Skip to content

MITRE ATT&CK

MITRE ATT&CK is the knowledge base of adversary tactics and techniques based on real-world observations. It’s the common language of modern cybersecurity: it connects offense, detection, hunting, and threat intelligence under one taxonomy.

Tactics the WHY: the adversary's goal (matrix columns)
TA0001 Initial Access, TA0002 Execution, ... TA0011 C2, TA0010 Exfiltration
Techniques the HOW: T#### (and sub-techniques T####.###)
e.g. T1566 Phishing, T1055 Process Injection, T1003 Credential Dumping
Procedures the concrete implementation by a specific group/malware
Matrices Enterprise (Win/Linux/macOS/Cloud), Mobile, ICS
Reconnaissance -> Resource Development -> Initial Access -> Execution ->
Persistence -> Privilege Escalation -> Defense Evasion -> Credential Access ->
Discovery -> Lateral Movement -> Collection -> Command and Control ->
Exfiltration -> Impact
# every offensive card in this wiki maps to one or more of these tactics
Detection map rules to techniques -> measure COVERAGE, not count rules (def-deteccion)
Hunting form hypotheses per technique (def-hunting)
CTI describe actors' TTPs in a standardized way (cti-informes)
Red/Purple plan and emulate TTPs; validate defenses (Atomic Red Team, CALDERA)
Gap analysis ATT&CK Navigator: visualize what's covered and the gaps
- color the matrix by detection coverage / a given actor's techniques
- overlay layers: "what I detect" vs "what adversary X uses" -> priority gaps
- DeTT&CT to assess visibility quality per log source
- ATT&CK catalogs Groups (e.g. APT29, FIN7) and Software (malware/tools)
- each group lists the techniques it uses -> basis for emulation and prioritization
- threat-informed defense: defend based on what the REAL adversaries of your sector do
  • Use ATT&CK as the lingua franca between CTI, SOC, hunting, and red team.
  • Measure coverage with Navigator and close gaps prioritizing by relevant actor (CTI fundamentals).
  • Map detections (Detection & logging), hunts (Threat hunting), and reports (Intelligence reporting) to T####.
  • Validate coverage with emulation (Atomic Red Team / CALDERA), don’t assume it.
  • ATT&CK-based adversary emulation (e.g. of APT29) is standard purple-team practice.
  • CTI reports across the industry describe campaigns in terms of ATT&CK techniques.
  • The ATT&CK Navigator is the de facto tool for detection gap analysis.
  • Understand tactics vs techniques vs procedures
  • Map the TTPs of the actor(s) relevant to your sector
  • Map your detections to techniques (Navigator)
  • Identify coverage gaps and prioritize them
  • Assess visibility per source (DeTT&CT)
  • Validate with emulation (Atomic Red Team/CALDERA)
  • Use ATT&CK as the language in reports (Intelligence reporting)