MITRE ATT&CK

framework · cybersecurity · organizing-schema

Globally accessible knowledge base of adversary tactics, techniques, and procedures based on real-world observations.

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is the comprehensive knowledge base of adversary behavior maintained by MITRE Corporation, structuring observed real-world attacks into a taxonomy of tactics (the 'why' — adversary objectives like Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact) and techniques (the 'how' — specific methods like Phishing, Spearphishing Attachment, PowerShell execution, Pass the Hash, Kerberoasting). The framework was first released publicly in 2015 and has substantially evolved through annual updates. ATT&CK is divided into matrices for different domains: Enterprise (Windows, macOS, Linux, cloud platforms, containers, network); Mobile (iOS, Android); ICS (Industrial Control Systems). Each technique includes detection guidance, mitigation suggestions, real-world incident references, and links to threat actor groups using the technique. The framework is widely used in threat intelligence (mapping observed adversary activity), security operations (designing detection rules aligned to ATT&CK techniques), red teaming (simulating realistic attacker behavior), and threat modeling (anticipating likely attack paths). MITRE complements ATT&CK with related frameworks: D3FEND (defensive countermeasures), CAR (Cyber Analytics Repository), CALDERA (automated adversary emulation). Empirical foundation in observed real-world attacks distinguishes ATT&CK from theory-based frameworks like Cyber Kill Chain. Substantial commercial adoption — virtually all enterprise security tools now claim ATT&CK alignment, with varying fidelity.

Originators

MITRE Corporation; substantial federal funding and public-interest mission high

Year / Decade

2013 (initial internal development); 2015 (public release); ongoing annual updates high

Primary sources

MITRE Corporation (ongoing). ATT&CK Knowledge Base at attack.mitre.org, Strom, B.E. et al. (2018). 'MITRE ATT&CK: Design and Philosophy', ongoing MITRE blog posts and research publications high

Band notes

Knowledge base structure rather than a prescriptive control framework; widely used as reference and threat-modeling input.

Core components

Primary use case

Threat intelligence and adversary behavior analysis; security operations (SOC playbook development, detection rule alignment); red team and purple team exercises; threat modeling and risk assessment; foundation for substantial commercial security tooling (SIEM, EDR, XDR vendors all claim ATT&CK alignment); reference framework in security operations education; integration with cyber threat intelligence platforms; basis for many security-program maturity assessments; influence on security investment prioritization.

Common criticisms

Lineage

Siblings
Cyber Kill Chain, Diamond Model of Intrusion Analysis