Shadowing Practice: MITRE ATT&CK® Framework - Learn English Speaking with Video

Creando lección...
1
It's been reported that once an organization is breached, adversaries typically lurk on networks for months before being detected.
2
How did they get in?
3
How are they moving around?
4
What are they doing?
5
So where do you start?
6
MITRE's ATT&CK framework describes how adversaries penetrate networks and then move laterally, escalate privileges, and generally evade your defenses.
7
ATT&CK looks at the problem from the perspective of the adversary, what goals they are trying to achieve, and what specific methods they use.
8
ATT&CK organizes adversary behaviors into a series of tactics, specific technical objectives that an attacker wants to achieve.
9
Some examples of tactics include defense evasion, lateral movement, and exfiltration.
10
Within each tactic category, attack defines a series of techniques.
11
Each technique describes one way an adversary may try to achieve that objective.
12
There are multiple techniques within each tactic
13
because adversaries may use different methods based on their own expertise
14
or things like the availability of tools or how your systems are configured.
15
Each technique defined in attack includes a description of the method used by the adversary, the systems or platforms it applies to,
16
and where known, what specific adversary groups use this technique.
17
Techniques also describe ways to mitigate the behavior, along with any published references to the technique being employed.
18
ATT&CK helps you understand how adversaries might operate so you can plan how to detect or stop that behavior.
19
Armed with this knowledge, you can better understand the different ways an adversary prepares for, launches, and executes their attacks.
20
Another important use of ATT&CK is to help you detect an adversary's actions.
21
The ATT&CK framework includes resources designed to help you develop analytics that detect the techniques used by an adversary.
22
ATT&CK also maintains a library of information about selected adversary groups and the campaigns they have conducted.
23
And since ATT&CK is based on real-world observations, it allows you to correlate specific adversaries and the techniques they've used.
24
Because adversaries often use different techniques to attack different platforms and technologies, the ATT&CK framework is divided into a series of technology domains.
25
currently covered by ATT&CK include enterprise networks with Windows and Linux operating systems and mobile devices.
26
The ATT&CK framework can help your organization better understand the techniques specific adversaries are likely to use,
27
information you can use to evaluate your defenses and strengthen them where it matters most.
28
MITRE is building a community around ATT&CK so that experts in different domains
29
and technologies can come together to refine and extend the knowledge contained in the framework.
30
And because MITRE is a not-for-profit organization operating in the public interest, we can provide a conflict-free environment to create,
31
collect, share, and manage this information, making it available to everyone.
32
Learn more about ATT&CK and what else we're doing in cyber threat intelligence.
33
MITRE.
34
We solve problems for a safer world.

Understanding the MITRE ATT&CK Framework: Context & Background

The video explains how adversaries often remain undetected on networks for months, raising critical questions about their methods. It introduces the MITRE ATT&CK framework, a tool that maps adversary behaviors—from initial breach to privilege escalation and evasion—by focusing on their goals and techniques. This framework organizes these behaviors into tactics (technical objectives like defensive evasion) and techniques (specific methods to achieve those objectives), helping organizations detect and mitigate attacks. It also covers technology domains like enterprise networks and mobile devices, and highlights MITRE’s role as a non-profit fostering a collaborative community to refine the framework.

Top 5 Phrases for Daily Communication

  • "lurk on networks": Describes staying hidden in a system (e.g., "Hackers often lurk on networks before attacking.")
  • "move laterally": Refers to moving across a network (e.g., "Adversaries move laterally to access more data.")
  • "escalate privileges": Gaining higher access rights (e.g., "Attackers escalate privileges to control systems.")
  • "evade defenses": Avoiding detection (e.g., "Malware uses tricks to evade defenses.")
  • "correlate specific adversaries": Connecting threat actors to their methods (e.g., "Analysts correlate specific adversaries with known techniques.")

Step-by-Step Shadowing Guide for This Video

To improve English pronunciation and master the video’s technical language, use shadow speech (repeating aloud immediately after the speaker). Here’s how:
1. Break it down: The video uses complex terms like "lateral movement" and "exfiltration." Pause after each sentence, repeat it, and focus on stressing key words (e.g., "adversaries," "techniques").
2. Match pace and tone: The speaker’s crisp, informative tone requires clear enunciation. Practice mimicking their rhythm to build fluency.
3. Focus on connectors: Phrases like "so, where do you start?" and "another important use" link ideas. Repeating these helps with natural flow.
4. Repeat challenging sections: The part about tactics and techniques is dense. Loop it 3–5 times, using shadowspeak to internalize the structure.
5. Record and compare: Record yourself shadowing, then listen to the video. Note differences in pronunciation (e.g., "mitigate" vs. "mitigate") and adjust.
Learning English with YouTube videos like this one—using shadow speak—is a practical way to build confidence and clarity. Consistent practice will help you improve English pronunciation and communicate complex ideas more effectively.

¿Qué es la Técnica de Shadowing?

Shadowing es una técnica de aprendizaje de idiomas respaldada por la ciencia, desarrollada originalmente para la formación de intérpretes profesionales y popularizada por el políglota Dr. Alexander Arguelles. El método es simple pero poderoso: escuchas audio en inglés nativo y lo repites en voz alta de inmediato, como una sombra que sigue al hablante con solo 1-2 segundos de retraso. A diferencia de la escucha pasiva o los ejercicios de gramática, el shadowing obliga a tu cerebro y músculos de la boca a procesar y reproducir simultáneamente patrones de habla reales. Las investigaciones muestran que mejora significativamente la precisión de la pronunciación, la entonación, el ritmo, el habla conectada, la comprensión auditiva y la fluidez al hablar, convirtiéndola en una de las metodologías más efectivas para la preparación del IELTS Speaking y la comunicación en inglés en el mundo real.

Técnica de shadowing: lee la guía completa paso a paso →