MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations of how attackers actually behave. It catalogues what adversaries do once they’re inside your environment — from initial access through to data exfiltration.
The framework is organised as a matrix: tactics run across the top (the attacker’s goals at each stage), and techniques sit beneath each tactic (the specific methods they use to achieve those goals). This gives your team a structured, shared vocabulary for describing threats and measuring your defensive coverage.
How ATT&CK helps your team defend what counts.
Most organisations collect threat intelligence but struggle to act on it. ATT&CK bridges that gap by giving you a structured way to map what you know about adversaries to the specific controls and detections you need. The result: your defensive investment goes where it counts.
We work with your team to map your environment against ATT&CK, identify gaps, and build a practical roadmap for improving your detection and prevention capabilities.
The best starting point is attack.mitre.org, which hosts the full ATT&CK knowledge base including all tactics, techniques, and threat group profiles. The ATT&CK documentation covers how the framework is structured and maintained. For hands-on exploration, the ATT&CK Navigator tool lets you create custom heatmaps and coverage layers.
CAPEC (Common Attack Pattern Enumeration and Classification) catalogues attack patterns at a higher abstraction level — describing general categories of attack. ATT&CK focuses on observed adversary behaviour and TTPs in real-world intrusions, providing much more specific and actionable detail about how attackers operate in practice.
CVE identifies specific vulnerabilities in software, while CWE classifies types of software weaknesses. ATT&CK describes what attackers do after exploiting vulnerabilities — the tactics and techniques they use to move through your environment, escalate privileges, and achieve their objectives. They’re complementary, not competing: CVE/CWE tell you what’s vulnerable, ATT&CK tells you what adversaries do next.
The Cyber Kill Chain describes attack phases at a high level across seven stages — from reconnaissance through to actions on objectives. ATT&CK provides much more granular detail within each phase, with hundreds of specific techniques mapped to real threat groups. Think of the Kill Chain as a high-level narrative and ATT&CK as the detailed playbook beneath it.
The Diamond Model describes the relationships between four core features of an intrusion: adversary, capability, infrastructure, and victim. It’s a framework for structuring intelligence analysis. ATT&CK provides the detailed technique taxonomy that you’d map into a Diamond Model analysis — specifically populating the “capability” vertex with granular, observed adversary behaviours.
Tell us about your environment and goals, and we’ll show you how ATT&CK mapping can strengthen your defences.