Mitre 22 WP
Mitre 22 WP
Mitre 22 WP
MITRE Engenuity™
ATT&CK® Evaluation
SentinelOne Participates for the
Fourth Year with Record Performance
April 2022
Table of Contents
Introduction 3
Results 5
• Wizard Spider is a financially motivated criminal group that has been conducting
ransomware campaigns since August 2018 against a variety of organizations,
ranging from major corporations to hospitals.
• Sandworm is a destructive Russian threat group that is known for carrying out
notable attacks such as the 2015 and 2016 targeting of Ukrainian electrical
companies and 2017’s NotPetya attacks.
The Evals team chose to emulate two threat groups that abuse the Data Encrypted For
Impact (T1486) technique. In Wizard Spider’s case, they have leveraged data encryption
for ransomware, including the widely known Ryuk malware (S0446). Sandworm, on the
other hand, leveraged encryption for the destruction of data, perhaps most notably with
their NotPetya malware (S0368) that disguised itself as ransomware. While the common
thread to this year’s evaluations is “Data Encrypted for Impact,” both groups have substan-
tial reporting on a broad range of post-exploitation tradecraft.
Though the ATT&CK evaluation is not a competition, the results do help organizations un-
derstand relative product performance under emulated adversary conditions. The 2022
test takes place over two days and involves 19 distinct steps comprising 109 sub-steps.
This year MITRE Engenuity emulates the Wizard Spider adversary group on Day 1 and the
Sandworm adversary group on Day 2.
Arm yourself against exaggerated competing vendor claims by taking time to understand
the differences among ATT&CK’s detection categories. In summary, not all detections have
the same level of quality. On one end of the quality, spectrum is “Telemetry” which is sim-
ple “minimally processed data.” On the other end of quality are “Techniques” that, accord-
ing to the ATT&CK website, “gives the analyst information on how the action was performed
or helps answer the question ‘what was done’.” The evaluation describes “Analytic Detec-
tions” as the sum total of all three higher quality, enriched detection types labeled as Gen-
eral, Tactic, and Technique. Lastly, ATT&CK defines two modifiers, configuration change
and delayed. During testing, if the vendor modifies how their product operates to adjust
for whatever reason, the evaluation proctors note these as “configuration changes.” During
testing, if a “detection is not immediately available to the analyst due to additional process-
ing unavailable due to some factor that slows or defers its presentation,” this detection is
labeled as “delayed.”
SOC teams often find themselves with too many alerts and not enough time to investigate,
research, and respond. Alerts for the sake of alerts become meaningless: unused and un-
noticed. Pinpointed alerts that are actionable with pre-assembled context maximize EDR
effectiveness and use.
According to MITRE Engenuity’s published results, SentinelOne recorded the highest num-
ber of analytic detections for this year’s evaluation as well as the last three years.
During the ATT&CK Evaluation, the TTPs used by Wizard Spider and Sandworm were
grouped into 19 attack steps, and SentinelOne Singularity detected all of them. This
allows a comprehensive view of the entire enterprise, minimizing incident dwell time and
reducing risk.
SentinelOne Singularity
XDR detects malicious file
execution and automatically
correlates it with other data
to provide context.
SentinelOne delivered the fastest protection. With its real-time protection, Singularity XDR
provided the MITRE ATT&CK Evaluation with the least amount of permitted actions in the
kill-chain for attackers to do damage. The ATT&CK results reveal our commitment to pre-
venting and protecting against every possible threat and keeping our customers safe from
most adversaries.
sentinelone.com
4.9
About SentinelOne
More Capability. Less Complexity. SentinelOne is pioneering the
future of cybersecurity with autonomous, distributed endpoint
intelligence aimed at simplifying the security stack without
forgoing enterprise capabilities. Our technology is designed to
scale people with automation and frictionless threat resolution.
Are you ready?
sentinelone.com
2022_MITRE_Engenuity_ATT&CK_Evaluation_04272022
© SentinelOne 2022
SENTINELONE WHITEPAPER