The MITRE ATT&CK Enterprise Matrix showing tactics across the top and techniques listed beneath each tactic

A structured map of how attackers operate

MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations of how attackers actually behave. It catalogues what adversaries do once they’re inside your environment — from initial access through to data exfiltration.

The framework is organised as a matrix: tactics run across the top (the attacker’s goals at each stage), and techniques sit beneath each tactic (the specific methods they use to achieve those goals). This gives your team a structured, shared vocabulary for describing threats and measuring your defensive coverage.

Talk to us about ATT&CK mapping

Why it matters

How ATT&CK helps your team defend what counts.

Track the techniques attackers are using against you — Map incidents and alerts to ATT&CK techniques to build a picture of which adversary behaviours are hitting your organisation. Over time, this shows you patterns and priorities — so you know exactly where to strengthen your defences.
Share intelligence across your industry — If you’re part of a CTI sharing community — an ISAC, sector CERT, or trusted group — you can pool ATT&CK-mapped data to see what’s targeting your peers. This lets you protect yourself against threats you haven’t seen yet, using real data from organisations facing the same adversaries.
Build detection and prevention rules that matter — Once you know the most common techniques targeting your sector, you can develop monitoring, detection, and prevention rules that specifically target them. Tailoring your existing controls to detect and prevent the attacks you are likely to see makes the most use of your current investment.
Figure out where your gaps are — Knowing the attack tactics and techniques you are likely to see will let you understand where your gaps are. You can then target your future security investment where you will get the best results.

Turn threat intelligence into targeted defences

Most organisations collect threat intelligence but struggle to act on it. ATT&CK bridges that gap by giving you a structured way to map what you know about adversaries to the specific controls and detections you need. The result: your defensive investment goes where it counts.

Diagram showing how ATT&CK techniques map to detection and prevention controls

How we run an ATT&CK engagement

We work with your team to map your environment against ATT&CK, identify gaps, and build a practical roadmap for improving your detection and prevention capabilities.

Step 01
Understand your environment — We start by understanding your infrastructure, tooling, and current detection capabilities so we can tailor the ATT&CK mapping to your actual environment.
Step 02
Map your coverage — We map your existing detections, logs, and controls against ATT&CK techniques to show where you have coverage and where the gaps are.
Step 03
Prioritise by threat profile — Using threat intelligence relevant to your sector, we identify which ATT&CK techniques are most likely to be used against you and prioritise accordingly.
Step 04
Build your roadmap — We deliver a prioritised roadmap of detection and prevention improvements, with practical guidance your team can act on immediately.
ATT&CK Navigator screenshot showing a matrix of tactics and techniques with a colour-coded heatmap overlay
Book an ATT&CK engagement
Cosive
Why work with us

ATT&CK expertise you can trust

ATT&CK and VERIS framework specialists — we help teams classify threats, map detections, and build structured security incident vocabularies
Deep SecOps experience across international CERTs and managed security providers — our team has worked in and with security operations centres around the world
Co-designers of Australia’s national threat intelligence program, CTIS — applying ATT&CK mapping at national scale
A team of senior security practitioners — you work directly with experienced consultants who’ve spent their careers building and running security operations
Chris Horsley presenting at AUSCERT
Cosive co-founder Chris Horsley presenting at AUSCERT.

Common questions about the ATT&CK Framework

Where can I find more information about the ATT&CK Framework?

The best starting point is attack.mitre.org, which hosts the full ATT&CK knowledge base including all tactics, techniques, and threat group profiles. The ATT&CK documentation covers how the framework is structured and maintained. For hands-on exploration, the ATT&CK Navigator tool lets you create custom heatmaps and coverage layers.

How is ATT&CK different from CAPEC?

CAPEC (Common Attack Pattern Enumeration and Classification) catalogues attack patterns at a higher abstraction level — describing general categories of attack. ATT&CK focuses on observed adversary behaviour and TTPs in real-world intrusions, providing much more specific and actionable detail about how attackers operate in practice.

How is ATT&CK different from CVE and CWE?

CVE identifies specific vulnerabilities in software, while CWE classifies types of software weaknesses. ATT&CK describes what attackers do after exploiting vulnerabilities — the tactics and techniques they use to move through your environment, escalate privileges, and achieve their objectives. They’re complementary, not competing: CVE/CWE tell you what’s vulnerable, ATT&CK tells you what adversaries do next.

How is ATT&CK different from Lockheed Martin’s Cyber Kill Chain?

The Cyber Kill Chain describes attack phases at a high level across seven stages — from reconnaissance through to actions on objectives. ATT&CK provides much more granular detail within each phase, with hundreds of specific techniques mapped to real threat groups. Think of the Kill Chain as a high-level narrative and ATT&CK as the detailed playbook beneath it.

How is ATT&CK different from the Diamond Model?

The Diamond Model describes the relationships between four core features of an intrusion: adversary, capability, infrastructure, and victim. It’s a framework for structuring intelligence analysis. ATT&CK provides the detailed technique taxonomy that you’d map into a Diamond Model analysis — specifically populating the “capability” vertex with granular, observed adversary behaviours.

Abstract geometric pattern of intersecting metal beams

Start using the ATT&CK Framework

Tell us about your environment and goals, and we’ll show you how ATT&CK mapping can strengthen your defences.