Pratica di Shadowing: MITRE ATT&CK® Framework - Impara a parlare inglese con i video

Creazione lezione...
1
It's been reported that once an organization is breached, adversaries typically lurk on networks for months before being detected.
2
How did they get in?
3
How are they moving around?
4
What are they doing?
5
So where do you start?
6
MITRE's ATT&CK framework describes how adversaries penetrate networks and then move laterally, escalate privileges, and generally evade your defenses.
7
ATT&CK looks at the problem from the perspective of the adversary, what goals they are trying to achieve, and what specific methods they use.
8
ATT&CK organizes adversary behaviors into a series of tactics, specific technical objectives that an attacker wants to achieve.
9
Some examples of tactics include defense evasion, lateral movement, and exfiltration.
10
Within each tactic category, attack defines a series of techniques.
11
Each technique describes one way an adversary may try to achieve that objective.
12
There are multiple techniques within each tactic
13
because adversaries may use different methods based on their own expertise
14
or things like the availability of tools or how your systems are configured.
15
Each technique defined in attack includes a description of the method used by the adversary, the systems or platforms it applies to,
16
and where known, what specific adversary groups use this technique.
17
Techniques also describe ways to mitigate the behavior, along with any published references to the technique being employed.
18
ATT&CK helps you understand how adversaries might operate so you can plan how to detect or stop that behavior.
19
Armed with this knowledge, you can better understand the different ways an adversary prepares for, launches, and executes their attacks.
20
Another important use of ATT&CK is to help you detect an adversary's actions.
21
The ATT&CK framework includes resources designed to help you develop analytics that detect the techniques used by an adversary.
22
ATT&CK also maintains a library of information about selected adversary groups and the campaigns they have conducted.
23
And since ATT&CK is based on real-world observations, it allows you to correlate specific adversaries and the techniques they've used.
24
Because adversaries often use different techniques to attack different platforms and technologies, the ATT&CK framework is divided into a series of technology domains.
25
currently covered by ATT&CK include enterprise networks with Windows and Linux operating systems and mobile devices.
26
The ATT&CK framework can help your organization better understand the techniques specific adversaries are likely to use,
27
information you can use to evaluate your defenses and strengthen them where it matters most.
28
MITRE is building a community around ATT&CK so that experts in different domains
29
and technologies can come together to refine and extend the knowledge contained in the framework.
30
And because MITRE is a not-for-profit organization operating in the public interest, we can provide a conflict-free environment to create,
31
collect, share, and manage this information, making it available to everyone.
32
Learn more about ATT&CK and what else we're doing in cyber threat intelligence.
33
MITRE.
34
We solve problems for a safer world.

Informazioni sulla lezione

In questa lezione, praticherai l'ascolto e la ripetizione di un video tecnico sull'ATT&CK Framework di MITRE, un argomento cruciale nella cybersecurity. Imparerai a seguire un discorso strutturato, comprendere termini specifici e migliorare la tua pronuncia inglese. La lezione si concentra sulla tecnica del "shadowspeak", che aiuta a sincronizzare la tua voce con il ritmo e l'intonazione del parlante, fondamentale per una conversazione fluida in inglese.

Parole chiave e frasi utili

  • Adversary: Avversario (in contesto cybersecurity, un attaccante)
  • Lateral movement: Movimento laterale (spostamento all'interno di una rete dopo l'accesso)
  • Defensive evasion: Evasione difensiva (técnica per eludere le difese di un sistema)
  • Exfiltration: Espilazione (estrazione di dati sensibili da una rete)
  • Tactic: Tattica (obiettivo tecnico specifico di un attacco)
  • Mitigate: Mitigare (ridurre il rischio o l'impatto di un attacco)

Consigli per la pratica

Il video ha un tono formale e un ritmo moderato, ideale per esercitarti con la tecnica del shadowing. Ecco come procedere: prima, ascolta il video intero per capire il contesto. Poi, riproduci un frammento di 5-10 secondi e ripetilo immediatamente, cercando di imitare l'intonazione e la velocità. Usa un shadowing site per registrare la tua voce e confrontarla con l'originale: questo ti aiuterà a notare differenze nella pronuncia. Per la pratica di conversazione in inglese, riassumi i concetti del video in modo spontaneo, usando le parole chiave apprese. Ricorda: il shadow speech non è solo ripetere, ma capire e riprodurre il senso del discorso. Ripeti l'esercizio con sezioni più lunghe finché non senti che la sincronizzazione è naturale. Questo metodo migliorerà la tua fluenza e la tua capacità di comprendere discorsi tecnici in inglese.

Cos'è la tecnica dello Shadowing?

Shadowing è una tecnica di apprendimento delle lingue supportata da studi scientifici, originariamente sviluppata per la formazione dei traduttori professionisti e resa popolare dal poliglotta Dr. Alexander Arguelles. Il metodo è semplice ma potente: ascolti un audio in inglese di madrelingua e lo ripeti immediatamente ad alta voce — come un'ombra che segue il parlante con un ritardo di solo 1–2 secondi. A differenza dell'ascolto passivo o degli esercizi di grammatica, lo shadowing costringe il tuo cervello e i muscoli della bocca a elaborare e riprodurre simultaneamente i modelli di discorso reale. La ricerca dimostra che migliora significativamente la precisione della pronuncia, l'intonazione, il ritmo, il discorso connesso, la comprensione dell'ascolto e la fluidità del parlato — rendendolo uno dei metodi più efficaci per la preparazione alla prova di speaking dell'IELTS e per la comunicazione reale in inglese.

Tecnica dello shadowing: leggi la guida completa passo dopo passo →