ATT&CK

Adversarial Tactics, Techniques & Common Knowledge

Wissensbasis gegnerischer Taktiken und Techniken

MITRE ATT&CK is an open, curated knowledge base of real adversary behaviour, organised by tactics (the „why“ of a step) and techniques (the „how“). It provides a common language to describe attacks, map detections and reveal gaps in one's own defence. ATT&CK is explicitly based on observed behaviour, not on theory.

History. ATT&CK arose at the non-profit MITRE Corporation from internal research into detecting real attacks and was made publicly available in the mid-2010s. Since then it has become the de-facto frame of reference for defenders and is continuously developed — alongside the Enterprise matrix there are dedicated matrices for Mobile and for industrial control systems.

Facts. The matrix arranges tactics as columns (such as initial access, persistence, privilege escalation, lateral movement, exfiltration) and fills them with techniques and sub-techniques, each with examples, observed actors and detection approaches. ATT&CK is neither a maturity model nor a checklist but a mapping tool: it shows which behaviours one can detect — and which one cannot.

Outlook & recommendation. The greatest benefit comes from systematically mapping one's own detection rules and incidents against ATT&CK and thus prioritising blind spots. Trying to cover everything leads nowhere; the sensible approach is to focus on the techniques typical of one's own sector and the relevant threat actors.

ATT&CK — Adversarial Tactics, Techniques & Common Knowledge