MITRE ATT&CK v19: What’s changed, and how EclecticIQ helps you keep up

MITRE ATT&CK v19: What’s changed, and how EclecticIQ helps you keep up

Keypoints

  • EclecticIQ Intelligence Center 3.9 now supports MITRE ATT&CK v19.1.
  • The update reflects a significant structural change in the framework, including the split of Defense Evasion into Stealth and Defense Impairment.
  • Most existing Defense Evasion techniques keep their IDs but move under the new tactics, while a smaller set of Impair Defenses techniques were revoked and reissued.
  • MITRE ATT&CK v19.1 adds new ICS sub-techniques, increasing granularity for industrial control system analysis.
  • Mobile ATT&CK now includes detection strategies for the first time, initially covering Initial Access and Execution.
  • New techniques address AI-enabled and social engineering threats, including Query Public AI Services, Generate Content, and a Social Engineering parent technique.
  • EclecticIQ’s ATT&CK Navigator helps analysts visualize mappings, coverage, and gaps across Enterprise, ICS, and Mobile matrices.

MITRE Techniques

  • [T1490] Inhibit System Recovery – Related to the former Impair Defenses area that was revoked and reissued under new technique IDs (‘a smaller set, centered on the former Impair Defenses techniques, has been revoked and reissued under new technique IDs’).
  • [T1562] Impair Defenses – Former Defense Evasion content was reorganized, with this technique area moved into the new Defense Impairment tactic (‘disabling or modifying tools, firewalls, logs, and command history logging’).
  • [T1027] Obfuscated Files or Information – Used under the new Stealth tactic for hiding artifacts and obfuscation (‘hiding artifacts, obfuscation, masquerading, and exploiting for stealth’).
  • [T1036] Masquerading – Moved under Stealth, describing attacker behavior that imitates legitimate objects or identities (‘masquerading’).
  • [T1589] Gather Victim Identity Information – Mentioned indirectly through impersonation-related social engineering content, now consolidated under the new Social Engineering parent technique (‘impersonation and email spoofing’).
  • [T1598] Phishing for Information – Social engineering-related behavior consolidated under the new Social Engineering parent technique (‘impersonation and email spoofing’).
  • [T1059] Command and Scripting Interpreter – Mobile ATT&CK detection strategies now cover Execution, which includes interpreters used for running code (‘Initial Access and Execution’).
  • [T1190] Exploit Public-Facing Application – The article notes new detection strategies for Mobile Initial Access (‘Initial Access and Execution’).
  • [T1580] Cloud Infrastructure Discovery – AI-enabled techniques are added to capture adversary use of public AI services for reconnaissance (‘Query Public AI Services’).
  • [T1036] Masquerading – Also relevant to the new Social Engineering grouping, which consolidates impersonation behavior (‘impersonation’).

Indicators of Compromise

  • [Version] platform and framework version references – Intelligence Center 3.9, MITRE ATT&CK v19.1
  • [Product/Platform] affected software and feature names – EclecticIQ Intelligence Center, ATT&CK Navigator
  • [Technique names] newly introduced or updated behavior labels – Query Public AI Services, Generate Content, Social Engineering


Read more: https://blog.eclecticiq.com/mitre-attck-v19