MITRE ATT&CK Framework
The globally adopted knowledge base of adversary tactics and techniques for cyber defence.
What it is
About MITRE ATT&CK Framework
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a freely available, community-maintained knowledge base that categorises the tactics, techniques, and sub-techniques used by real threat actors against enterprise, mobile, and cloud environments. Organised as a matrix where columns represent adversary goals (initial access, execution, persistence, privilege escalation, defence evasion, credential access, discovery, lateral movement, collection, exfiltration, impact) and cells contain specific techniques with examples from documented malware campaigns, it gives security teams a common language for describing attack behaviour. Security operations centre (SOC) analysts, red teams, threat intelligence analysts, and security architects use ATT&CK as a reference for detection engineering (mapping alerts to techniques), threat hunting (proactively searching for technique evidence), red team exercise planning (ensuring realistic simulation of known adversary behaviour), and gap analysis (assessing which techniques the organisation has no detection coverage for). ATT&CK Navigator — the free interactive matrix tool — allows teams to visualise their detection coverage against specific threat actor groups.
What you can do with it
Capabilities
Look up a specific technique (e.g. T1059 Command and Scripting Interpreter) and identify its sub-techniques and mitigations.
Map a security incident's observed behaviours to ATT&CK techniques to build a kill chain narrative.
Use ATT&CK Navigator to visualise which techniques a threat actor group is known to use.
Perform a gap analysis by overlaying your SIEM detection rules against the ATT&CK matrix to identify uncovered techniques.
Plan a red team exercise using ATT&CK to simulate a specific threat actor's known TTPs (Tactics, Techniques, and Procedures).
How to learn it
Learning Resources
MITRE ATT&CK Getting Started at attack.mitre.org/resources/getting-started — free official guide
ATT&CK Navigator — free interactive tool at mitre-attack.github.io/attack-navigator — best way to explore the matrix practically
CISA (Cybersecurity & Infrastructure Security Agency) free advisory reports that map threats to ATT&CK — at cisa.gov
Blue Team Labs Online (blueteamlabs.online) — free and paid labs structured around ATT&CK technique detection
Pro Tip
Start with a specific threat actor group relevant to your sector (use ATT&CK Groups) rather than trying to cover the entire matrix — a focused adversary simulation exercise using 10–15 realistic techniques delivers more detection improvement than an unfocused broad coverage review.
Skills that use this tool
Roles that use this tool