MITRE ATT&CK (Adversarial Tactics, Techniques and Common Knowledge) is a free, globally used knowledge base of real-world attacker behaviour, organised into tactics and techniques.
How ATT&CK is structured
The non-profit MITRE Corporation started ATT&CK in 2013 and published it in 2015. It is built from public reports on real intrusions. The framework contains several matrices – Enterprise (Windows, Linux, macOS, cloud, network devices), Mobile and ICS for industrial systems.
- Tactics describe the attacker’s goal at a given moment – the “why”: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact and others.
- Techniques and sub-techniques describe the “how”, each with an ID: for example T1566 Phishing or T1059 Command and Scripting Interpreter.
- Entries for groups and software list which APT groups and malware families use which techniques, with sources.
Why ATT&CK matters
ATT&CK has become the common language of security teams:
- Detection engineering – mapping SIEM and EDR rules to techniques shows coverage gaps.
- Threat intelligence – reports describe adversaries in ATT&CK terms, making them comparable and actionable.
- Threat hunting and red teaming – hypotheses and emulation plans are built around specific techniques.
- Product evaluation – MITRE’s ATT&CK Evaluations test how security products detect emulated real attacks.
Compared with the high-level kill chain, ATT&CK is far more detailed and covers what attackers do after getting in.
Best practices
Do not try to cover every technique at once. Prioritise the techniques used by groups that target your sector, measure detection coverage with tools such as ATT&CK Navigator and update the mapping as the framework evolves.