GRC Careers

HomeResourcesMITRE ATT&CK

CS-008 · Foundations

MITRE ATT&CK

A shared knowledge base of the tactics and techniques attackers actually use.

Executive Summary

MITRE ATT&CK is a freely available knowledge base that describes how attackers behave, organized into tactics (their goals) and techniques (how they achieve them). It is based on observed real-world activity and gives defenders a common language for describing, detecting, and comparing adversary behavior. It has become a standard reference across the security industry.

What It Is

MITRE ATT&CK is a structured catalog of adversary behavior maintained by the nonprofit MITRE. It is organized as a matrix where columns are tactics, the objectives an attacker pursues such as initial access, persistence, privilege escalation, and exfiltration, and the entries beneath each are techniques and sub-techniques, the specific ways those objectives are achieved. Each technique includes descriptions, real-world examples, detection ideas, and mitigations. Because it is grounded in observed activity rather than theory, teams use it to describe what attackers actually do rather than what they might do in the abstract. It is free to use and widely adopted.

Why It Matters

Before a shared framework existed, teams described attacks in inconsistent, private language, which made it hard to compare incidents, measure coverage, or share intelligence. ATT&CK gives everyone the same vocabulary. Defenders use it to map their detection coverage, find gaps, and prioritize improvements. Threat intelligence teams use it to describe actors consistently. Red teams use it to plan realistic tests, and blue teams use it to verify they can see those tests. For professionals, familiarity with ATT&CK is now a common expectation in security operations, detection engineering, threat intelligence, and increasingly in governance and risk roles.

How It Works

A team typically starts by identifying which techniques are most relevant to their environment and likely adversaries. They then map their existing detections and controls to those techniques, often visualizing coverage as a heat map across the matrix. Gaps reveal where an attacker could operate unseen, guiding where to build new detections or add mitigations. During an incident, analysts tag observed behavior with technique identifiers so the activity can be understood and shared consistently. Red and purple team exercises use ATT&CK to design attacks and confirm that defenses detect them. The framework is updated regularly as new adversary behavior is observed.

Architecture Diagram

Tactics: the attacker's goals, such as initial access and exfiltration
Techniques: specific ways each goal is achieved
Sub-techniques: finer-grained variations
Coverage mapping: match detections to techniques
Gaps: techniques with no detection or mitigation
Tactics are the columns (attacker goals) and techniques sit beneath each, forming a matrix defenders map coverage against.

Visual Workflow

Identify the tactics and techniques most relevant to your environment and adversaries.Map current detections and controls to those techniques.Visualize coverage to see where detection is strong and where it is missing.Prioritize and build detections or mitigations for the biggest gaps.Tag incident and intelligence data with technique identifiers for consistency.Validate coverage with red or purple team exercises and update over time.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

ATT&CK Navigator
Free tool to visualize and annotate coverage on the matrix
SIEM and detection platforms
Where detections mapped to techniques are built and run
Breach and attack simulation tools
Test whether techniques are detected
Threat intelligence platforms
Describe actors using ATT&CK techniques consistently

Industry Standards

MITRE ATT&CK
The knowledge base itself, a de facto industry standard
MITRE D3FEND
Companion knowledge base of defensive countermeasures
NIST Cybersecurity Framework (CSF) 2.0
Detect and Respond outcomes that ATT&CK helps operationalize

Career Relevance

MITRE ATT&CK is essential for SOC analysts, detection engineers, threat hunters, threat intelligence analysts, and red teamers. GRC analysts and risk professionals increasingly use it to describe threats and measure defensive coverage. Knowing how to map, test, and communicate coverage with ATT&CK is a strong differentiator in security operations interviews.

Interview Questions

Related Certifications

CompTIA CySA+ GIAC Cyber Threat Intelligence (GCTI) CompTIA Security+

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Is MITRE ATT&CK free to use?

Yes. It is publicly available and free to use, which is a major reason it became so widely adopted across the security industry.

How is a tactic different from a technique?

A tactic is the attacker's goal, such as gaining persistence. A technique is a specific method used to achieve that goal. One tactic usually has many techniques beneath it, and techniques can have finer sub-techniques.

How does ATT&CK relate to the cyber kill chain?

The kill chain describes the broad ordered stages of an intrusion. ATT&CK provides the detailed techniques that occur within those stages. Many teams use the kill chain for high-level framing and ATT&CK for technique-level detail.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA CySA+GIAC Cyber Threat Intelligence (GCTI)CompTIA Security+

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: MITRE ATT&CK
  3. Go deeper: Cybersecurity
  4. Go deeper: Threat Actors
  5. Validate it: work toward CompTIA CySA+
  6. Find the role: browse current openings

Related sheets

More in Foundations

Share this LinkedIn Facebook X Email