting quickly. The Decider tool really just brings it into more plain language for an analyst to use, regardless of their level of expertise,&#8221; he says. &#8220;We wanted to give our stakeholders more guidance on how to use the framework, and make it available to, say, junior analysts who could benefit from using it in real time during middle-of-the-night incident response, for instance.&#8221;<\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" data-image=\"ng6rm5bxnc4s\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\" data-sys-asset-uid=\"blt7c5d2d4f5541b3a4\" alt=\"A screenshot of MITRE's decider tool\">\n<\/picture><figcaption>Decider uses a series of questions to guide analysts through the framework. Source: MITRE Corp.<\/figcaption><\/figure>\n<p>On a broader level, proselytizers at CISA and MITRE believe that a wider use of ATT&amp;CK \u2014 as encouraged by Decider \u2014 will lead to better, more actionable threat intelligence \u2014 and better cyber-defense outcomes.<\/p>\n<p>&#8220;At CISA, we really want to put the emphasis on using threat intelligence to be proactive in your defense and not reactive,&#8221; Stanley says. &#8220;For a very long time, the industry&#8217;s go-to for that has been to share indicators of compromise (IOCs), which have very broad, very limited context.&#8221;&nbsp;<\/p>\n<p>In contrast,&nbsp;ATT&amp;CK tips the playing field to the defense&#8217;s advantage, he says, because it&#8217;s granular and gives organizations a way to understand the specific threat actor playbooks that are relevant to <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/augmenting-smb-defense-strategies-with-mitre-att-ck-a-primer\" target=\"_blank\" rel=\"noopener\">their specific environments<\/a>.<\/p>\n<p>&#8220;Threat actors should know that their playbooks are essentially useless once we highlight what they do and how they do it and incorporate it into the framework,&#8221; he explains. &#8220;Organizations that can use it have a much stronger security posture as opposed to just kind of blindly blocking IP addresses or hashes, like the industry is so used to doing. Decider gets us closer to that.&#8221;<\/p>\n<h2 class=\"regular-text\">Simplifying ATT&amp;CK for Analyst Accessibility<\/h2>\n<p>Decider makes ATT&amp;CK mapping more accessible by walking users through a series of guided questions about adversary activity, with the goal of identifying the correct tactics, techniques, or sub-techniques in the framework to fit the incident in an intuitive way. From there, those results can &#8220;inform a range of important activities such as sharing the findings, discovering mitigations, and detecting further techniques,&#8221; according to CISA&#8217;s <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2023\/03\/01\/cisa-releases-decider-tool-help-mitre-attck-mapping\" target=\"_blank\" rel=\"noopener\">March 1 announcement<\/a> of the new tool.<\/p>\n<figure>\n<picture><source type=\"image\/webp\" media=\"(max-width: 576px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltc99f078012c712bb\/64011617bd118e121669f1d4\/Decider2-MITRE-MITRE.png?width=480&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(max-width: 767px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltc99f078012c712bb\/64011617bd118e121669f1d4\/Decider2-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/webp\" media=\"(min-width: 768px)\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltc99f078012c712bb\/64011617bd118e121669f1d4\/Decider2-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"><source type=\"image\/jpeg\" srcset=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltc99f078012c712bb\/64011617bd118e121669f1d4\/Decider2-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=jpg&amp;disable=upscale\"><img decoding=\"async\" data-image=\"ogh0zarvn0aj\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/bltc99f078012c712bb\/64011617bd118e121669f1d4\/Decider2-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\" data-sys-asset-uid=\"bltc99f078012c712bb\" alt=\"Decider sub-technique definition of spearphishing\">\n<\/picture><figcaption>Decider uses simplified language and definitions for techniques and sub-techniques. Source: MITRE Corp.<\/figcaption><\/figure>\n<p>In addition to the prepopulated guiding questions, Decider uses simplified language that would be accessible to any security analyst, an intuitive search and filter function for uncovering relevant techniques, and a &#8220;shopping cart&#8221; functionality that lets users export results to commonly used formats. Additionally, organizations can tailor and tune it to their own individual environments, including flagging common mis-mappings.<\/p>\n<p>The hope is for ATT&amp;CK to eventually become a foundational, background tool for cybersecurity organizations, according to John Wunder, department manager, CTI, and Adversary Emulation at MITRE, rather than the unwieldy, if useful, instrument that it has been.<\/p>\n<p>&#8220;One thing that I would really love to see as ATT&amp;CK moves more into the background is just a part of the day-to-day operations of cybersecurity and individual analysts just having to pay less attention to it,&#8221; he says. &#8220;It&#8217;s just something that should form the foundation of what we do and thinking about understanding adversary behaviors, and not something that you have to spend a lot of time thinking through each time you&#8217;re doing an incident response. Decider is a big step forward to that.&#8221;<\/p>\n<p>The tool also helps ATT&amp;CK&#8217;s syntax to become the de facto common nomenclature across tools and security platforms, and for sharing threat intelligence.<\/p>\n<p>&#8220;Once you see ATT&amp;CK used across more and more of the ecosystem, and everyone using a common language, then the users of ATT&amp;CK start to see more and more benefit from aligning things to the framework and using it to more effectively correlate tools and so on,&#8221; Wunder says. &#8220;Hopefully through things like&nbsp;Decider that make it easier to use, we&#8217;ll start to see more and more of that.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cisa-mitre-look-to-takeattack-framework-out-of-the-weeds\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Decider tool is designed to make the ATT&#038;CK framework more accessible and usable for security analysts of every level, with an intuitive interface and simplified language.Read More <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cisa-mitre-look-to-takeattack-framework-out-of-the-weeds\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-50870","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-03-02T23:06:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds\",\"datePublished\":\"2023-03-02T23:06:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/\"},\"wordCount\":1069,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt7c5d2d4f5541b3a4\\\/6401159793bae56487af02f1\\\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/\",\"name\":\"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt7c5d2d4f5541b3a4\\\/6401159793bae56487af02f1\\\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"datePublished\":\"2023-03-02T23:06:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt7c5d2d4f5541b3a4\\\/6401159793bae56487af02f1\\\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt7c5d2d4f5541b3a4\\\/6401159793bae56487af02f1\\\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/","og_locale":"en_US","og_type":"article","og_title":"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-03-02T23:06:00+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds","datePublished":"2023-03-02T23:06:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/"},"wordCount":1069,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/","url":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/","name":"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","datePublished":"2023-03-02T23:06:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt7c5d2d4f5541b3a4\/6401159793bae56487af02f1\/Decider-MITRE-MITRE.png?width=690&amp;quality=80&amp;format=webply&amp;disable=upscale"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/cisa-mitre-look-to-take-attck-framework-out-of-the-weeds\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"CISA, MITRE Look to Take ATT&amp;CK Framework Out of the Weeds"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=50870"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/50870\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=50870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=50870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=50870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}