M

MITRE ATT&CK

A comprehensive knowledge base of adversary tactics and techniques based on real-world observations of cyberattacks.

What is MITRE ATT&CK?

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally-accessible knowledge base of adversary behaviors based on real-world observations. It provides a common language and framework for describing cyberattack patterns.

ATT&CK Structure

Tactics: The "why" - adversary's goals

  1. Reconnaissance
  2. Resource Development
  3. Initial Access
  4. Execution
  5. Persistence
  6. Privilege Escalation
  7. Defense Evasion
  8. Credential Access
  9. Discovery
  10. Lateral Movement
  11. Collection
  12. Command and Control
  13. Exfiltration
  14. Impact

Techniques: The "how" - methods to achieve goals Sub-techniques: Specific implementations

ATT&CK Matrices

  • Enterprise: Windows, macOS, Linux, Cloud
  • Mobile: iOS and Android
  • ICS: Industrial Control Systems

Using ATT&CK

  • Map detected behaviors to techniques
  • Identify detection gaps
  • Simulate adversary behaviors
  • Communicate threats clearly
  • Benchmark security coverage
  • Guide red team exercises