Automated ATT&CK Technique Chaining @FIRSTdotorg
Automated ATT&CK Technique Chaining  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 11 hours ago
Martin Eian (mnemonic, NO)

Dr. Martin Eian is a Researcher at mnemonic. He has more than 20 years of work experience in IT security, IT operations, and information security research roles. In addition to his position at mnemonic, he is a member of the Europol EC3 Advisory Group on Internet Security. He has previously worked as the Head of Research at mnemonic, as an Adjunct Associate Professor at the Norwegian University of Science and Technology (NTNU), as a Threat Intelligence analyst at mnemonic, and as an Information Security Specialist at Nordea. He holds a PhD in Telematics from NTNU (2012). His current research topics are threat intelligence automation, quantitative cyber risk analysis, vulnerability measurements and analysis, and alert aggregation and contextualization. He has previously presented at the FIRST Annual Conference, the ONE Conference, and at Black Hat USA Arsenal.

Incident response teams need to determine what happened before and after an observation of adversary behavior in order to effectively respond to incidents. The MITRE ATT&CK knowledge base provides useful information about adversary behaviors, but provides no guidance on what most likely happened before and after an observed behavior. We have developed methods and open source tools to help incident responders answer the questions "What did most likely happen prior to this observation" and "What are the adversary's most likely next steps given this observation". To be able to answer these questions, we combine semantic modeling of subject matter expert knowledge with data-driven methods trained on data from computer security incidents.
Automated ATT&CK Technique ChainingPanel: The CVE Supplier ADP (SADP) Pilot: Am I Affected byUpstream?Establishing a Global Community of Practice on Coordinated Vulnerability Disclosure (CVD)Lazarus Group Evolved Their Infection Chain with Old and New MalwareAI Interpretability as a Security Control: Introducing the CIRCUIT FrameworkFrom Dork to Diplomat: Communicating Coherently for Vulnerability & Incident ResponseBroken Seals, Broken Trust: Flaws and Defences in the Certificate EcosystemBringing Chronological Context to Disparate Artifacts: Accelerating Digital ForensicsQuantifying Swiss Cheese, the Bayesian WayMind Over Malware: Reducing Decision Fatigue in Incident Response TeamsSupply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?Incident Preparedness Takeaways from 5000 Exercise Participants
FIRST |

Automated ATT&CK Technique Chaining

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER