{"id":6577,"date":"2024-12-11T09:00:00","date_gmt":"2024-12-11T15:00:00","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=82864"},"modified":"2024-12-11T09:00:00","modified_gmt":"2024-12-11T15:00:00","slug":"latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/12\/11\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware\/","title":{"rendered":"Latest round of MITRE ATT&amp;CK evaluations put cybersecurity products through rigors of ransomware\u00a0"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v21.7 (Yoast SEO v21.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ --> <title>Latest round of MITRE ATT&amp;CK evaluations put cybersecurity products through rigors of ransomware&nbsp; | CyberScoop<\/title> <meta name=\"description\" content=\"The sixth round of tests included two ransomware variants, while also incorporating macOS for the first time.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/mitre-attack-evaluations-ransomware-macos\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"Latest round of MITRE ATT&amp;CK evaluations put cybersecurity products through rigors of ransomware&nbsp;\"> <meta property=\"og:description\" content=\"The sixth round of tests included two ransomware variants, while also incorporating macOS for the first time.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/mitre-attack-evaluations-ransomware-macos\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:published_time\" content=\"2024-12-11T15:00:00+00:00\"> <meta property=\"article:modified_time\" content=\"2024-12-11T01:01:34+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg\"> <meta property=\"og:image:width\" content=\"1920\"> <meta property=\"og:image:height\" content=\"1440\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Greg Otto\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@gregotto\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1732206022g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress\/dist\/css\/related-posts-block-styles.min.css?m=1730999764g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1732010462g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=ddc036fa194c40cf406f\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" title=\"JSON\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/82864\"><link rel=\"EditURI\" type=\"application\/rsd+xml\" title=\"RSD\" href=\"https:\/\/cyberscoop.com\/xmlrpc.php?rsd\">\n<meta name=\"generator\" content=\"WordPress 6.7.1\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=82864\">\n<link rel=\"alternate\" title=\"oEmbed (JSON)\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fmitre-attack-evaluations-ransomware-macos%2F\">\n<link rel=\"alternate\" title=\"oEmbed (XML)\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fmitre-attack-evaluations-ransomware-macos%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"post-template-default single single-post postid-82864 single-format-standard\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/mitre-attack-evaluations-ransomware-macos\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"25.454819277108\">\n<div class=\"single-article__header-content\" readability=\"31.416\">\n<ul class=\"single-article__eyebrow\">\n<li class=\"single-article__category\"> <a class=\"single-article__category-link\" href=\"https:\/\/cyberscoop.com\/mitre-attack-evaluations-ransomware-macos\/\"> <span>Technology<\/span> <\/a> <\/li>\n<\/ul>\n<p> The sixth round of tests included two ransomware variants, while also incorporating macOS for the first time. <\/p>\n<p> <!-- Listen to this article section --> <!-- End of audio player --> <\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"480\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware.jpg?resize=640%2C480&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt=\"MITRE ATT&amp;CK\" decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg 1920w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=300,225 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=768,576 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=1024,768 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=1536,1152 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=600,450 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=224,168 224w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=449,337 449w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=900,675 900w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-2.jpg?resize=1124,843 1124w\" sizes=\"(max-width: 900px) 100vw, 900px\"><figcaption> MITRE at the 2020 RSA Conference in San Francisco. (Greg Otto \/ Scoop News Group) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"65.022696219827\"><body readability=\"130.52371508842\"> <\/p>\n<p>MITRE Corporation released findings Wednesday from its latest round of ATT&amp;CK evaluations, assessing the capabilities of enterprise cybersecurity solutions against some of the most prevalent ransomware tactics and North Korean malware.<\/p>\n<p>The sixth such evaluation from the nonprofit research organization measured 19 different vendors\u2019 ability to protect enterprise systems by evaluating them against two prominent ransomware strains -\u2014Cl0p and LockBit \u2014 as well as North Korean-linked malware targeting macOS systems. For the latter, MITRE\u2019s evaluation used advanced multi-stage malware emulations that highlighted sophisticated tactics, such as exploiting legitimate macOS utilities and stealthily exfiltrating sensitive data.<\/p>\n<p>According to William Booth, the general manager of MITRE\u2019s ATT&amp;CK evaluations, the results revealed significant disparities between vendors\u2019 detection rates and their ability to accurately distinguish malicious activity from benign system behavior.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cSome vendors had higher false-positive rates than detection rates, which indicates a need to better distinguish legitimate activity from malicious activity,\u201d Booth told CyberScoop.&nbsp;<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-how-the-tests-were-conducted\"><strong>How the tests were conducted&nbsp;<\/strong><\/h4>\n<p>The evaluation is conducted in multiple stages.<\/p>\n<p>First, MITRE runs an initial emulation plan to assess the vendors\u2019 baseline detection capabilities. This means they execute a series of malicious activities and see which ones the vendors can detect without any prior knowledge.<\/p>\n<p>After this initial detection test, MITRE gives vendors a day to make configuration changes to their products. This could involve things like adding new detection logic, updating user interfaces, or making other adjustments to improve product performance.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The purpose of this configuration change period is to allow the vendors to enhance their products based on the initial test results. MITRE wants to see if the vendors can improve their detection and protection capabilities by making targeted changes.<\/p>\n<p>In the second phase of testing, MITRE runs a separate emulation plan focused on the protection capabilities of the vendors\u2019 products, complete with a new set of malicious activities that the vendors haven\u2019t seen before.<\/p>\n<p>By separating the detection and protection tests, and allowing the configuration changes in between, MITRE can assess how well the vendors can adapt and improve their security controls in response to new threats.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-what-the-results-show-nbsp\"><strong>What the results show&nbsp;<\/strong><\/h4>\n<p>The organization explicitly states that \u201cthe evaluations do not rank vendors and their solutions, but instead provide insights\u201d for organizations to make their own decisions based on their unique IT systems and threat models. However, Booth told CyberScoop there were surprising findings from the evaluation\u2019s data.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>One of the most striking discoveries was that some vendors had higher false-positive rates than actual detection rates. Booth explained that this indicates a significant need for vendors to improve the specificity of their detection and blocking capabilities.<\/p>\n<p>\u201cThere are certain vendors where you\u2019ll see, yes, they had 100% detections, but their false-positive rate was also 90%,\u201d Booth said. \u201cThat\u2019s really interesting when you start to look at, OK, how can [vendors] determine what needs to be detected versus what is just noise?\u201d<\/p>\n<p>Another surprising finding was the difficulty vendors faced in protecting against threats in the post-compromise stage. Booth noted that MITRE\u2019s evaluation placed a strong emphasis on assessing vendors\u2019 ability to detect and mitigate ransomware activities after the initial breach, rather than just the initial infection.<\/p>\n<p>\u201cThe assumption that you\u2019re always going to block on the first piece of activity is not the case,\u201d Booth said. \u201cWe\u2019re focused on what happens after that initial compromise.\u201d<\/p>\n<p>Many vendors seemed to struggle with this post-compromise focus, as ransomware can often mimic normal system and file encryption behaviors.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Booth also highlighted the varied approaches vendors are taking when it comes to detection, noting some key differences between machine learning-based methods and more heuristic-based techniques.<\/p>\n<p>\u201cThere\u2019s certainly some that are using AI, applying the language models on the raw data, and then there\u2019s others that are using more of a heuristic approach,\u201d Booth explained.<\/p>\n<p>The evaluation revealed that these differing detection strategies can lead to vastly different results, both in terms of detection rates and false-positive rates.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-a-first-for-mac\"><strong>A first for Mac<\/strong><\/h4>\n<p>Booth told CyberScoop the inclusion of macOS in this latest evaluation round presented some unique challenges, noting that evaluating Mac-based threats required a different approach compared to previous Windows-focused assessments.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cMacOS was a bit tougher because there\u2019s not a lot of public CTI [Cyber Threat Intelligence] on that,\u201d Booth said.<\/p>\n<p>That lack of public threat intelligence on Mac-targeted malware campaigns made it more challenging for MITRE to construct realistic, evidence-based emulation scenarios for the evaluation.<\/p>\n<p>\u201cThere\u2019s a lot that goes into formulating [the evaluation], in terms of our discussions with many different groups and organizations to get input into doing that. But Mac was hard because there\u2019s not a lot of public CTI,\u201d Booth acknowledged.<\/p>\n<p>Despite these difficulties, MITRE included macOS in this round of testing to better reflect the evolving threat landscape. As more organizations adopt Apple devices, understanding the security capabilities of products against Mac-based attacks has become increasingly important.<\/p>\n<h4 class=\"wp-block-heading\" id=\"h-full-list-of-vendors\"><strong>Full list of vendors<\/strong><\/h4>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The full cohort of products that MITRE evaluated included:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>AhnLab<\/li>\n<li>Bitdefender<\/li>\n<li>Check Point<\/li>\n<li>Cisco Systems<\/li>\n<li>Cybereason<\/li>\n<li>Cynet<\/li>\n<li>ESET<\/li>\n<li>HarfangLab<\/li>\n<li>Microsoft<\/li>\n<li>Palo Alto Networks<\/li>\n<li>Qualys<\/li>\n<li>SentinelOne<\/li>\n<li>Sophos<\/li>\n<li>Tehtris<\/li>\n<li>ThreatDown<\/li>\n<li>Trellix<\/li>\n<li>Trend Micro<\/li>\n<li>WatchGuard<\/li>\n<li>WithSecure<\/li>\n<\/ul>\n<p>The evaluation results <a href=\"https:\/\/attackevals.mitre-engenuity.org\/\">are publicly available<\/a> on MITRE\u2019s ATT&amp;CK evaluation website.&nbsp;<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\" readability=\"4.281308411215\">\n<div class=\"author-card\" readability=\"14\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/latest-round-of-mitre-attck-evaluations-put-cybersecurity-products-through-rigors-of-ransomware-1.jpg?w=640&#038;ssl=1\" alt=\"Greg Otto\"> <\/figure>\n<\/p><\/div>\n<p><h4 class=\"author-card__name\">Written by Greg Otto<\/h4>\n<p> Greg Otto is Editor-in-Chief of CyberScoop, overseeing all editorial content for the website. Greg has led cybersecurity coverage that has won various awards, including accolades from the Society of Professional Journalists and the American Society of Business Publication Editors. Prior to joining Scoop News Group, Greg worked for the Washington Business Journal, U.S. News &amp; World Report and WTOP Radio. He has a degree in broadcast journalism from Temple University. <\/p>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/mitre-attack-evaluations-ransomware-macos\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Latest round of MITRE ATT&amp;CK evaluations put cybersecurity products through<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[322,462,3303,46,256,310,288],"tags":[326,463,3304,54,262,311,294],"class_list":["post-6577","post","type-post","status-publish","format-standard","hentry","category-clop","category-lockbit","category-mitre","category-ransomware","category-research","category-technology","category-threats","tag-clop","tag-lockbit","tag-mitre","tag-ransomware","tag-research","tag-technology","tag-threats"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/clop\/\" rel=\"category tag\">Clop<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/lockbit\/\" rel=\"category tag\">LockBit<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/mitre\/\" rel=\"category tag\">MITRE<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ransomware\/\" rel=\"category tag\">ransomware<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/research\/\" rel=\"category tag\">Research<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/technology\/\" rel=\"category tag\">Technology<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/threats\/\" rel=\"category tag\">Threats<\/a>","tag_info":"Threats","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6577"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6577\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}