MITRE ATT&CK
MITRE ATT&CK is the knowledge base of adversary tactics and techniques based on real-world observations. It’s the common language of modern cybersecurity: it connects offense, detection, hunting, and threat intelligence under one taxonomy.
Structure
Section titled “Structure”Tactics the WHY: the adversary's goal (matrix columns) TA0001 Initial Access, TA0002 Execution, ... TA0011 C2, TA0010 ExfiltrationTechniques the HOW: T#### (and sub-techniques T####.###) e.g. T1566 Phishing, T1055 Process Injection, T1003 Credential DumpingProcedures the concrete implementation by a specific group/malwareMatrices Enterprise (Win/Linux/macOS/Cloud), Mobile, ICSThe tactics (the attack flow)
Section titled “The tactics (the attack flow)”Reconnaissance -> Resource Development -> Initial Access -> Execution ->Persistence -> Privilege Escalation -> Defense Evasion -> Credential Access ->Discovery -> Lateral Movement -> Collection -> Command and Control ->Exfiltration -> Impact# every offensive card in this wiki maps to one or more of these tacticsUses of ATT&CK
Section titled “Uses of ATT&CK”Detection map rules to techniques -> measure COVERAGE, not count rules (def-deteccion)Hunting form hypotheses per technique (def-hunting)CTI describe actors' TTPs in a standardized way (cti-informes)Red/Purple plan and emulate TTPs; validate defenses (Atomic Red Team, CALDERA)Gap analysis ATT&CK Navigator: visualize what's covered and the gapsATT&CK Navigator and coverage mapping
Section titled “ATT&CK Navigator and coverage mapping”- color the matrix by detection coverage / a given actor's techniques- overlay layers: "what I detect" vs "what adversary X uses" -> priority gaps- DeTT&CT to assess visibility quality per log sourceGroups and software
Section titled “Groups and software”- ATT&CK catalogs Groups (e.g. APT29, FIN7) and Software (malware/tools)- each group lists the techniques it uses -> basis for emulation and prioritization- threat-informed defense: defend based on what the REAL adversaries of your sector doBlue Team / operation
Section titled “Blue Team / operation”- Use ATT&CK as the lingua franca between CTI, SOC, hunting, and red team.
- Measure coverage with Navigator and close gaps prioritizing by relevant actor (CTI fundamentals).
- Map detections (Detection & logging), hunts (Threat hunting), and reports (Intelligence reporting) to T####.
- Validate coverage with emulation (Atomic Red Team / CALDERA), don’t assume it.
Real-world cases
Section titled “Real-world cases”- ATT&CK-based adversary emulation (e.g. of APT29) is standard purple-team practice.
- CTI reports across the industry describe campaigns in terms of ATT&CK techniques.
- The ATT&CK Navigator is the de facto tool for detection gap analysis.
Testing checklist
Section titled “Testing checklist”- Understand tactics vs techniques vs procedures
- Map the TTPs of the actor(s) relevant to your sector
- Map your detections to techniques (Navigator)
- Identify coverage gaps and prioritize them
- Assess visibility per source (DeTT&CT)
- Validate with emulation (Atomic Red Team/CALDERA)
- Use ATT&CK as the language in reports (Intelligence reporting)