ATT&CK

Last reviewed:

ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a framework developed by MITRE Corporation to document and track tactics and techniques used by cyber adversaries. It serves as a comprehensive knowledge base for understanding the behavior of threat actors and is widely used by cybersecurity professionals for threat modeling, detection, and response. As of October 2023, ATT&CK is recognized as a critical tool in the cybersecurity industry, aiding organizations in enhancing their security posture by providing a structured approach to analyze and mitigate cyber threats.

Overview

The MITRE ATT&CK Framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It is designed to help organizations understand the actions of threat actors and improve their cybersecurity defenses. The framework categorizes adversary behavior into tactics, techniques, and procedures (TTPs), providing a detailed view of how attackers operate. ATT&CK is widely used for threat intelligence, security operations, and risk management, offering a common language for cybersecurity professionals to communicate and collaborate effectively.

How it works

The ATT&CK framework is organized into several matrices, each representing a different domain of adversarial behavior. The most well-known is the Enterprise matrix, which focuses on techniques used against enterprise IT environments. Each matrix is divided into columns representing tactics, which are the adversary's goals during an attack. Under each tactic, specific techniques describe how adversaries achieve these goals. Techniques may also have sub-techniques that provide additional granularity.

For example, the tactic of lateral movement involves techniques that allow attackers to move through a network to access additional resources. Each technique in the framework is documented with detailed descriptions, examples, and references to real-world incidents. This structured approach helps organizations identify potential vulnerabilities and develop strategies to detect and mitigate attacks.

Applications

ATT&CK is used in various cybersecurity applications, including threat intelligence, detection and response, and security assessments. Organizations use the framework to map their security controls against known adversary techniques, identify gaps, and prioritize improvements. Security teams can also use ATT&CK to simulate attacks and test their defenses, enhancing their ability to detect and respond to real-world threats.

The framework is also valuable for threat intelligence analysis, allowing analysts to categorize and compare adversary behavior. By understanding the TTPs used by threat actors, organizations can develop more effective threat intelligence and improve their overall security posture.

Limitations

While ATT&CK is a powerful tool, it has limitations. The framework is based on publicly available information and may not cover all possible adversary behaviors. Additionally, the framework's focus on known techniques means it may not account for novel or emerging threats. Organizations should use ATT&CK as part of a broader cybersecurity strategy, combining it with other tools and methodologies to address these limitations.

Furthermore, the framework requires regular updates to remain relevant, and organizations must invest time and resources to keep their implementations current. Despite these challenges, ATT&CK remains an essential resource for understanding and mitigating cyber threats.

ATT&CK Framework Overview

Distribution of Tactics in ATT&CK Framework

See also

Sources

Categories: Techniques | Tools
Last updated: September 8, 2026