Skip to main content
Category: Threat Intelligence & Simulation

MITRE ATT&CK

Also known as: ATT&CK, MITRE ATT&CK Framework, Adversarial Tactics, Techniques, and Common Knowledge
Simply put

MITRE ATT&CK is a freely available, regularly updated knowledge base that catalogs the tactics and techniques attackers use, based on real-world observations of cyber incidents. Security teams use it as a common reference to understand adversary behavior and to plan how they will detect or stop those behaviors. It is a reference model rather than a piece of software or a security service.

Formal definition

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base of adversary tactics and techniques derived from real-world observations, organized as a matrix that maps tactics (an adversary's objectives, such as initial access or exfiltration) against the techniques and sub-techniques used to achieve them. Threat hunters, defenders, and red teamers reference it to model adversary behavior, assess detection and defensive coverage, structure threat intelligence, and inform detection engineering and adversary emulation. It is descriptive and continuously maintained rather than prescriptive, and it does not by itself provide controls, tooling, or guaranteed defensive outcomes; its value in an engagement depends on how well an organization operationalizes the model against its own environment, telemetry, and threat profile.

Why it matters

MITRE ATT&CK gives security teams a shared vocabulary for describing how attackers actually behave. Rather than discussing threats in vague or inconsistent terms, defenders, threat hunters, and red teamers can reference a common matrix of tactics and techniques based on real-world observations. This shared reference reduces ambiguity when teams communicate about adversary activity, plan detection strategies, or evaluate where their defensive coverage may have gaps.

For organizations engaging security leadership, ATT&CK matters because it turns an abstract question, "are we prepared for the threats that face us?", into a structured, examinable one. A security program can map its existing detections and controls against specific techniques to see what it can plausibly detect or stop and where blind spots remain. Because the knowledge base is freely available and continuously updated, it also lets smaller organizations benefit from a globally maintained view of adversary behavior without building that intelligence from scratch.

It is important to be realistic about what ATT&CK does and does not provide. It is a descriptive knowledge base, not software, a security service, or a set of prescriptive controls. Mapping to ATT&CK does not by itself detect or stop anything, nor does it guarantee any defensive outcome. Its value depends entirely on how well an organization operationalizes the model against its own environment, telemetry, and threat profile, which typically requires deliberate effort and appropriate tooling.

Who it's relevant to

Security and Threat Detection Teams
Defenders and threat hunters use ATT&CK to model adversary behavior, structure threat intelligence, and identify where their detection coverage is strong or weak. This supports detection engineering by tying specific detections back to the techniques they are meant to catch.
Red Teams and Adversary Emulation
Red teamers reference ATT&CK to plan and structure adversary emulation exercises against realistic techniques observed in the wild, helping organizations test how their defenses respond to specific attacker methods rather than generic scenarios.
Virtual and Fractional CISOs
A virtual or fractional CISO may use ATT&CK as a governance and communication tool to frame an organization's threat exposure and to assess defensive coverage at a strategic level. In this advisory capacity, the vCISO typically directs how the model is applied and interpreted rather than performing the hands-on detection engineering or emulation work, which usually remains with operational teams or is separately contracted. The value of this framing depends on the organization's maturity, its available telemetry, and stakeholder cooperation in operationalizing the model.
Security Leaders and Buyers
Executives and those evaluating security investments benefit from ATT&CK as a way to ask specific, examinable questions about coverage rather than relying on vague assurances. It is worth remembering that ATT&CK is a reference model and not a product or service, so mapping to it should be understood as a starting point for improvement, not a guarantee of protection.

Inside ATT&CK

Tactics
The adversary's high-level objectives or the 'why' behind an action, such as initial access, persistence, privilege escalation, or exfiltration. Tactics represent the columns of the ATT&CK matrix and organize techniques by goal rather than by tool.
Techniques and Sub-techniques
The 'how' an adversary achieves a tactical objective. Techniques describe specific methods, while sub-techniques provide more granular variations of a given technique. These form the core cells of the ATT&CK matrix.
Procedures
The specific, in-the-wild implementations of techniques observed for particular threat actors or malware. Procedures illustrate concrete examples of how a technique has been carried out in real intrusions.
Matrices
Structured views of tactics and techniques organized by technology domain, such as Enterprise, Mobile, and industrial control systems (ICS). Each matrix reflects adversary behavior relevant to that environment.
Groups and Software
Catalogued threat actor groups and associated malware or tools, mapped to the techniques they have been observed using. These support threat intelligence and adversary emulation activities.
Mitigations
Defensive measures and configurations associated with techniques, intended to help organizations reduce the likelihood or impact of specific adversary behaviors. Mitigations are guidance rather than guarantees of prevention.
Data Sources and Detections
References to the log sources, telemetry, and observable events that can help detect specific techniques, supporting detection engineering and gap analysis.

Common questions

Answers to the questions practitioners most commonly ask about ATT&CK.

Does a virtual CISO use MITRE ATT&CK to actively hunt threats or run detection operations for us?
Generally not as a hands-on function. A virtual CISO advises on how MITRE ATT&CK can inform your detection strategy, threat modeling, and control prioritization, but the operational work of threat hunting, tuning detections, or monitoring a SOC typically falls outside a standard vCISO scope. Those tasks are usually performed by internal security operations staff or a managed detection provider. A vCISO may help you evaluate whether your operational teams are using ATT&CK effectively and where coverage gaps exist, but the execution itself is normally out of scope unless explicitly contracted. Treating ATT&CK adoption as something the vCISO personally performs conflates governance-level guidance with operational security functions.
If we map our controls to MITRE ATT&CK, does that mean we are compliant or protected against breaches?
No. MITRE ATT&CK is a knowledge base of adversary tactics and techniques, not a compliance standard or a certification, and it does not map directly to frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, or CMMC. Mapping controls to ATT&CK can help you reason about coverage against known adversary behaviors, but it does not guarantee regulatory compliance and it does not prevent breaches. A virtual CISO can help you use ATT&CK to identify potential detection and control gaps, yet accountability for security decisions and outcomes generally remains with your organization and its officers. The value of any ATT&CK-informed effort depends heavily on organizational maturity, quality of underlying telemetry, and how the findings are acted upon.
How might a virtual CISO incorporate MITRE ATT&CK into a security program?
In many engagements, a vCISO uses ATT&CK as a reference to structure conversations about threat exposure, prioritize investments, and communicate risk to executives and boards in terms of adversary behavior rather than tool features. This often includes advising on which techniques are most relevant to your industry and environment, helping frame detection and response priorities, and guiding how internal or third-party teams should apply the framework. The specific approach may vary by provider and by the maturity of the client organization. The vCISO typically directs and advises on this integration rather than performing the underlying technical implementation.
What organizational conditions make ATT&CK-informed guidance from a vCISO effective?
Effectiveness typically depends on several factors: sufficient security maturity to act on identified gaps, access to relevant telemetry and logging so that technique coverage can be assessed, cooperation from operational and IT stakeholders, and a clearly defined engagement scope. In lower-maturity organizations, a vCISO may recommend foundational work before ATT&CK-based analysis delivers meaningful value, since mapping techniques against nonexistent or immature controls tends to produce limited insight. As with most vCISO deliverables, the outcome relies on client access, stakeholder engagement, and follow-through on recommendations.
Who is responsible for acting on the gaps a vCISO identifies through ATT&CK?
Responsibility for remediation and implementation generally sits with the client organization's internal teams or contracted operational providers, while the vCISO advises on prioritization and direction. It is important to separate the advisory role from accountability: a virtual CISO can recommend which technique-related gaps to address first and help build the roadmap, but the organization and its officers usually retain accountability for decisions, resourcing, and the resulting security posture. Contracts should clarify these boundaries so that expectations about who executes changes are explicit.
Can ATT&CK guidance from a vCISO help with framework or compliance efforts like NIST CSF or SOC 2?
It can support readiness efforts, but it does not replace them. A vCISO may use ATT&CK to enrich risk assessments and detection planning in ways that complement compliance frameworks, since understanding adversary behavior can strengthen the rationale behind certain controls. However, ATT&CK is distinct in purpose from compliance frameworks and certifications; supporting readiness for NIST CSF, SOC 2, or similar standards is a separate activity that a vCISO may assist with, but ATT&CK usage alone does not assert or produce certification. The degree of overlap and how the two are combined may vary by provider and engagement scope.

Common misconceptions

MITRE ATT&CK is a compliance framework or certification standard that an organization can be certified against, similar to ISO 27001 or SOC 2.
ATT&CK is a knowledge base of adversary tactics and techniques, not a certifiable standard or regulatory requirement. It informs defensive strategy and threat modeling, but there is no formal certification, and mapping to ATT&CK does not by itself demonstrate compliance with any regulation.
Mapping security controls to ATT&CK guarantees that an organization can prevent or detect the associated attacks.
Coverage against a technique in the matrix indicates that a mitigation or detection capability has been considered or deployed, not that it will reliably stop a real adversary. Effectiveness depends on implementation quality, tuning, telemetry availability, and organizational maturity, and coverage claims should be qualified accordingly.
A virtual CISO or security leader who references ATT&CK is performing hands-on detection engineering, threat hunting, or SOC operations.
In many engagements a vCISO uses ATT&CK at the governance and strategy level, such as guiding threat-informed program priorities and evaluating coverage gaps. The hands-on operational work of building detections, running the SOC, or executing threat hunts is typically out of scope unless explicitly contracted, and accountability for security decisions generally remains with the client organization.

Best practices

Use ATT&CK to build a threat-informed view of your program by prioritizing tactics and techniques most relevant to your industry, technology environment, and observed adversary groups rather than attempting to address the entire matrix at once.
Map existing detections and mitigations to specific techniques to identify coverage gaps, but document coverage in qualified terms that distinguish 'capability exists' from 'reliably detects or prevents.'
Select the matrix that matches your environment, such as Enterprise, Mobile, or ICS, so that the tactics and techniques you assess reflect the systems you actually operate.
Tie ATT&CK-based analysis to available data sources and telemetry, confirming that the logs needed to detect a technique are actually being collected before claiming detection coverage.
Keep governance and accountability clear when a security leader or vCISO drives ATT&CK-informed decisions, ensuring the client organization understands it retains responsibility for security outcomes and resourcing.
Revisit ATT&CK mappings periodically, since the knowledge base evolves and adversary behavior changes, and treat prior assessments as point-in-time rather than permanent.