Reference note
MITRE ATT&CK
A common knowledge base for adversary tactics, techniques, and procedures observed in real attacks.
What ATT&CK captures
MITRE began ATT&CK in 2013 to document the tactics, techniques, and procedures used by advanced persistent threat groups against enterprise environments. The framework can be applied to any technology or software an attacker may target.
Reading the name
- MITRE is the organization's name, not an acronym.
- AT means Adversarial Tactics.
- T means Techniques.
- CK means Common Knowledge.
How the framework is organized
The Enterprise matrix follows the phases of an attack, from initial access through post-compromise activity. Tactics describe an adversary's goal, techniques describe how that goal may be achieved, and procedures describe observed real-world implementations.
How defenders use it
Organizations use ATT&CK to build threat models, evaluate security tools, develop detections, prioritize security investments, and share threat and defensive information using a common vocabulary.