
Sophos excels in the 2024 MITRE ATT&CK® Evaluations: Enterprise
2024 MITRE ATT&CK® Evaluations: Enterprise (Round 6)
MITRE ATT&CK® Evaluations are among the world’s most respected independent security tests. They emulate the tactics, techniques, and procedures (TTPs) leveraged by real-world adversarial groups and evaluate each participating vendor’s ability to detect, analyze, and describe threats, with output aligned to the language and structure of the MITRE ATT&CK® Framework.
Round 6 focused on behaviors inspired by three known threat groups:
- Democratic People's Republic of Korea (DPRK)
The evaluation emulated DPRK’s adversary behaviors targeting macOS via multi-stage operations, including elevating privileges and credential theft.
- Ransomware (CL0P and LockBit)
The evaluation emulated behaviors prevalent across campaigns using CL0P and LockBit ransomware, including abusing legitimate tools and disabling critical services.
Evaluation results
Sophos achieved full ‘technique’ level coverage — the highest possible rating — for 78 out of 80 adversary activities (sub-steps) across three comprehensive attack scenarios.
Evaluation attack scenarios
The evaluation comprised 80 adversary events (sub-steps) across three attack scenarios.








