Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is MITRE ATT&CK?

DefinitionMITRE ATT&CK is a free, public knowledge base maintained by MITRE that catalogs the tactics and techniques adversaries use in real-world attacks. It provides a common vocabulary to describe, detect and test attack behavior.

How it works

ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) organizes attacker behavior into a matrix. The columns are the tactics, the adversary's goal at each stage, such as initial access, persistence, lateral movement and exfiltration. Under each tactic are the techniques and sub-techniques that describe how that goal is achieved. Each technique has an identifier, such as T1566 for phishing, along with procedure examples, data sources useful for detecting it, and mitigations.

There are matrices for enterprise environments (Enterprise, covering operating systems, cloud and network), mobile devices and industrial control systems (ICS). The knowledge base also documents threat groups and malicious software, linking each to the techniques observed.

What it is used for

  • Detection coverage: mapping SOC rules against techniques shows what is visible and where the gaps are.
  • Threat hunting: techniques become hunting hypotheses.
  • Red, Blue and Purple Team: adversary emulation exercises use ATT&CK as a script and a common language between offense and defense.
  • Threat intelligence: campaign reports cite techniques by identifier, which makes comparison and prioritization easier.

ATT&CK vs Cyber Kill Chain

Lockheed Martin's Cyber Kill Chain describes the phases of an attack as a linear, high-level sequence. ATT&CK is far more granular and does not impose an order: an attacker can repeat tactics and skip stages. In practice, the Kill Chain helps explain an attack to management, while ATT&CK guides the technical work of detection and testing.

Network Secure offers a 24×7 SOC and MDR, as well as Red, Blue and Purple Team exercises.

Frequently asked questions

Is MITRE ATT&CK free?

Yes. The knowledge base is public and can be freely consulted and used by companies, vendors and researchers. It is maintained by MITRE, a US not-for-profit organization.

What is the difference between a tactic and a technique in ATT&CK?

A tactic is the attacker's goal at a given stage, such as gaining initial access. A technique is the means used to achieve it, such as sending a phishing email.

Go deeper