MITRE ATT&CK
Also known as:ATT&CK
MITRE ATT&CK: Structures known tactics and techniques of real-world cyberattacks. This capability processes information about threats and attackers into an actionable format. Source evaluationSource EvaluationAssessment of a source's reliability, relevance, timeliness, and potential bias., context, currency, structured dissemination, and feedback into protective measures determine its utility.
How it works and where it fits
MITRE ATT&CK structures knowledge about potential adversaries, their objectives, capabilities, infrastructure, and observed behavior. Individual indicators are short-lived and easy to change, while behavioral patterns and technical relationships often have greater analytical value. Reporting should distinguish observed facts, assessments, and assumptions.
Practical security relevance
Practical use depends on source quality, timeliness, and relevance to the organization’s own attack surface. Information is prioritized, correlated with internal data, and converted into searches, detections, or safeguards. Investigation feedback continuously improves the assessment. Confidentiality and permitted sharing are as important as technical exchange formats.
Related concepts
- Tactics, Techniques and ProceduresTactics, Techniques and ProceduresDescription of the typical objectives, methods, and procedures of threat actors.: Description of the typical objectives, methods, and procedures of threat actors.
- Threat-Informed DefenseThreat-Informed DefenseAlignment of controls and tests with specific threats and attack techniques.: Alignment of controls and tests with specific threats and attack techniques.
- Threat EmulationThreat EmulationRealistic simulation of known attacker techniques to test defenses.: Realistic simulation of known attacker techniques to test defenses.
- Cyber Kill ChainCyber Kill ChainModel describing the successive phases of a cyberattack.: Model describing the successive phases of a cyberattack.