A data-driven approach to prioritize MITRE ATT&CK techniques for active directory adversary emulation
Alshaimaa Abo-Alian1, Mahmoud Youssef2, Nagwa L Badr1
1Faculty of Computer and Information Sciences, Ain Shams University, Cairo, Egypt.
Scientific Reports
|July 30, 2025
Summary
This study introduces a new method for prioritizing cyber adversary techniques in Active Directory environments. It uses Multi-Criteria Decision-Making to focus on high-impact threats, improving cybersecurity defenses.
Area of Science:
- Cybersecurity
- Information Security
- Computer Science
Background:
- Advanced Persistent Threats (APTs) pose evolving challenges to Active Directory (AD) security.
- Adversary emulation is crucial for assessing security but lacks structured prioritization.
- Existing frameworks struggle with resource allocation for effective emulation.
Purpose of the Study:
- To develop a structured approach for prioritizing adversary emulation techniques.
- To enhance the effectiveness of security controls against APTs in AD environments.
- To align adversary emulation with real-world attack scenarios.
Main Methods:
- A Multi-Criteria Decision-Making (MCDM) approach integrating Operational Threat Intelligence (OTI) and MITRE ATT&CK data.
- Evaluation of techniques based on Active Directory Impact, Threat Score, and Security Control Gap.
- Entropy-based weighting for objective, data-driven prioritization.
Main Results:
- A validated framework for systematically prioritizing adversary techniques.
- Demonstrated effectiveness through a case study using the APT3 threat group.
- Identification of high-impact and difficult-to-detect techniques for focused emulation.
Conclusions:
- The proposed MCDM framework significantly enhances adversary emulation effectiveness.
- It strengthens security postures in Active Directory environments by focusing on critical threats.
- Provides a data-driven method for optimizing cybersecurity resource allocation.
Keywords:
Active directory securityAdversary emulationMITRE ATT&CKMulti-Criteria Decision-Making (MCDM)Technique prioritizationThreat intelligenceMore Related Videos
Related Concept Videos
Masking and Demasking Agents
2.7K
EDTA titrations may necessitate masking and demasking agents to temporarily protect a particular metal ion in a mixture from the EDTA reaction. These agents facilitate the sequential analysis of the metal ions by forming stable complexes with some—but not all—metal ions during certain steps.
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
There are many masking agents, such as cyanide, fluoride, triethanolamine, thiourea, and 2,3-bis(sulfanyl)propan-1-ol (formerly 2,3-dimercapto-1-propanol), with the masking agent chosen based on...
2.7K
Guidelines and Strategies for Safe Computer Charting
877
The guidelines and strategies provided by the American Nurses Association (ANA) and the Canadian Nurses Association (CNA) offer essential principles for ensuring safe and secure computer charting systems in healthcare settings. Let's break down each recommendation:
Maintain Confidentiality and Security:
Maintain Confidentiality and Security:
877
Olefin Metathesis Polymerization: Acyclic Diene Metathesis (ADMET)
2.0K
Acyclic diene metathesis polymerization or ADMET polymerization involves cross-metathesis of terminal dienes, such as 1,8-nonadiene, to give linear unsaturated polymer and ethylene. As ADMET is a reversible process, the formed ethylene gas must be removed from the reaction mixture to complete the polymerization process.
Similar to cross-metathesis, ADMET also involves the formation of metallacyclobutane intermediate by [2+2] cycloaddition of one of the double bonds of a terminal diene with...
Similar to cross-metathesis, ADMET also involves the formation of metallacyclobutane intermediate by [2+2] cycloaddition of one of the double bonds of a terminal diene with...
2.0K


