What Is the MITRE ATT&CK Framework?

Also called: MITRE ATT&CK, ATT&CK framework, Adversarial Tactics, Techniques and Common Knowledge

Related problems: Can't tell which attacks our security tools would actually detect; Every vendor claims full coverage and we can't compare them; Need a common language between our team, our MDR provider and testers; Don't know where to focus detection and testing effort

The MITRE ATT&CK framework is the shared reference security teams use to name attacker behavior, so that a detection rule, a threat report, a penetration test and a vendor’s coverage claim can all be compared in the same terms. Each behavior gets a standard name and ID, which lets a buyer check what a tool or provider covers and where the gaps are. Under the hood it is a free, public catalog arranged as a matrix of attacker goals (tactics) and the methods used to achieve them (techniques), with examples drawn from documented intrusions. The not-for-profit MITRE Corporation maintains it. ATT&CK stands for Adversarial Tactics, Techniques and Common Knowledge.

At a glance

  • ATT&CK catalogs attacker behavior: tactics (the why), techniques and sub-techniques (the how), plus the groups and malware seen using them.
  • Separate matrices cover enterprise IT, including cloud platforms, as well as mobile devices and industrial control systems.
  • It is a reference, not a compliance standard: organizations and products aren’t certified against it.
  • Vendors and providers often map their detections to it, which helps comparison but can be oversold.
  • It is free to use and updated over time as new attacker behavior is documented.

What problem it solves

Before shared frameworks, vendors and teams each described attacks in their own words. One product “stopped ransomware,” another “detected lateral movement,” and a buyer had no way to compare them or to see what was missing. Threat reports, test results and alerts used different terms for the same activity.

ATT&CK gives everyone one catalog. A threat report can say which techniques a group used, a detection rule can be labeled with the technique it catches, and a red teaming exercise can list the techniques it simulated. Putting those side by side shows where defenses are strong and where they are thin. It builds on the idea of tactics, techniques and procedures (TTPs): defending against attacker behavior is more durable than chasing indicators that change daily.

How it works

Tactics. Columns in the matrix represent attacker goals across an intrusion, such as initial access, execution, persistence, privilege escalation, credential access, lateral movement, exfiltration and impact.

Techniques and sub-techniques. Under each tactic are the methods attackers use, for example phishing for initial access or dumping credentials from memory. Each technique page explains the behavior, gives real-world examples, and suggests ways to detect and mitigate it.

Groups and software. ATT&CK records which known threat groups and malware families have been observed using which techniques, which helps cyber threat intelligence (CTI) teams focus on the threats most relevant to their industry.

How teams use it. Detection engineers tag rules in a security information and event management (SIEM) platform or EDR tool with technique IDs and build coverage maps. Threat hunting teams pick techniques to hunt for. Testers plan attack simulations by technique. A managed detection and response (MDR) provider or security operations center (SOC) can report incidents and coverage in the same terms.

When it matters for buyers

  • When comparing detection tools or MDR providers. Ask for coverage mapped to ATT&CK, then ask how coverage was measured.
  • When scoping a penetration test or red team. Agree on which techniques will be simulated and get results reported against them.
  • When reviewing a SOC’s performance. Coverage maps show which techniques have no detection at all, which is a useful planning view.
  • When reading vendor test claims. Published evaluation results are detailed and nuanced; marketing summaries of them often aren’t.
  • When prioritizing. Mapping the groups that target your industry to their techniques helps decide where to invest first.

Questions to ask vendors

  • Which ATT&CK techniques do your detections cover, and for which of our data sources?
  • How did you determine coverage: one rule per technique, or tested against multiple variations?
  • Which techniques do you not cover, and how do you suggest we handle them?
  • Do your alerts and incident reports include ATT&CK technique IDs?
  • If you took part in ATT&CK Evaluations, which configuration did you test, and does it match what we would buy?
  • Can you test our environment against the techniques used by groups that target our sector?

Our penetration testing advisors help buyers scope tests and compare detection coverage in ATT&CK terms.

How it differs from TTPs

Tactics, techniques and procedures (TTPs) is a general concept: a way of describing how attackers operate, at three levels of detail. MITRE ATT&CK is one specific, public catalog built on that concept, and the most widely used one. ATT&CK focuses on tactics and techniques; procedures, the exact steps a particular group takes, appear mainly as examples on each technique page. When a vendor says it “tracks TTPs,” it often means it maps activity to ATT&CK, but other catalogs and in-house taxonomies exist. ATT&CK is also different from attack-sequence models such as the cyber kill chain, which describe the stages of an intrusion at a higher level without cataloging individual techniques.

Frequently Asked Questions

What does ATT&CK stand for?
Adversarial Tactics, Techniques and Common Knowledge. Most people simply say "MITRE ATT&CK" or "the ATT&CK framework."
Is MITRE ATT&CK a compliance standard?
No. It is a reference catalog of attacker behavior, not a set of required controls. Organizations and products aren't certified as compliant with ATT&CK, although individual practitioners can earn MITRE's ATT&CK training certifications (offered under the ATT&CK Defender name). Compliance frameworks such as the NIST Cybersecurity Framework or ISO/IEC 27001 describe what a security program should include; ATT&CK describes what attackers do.
Does 100% ATT&CK coverage mean we are protected?
No. Coverage maps usually show whether a tool has at least one detection for a technique, not whether it catches every way that technique can be carried out. Coverage also depends on which data sources you actually send to the tool and how detections are tuned.
What are the MITRE ATT&CK Evaluations?
They are tests in which participating security vendors' products are run against emulated attacks and the results are published. They don't produce scores or rankings, so be wary of vendor marketing that presents them as a winner list, and read the detailed results for the scenarios relevant to you.
Do mid-sized companies need to use ATT&CK directly?
Usually not in depth. It is most useful as a shared vocabulary for asking providers what they detect, what testers simulated and where the gaps are. Your MDR provider, SOC or penetration tester should do the detailed mapping.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.