Fortinet white logo
Fortinet white logo

Administration Guide

Running an ATT&CK v10+ case

Running an ATT&CK v10+ case

Adding groups

A group containing a collection of agents. You can later reference this group in the ATT&CK case settings so that FortiTester will perform adversary actions in this group..

  1. Go to Cases > ATT&CK v10+ Testing.

  2. Click ATT&CK Cases > Groups.

  3. Click + Create New.

  4. Enter a name for the groups.

  5. Click + Create New. Select agent. The agents to be added in this group.

  6. Repeat step 3 and 5 to add more groups.

Creating an adversary

The adversary represents a real adversary’s tactics and techniques. You can later reference the adversary in ATT&CK Cases.

  1. Go to Cases > ATT&CK v10+ Testing.

  2. Click ATT&CK Cases > Adversaries.

  3. Click + Create New.

  4. Enter a name and description for the Adversary.

  5. Click + Add ability.

  6. On the Abilities page, select the abilities you want to add. You can use the Platform, ATT&CK Tactic, and ATT&CK Technique options to filter out the desired abilities.

  7. Click Save.

On ATT&CK > ATT&CK Matrix v10+ Coverage, the supported abilities on you FortiTester appliance are displayed in green background. You can upgrade your service through System > FortiGuard to support a higher version of ATT&CK, so that more abilities will be included.

Creating an ATT&CK v10+ Case
  1. Go to Cases > ATT&CK v10+ Testing.

  2. Select ATT&CK Cases > ATT&CK Cases.

  3. Click + Create New.

  4. Configure the following settings.

    Name

    Enter a name for this case.

    Adversary

    Select the adversary which will perform a collection of operations on the target agents.

    Group

    Select the group which includes a collection of target hosts.

    Jitter Min/Max

    Agents normally check in with FortiTester every 60 seconds. Once recognizing they are part of an active operation, agents will start checking in according to the jitter time, which is by default 4/8(min/max). This fraction tells the agents that they should pause between 4 and 8 seconds (picked at random each time an agent checks in).

Running an ATT&CK v10+ case

Running an ATT&CK v10+ case

Adding groups

A group containing a collection of agents. You can later reference this group in the ATT&CK case settings so that FortiTester will perform adversary actions in this group..

  1. Go to Cases > ATT&CK v10+ Testing.

  2. Click ATT&CK Cases > Groups.

  3. Click + Create New.

  4. Enter a name for the groups.

  5. Click + Create New. Select agent. The agents to be added in this group.

  6. Repeat step 3 and 5 to add more groups.

Creating an adversary

The adversary represents a real adversary’s tactics and techniques. You can later reference the adversary in ATT&CK Cases.

  1. Go to Cases > ATT&CK v10+ Testing.

  2. Click ATT&CK Cases > Adversaries.

  3. Click + Create New.

  4. Enter a name and description for the Adversary.

  5. Click + Add ability.

  6. On the Abilities page, select the abilities you want to add. You can use the Platform, ATT&CK Tactic, and ATT&CK Technique options to filter out the desired abilities.

  7. Click Save.

On ATT&CK > ATT&CK Matrix v10+ Coverage, the supported abilities on you FortiTester appliance are displayed in green background. You can upgrade your service through System > FortiGuard to support a higher version of ATT&CK, so that more abilities will be included.

Creating an ATT&CK v10+ Case
  1. Go to Cases > ATT&CK v10+ Testing.

  2. Select ATT&CK Cases > ATT&CK Cases.

  3. Click + Create New.

  4. Configure the following settings.

    Name

    Enter a name for this case.

    Adversary

    Select the adversary which will perform a collection of operations on the target agents.

    Group

    Select the group which includes a collection of target hosts.

    Jitter Min/Max

    Agents normally check in with FortiTester every 60 seconds. Once recognizing they are part of an active operation, agents will start checking in according to the jitter time, which is by default 4/8(min/max). This fraction tells the agents that they should pause between 4 and 8 seconds (picked at random each time an agent checks in).