Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1017
MITRE ATT&CK Mitigation

M1017: User Training

ShareXLinkedInRedditHN

User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures: Create Comprehensive Training Programs: - Design training modules tailored to the organization's risk profile, covering topics such as phishing, password management, and incident reporting. - Provide role-specific training for high-risk employees, such as helpdesk staff or executives. Use Simulated Exercises: - Conduct phishing simulations to measure user susceptibility and provide targeted follow-up training. - Run social engineering drills to evaluate employee responses and reinforce protocols. Leverage Gamification and Engagement: - Introduce interactive learning methods such as quizzes, gamified challenges, and rewards for successful detection and reporting of threats. Incorporate Security Policies into Onboarding: - Include cybersecurity training as part of the onboarding process for new employees. - Provide easy-to-understand materials outlining acceptable use policies and reporting procedures. Regular Refresher Courses: - Update training materials to include emerging threats and techniques used by adversaries. - Ensure all employees complete periodic refresher courses to stay informed. Emphasize Real-World Scenarios: - Use case studies of recent attacks to demonstrate the consequences of successful phishing or social engineering. - Discuss how specific employee actions can prevent or mitigate such attacks.

▪Techniques addressed (60)

T1566.003Spearphishing via ServiceT1566.004Spearphishing VoiceT1204User ExecutionT1213.003Code RepositoriesT1552Unsecured CredentialsT1213.006DatabasesT1036MasqueradingT1213Data from Information RepositoriesT1598Phishing for InformationT1213.001ConfluenceT1078.002Domain AccountsT1557.002ARP Cache PoisoningT1598.003Spearphishing LinkT1213.005Messaging ApplicationsT1598.004Spearphishing VoiceT1213.004Customer Relationship Management SoftwareT1684.001ImpersonationT1598.001Spearphishing ServiceT1557Adversary-in-the-MiddleT1003.005Cached Domain CredentialsT1003OS Credential DumpingT1003.003NTDST1185Browser Session HijackingT1072Software Deployment ToolsT1204.003Malicious ImageT1657Financial TheftT1555.005Password ManagersT1552.001Credentials In FilesT1036.007Double File ExtensionT1111Multi-Factor Authentication InterceptionT1204.005Malicious LibraryT1528Steal Application Access TokenT1555.003Credentials from Web BrowsersT1598.002Spearphishing AttachmentT1176.002IDE ExtensionsT1176Software ExtensionsT1221Template InjectionT1003.001LSASS MemoryT1056.002GUI Input CaptureT1556.001Domain Controller AuthenticationT1557.004Evil TwinT1176.001Browser ExtensionsT1566.001Spearphishing AttachmentT1189Drive-by CompromiseT1078.004Cloud AccountsT1213.002SharepointT1566.002Spearphishing LinkT1684Social EngineeringT1552.008Chat MessagesT1204.001Malicious LinkT1204.002Malicious FileT1003.002Security Account ManagerT1003.004LSA SecretsT1078Valid AccountsT1566PhishingT1667Email BombingT1027Obfuscated Files or InformationT1547.007Re-opened ApplicationsT1539Steal Web Session CookieT1621Multi-Factor Authentication Request Generation

▪Reference

M1017on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.