Bobby Liu.
← Security notebook

Reference note

MITRE ATT&CK

A common knowledge base for adversary tactics, techniques, and procedures observed in real attacks.

What ATT&CK captures

MITRE began ATT&CK in 2013 to document the tactics, techniques, and procedures used by advanced persistent threat groups against enterprise environments. The framework can be applied to any technology or software an attacker may target.

Reading the name

  • MITRE is the organization's name, not an acronym.
  • AT means Adversarial Tactics.
  • T means Techniques.
  • CK means Common Knowledge.

How the framework is organized

The Enterprise matrix follows the phases of an attack, from initial access through post-compromise activity. Tactics describe an adversary's goal, techniques describe how that goal may be achieved, and procedures describe observed real-world implementations.

How defenders use it

Organizations use ATT&CK to build threat models, evaluate security tools, develop detections, prioritize security investments, and share threat and defensive information using a common vocabulary.

Visual reference

Click an image to expand
MITRE ATT&CK Enterprise matrix