MITRE ATT&CK
MITRE ATT&CK is a freely available, regularly updated knowledge base that catalogs the tactics and techniques attackers use, based on real-world observations of cyber incidents. Security teams use it as a common reference to understand adversary behavior and to plan how they will detect or stop those behaviors. It is a reference model rather than a piece of software or a security service.
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base of adversary tactics and techniques derived from real-world observations, organized as a matrix that maps tactics (an adversary's objectives, such as initial access or exfiltration) against the techniques and sub-techniques used to achieve them. Threat hunters, defenders, and red teamers reference it to model adversary behavior, assess detection and defensive coverage, structure threat intelligence, and inform detection engineering and adversary emulation. It is descriptive and continuously maintained rather than prescriptive, and it does not by itself provide controls, tooling, or guaranteed defensive outcomes; its value in an engagement depends on how well an organization operationalizes the model against its own environment, telemetry, and threat profile.
Why it matters
MITRE ATT&CK gives security teams a shared vocabulary for describing how attackers actually behave. Rather than discussing threats in vague or inconsistent terms, defenders, threat hunters, and red teamers can reference a common matrix of tactics and techniques based on real-world observations. This shared reference reduces ambiguity when teams communicate about adversary activity, plan detection strategies, or evaluate where their defensive coverage may have gaps.
For organizations engaging security leadership, ATT&CK matters because it turns an abstract question, "are we prepared for the threats that face us?", into a structured, examinable one. A security program can map its existing detections and controls against specific techniques to see what it can plausibly detect or stop and where blind spots remain. Because the knowledge base is freely available and continuously updated, it also lets smaller organizations benefit from a globally maintained view of adversary behavior without building that intelligence from scratch.
It is important to be realistic about what ATT&CK does and does not provide. It is a descriptive knowledge base, not software, a security service, or a set of prescriptive controls. Mapping to ATT&CK does not by itself detect or stop anything, nor does it guarantee any defensive outcome. Its value depends entirely on how well an organization operationalizes the model against its own environment, telemetry, and threat profile, which typically requires deliberate effort and appropriate tooling.
Who it's relevant to
Inside ATT&CK
Common questions
Answers to the questions practitioners most commonly ask about ATT&CK.