Skip to content
Cybersecurity · Glossary

MITRE ATT&CK

A publicly maintained knowledge base of adversary tactics, techniques, and procedures (TTPs) derived from real-world observations, used by detection engineers and threat hunters to model, detect, and communicate attacker behaviour.


What is MITRE ATT&CK?

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally recognised framework of adversary behaviour, maintained by MITRE Corporation from real-world threat intelligence. The framework organises attacker behaviour into tactics (high-level goals such as Persistence, Lateral Movement, Exfiltration) and techniques (specific methods used to achieve each tactic, such as T1566 Phishing or T1078 Valid Accounts). Each technique includes sub-techniques, procedure examples, detection guidance, and mitigation recommendations.

Detection engineers use ATT&CK to structure detection rule libraries — mapping each SIEM or XDR rule to the technique it detects, and using a 'heat map' view of coverage to identify gaps in the detection programme. A red team exercise against ATT&CK techniques reveals which attacker behaviours have no detective controls, enabling prioritised investment in detection engineering. Threat intelligence teams use ATT&CK to communicate about specific threat actor groups (APT29, FIN7) and their known TTP patterns.

AiRAT structures detection libraries using ATT&CK mappings across all client SOC deployments. The csoc platform uses ATT&CK tactic and technique tags on every alert — enabling security leads to view coverage heatmaps and prioritise detection investment based on the techniques most commonly used by threat actors relevant to their sector.


Examples in production

Detection coverage heatmap

ATT&CK Navigator heatmap showing detection coverage across 14 tactics and 196 techniques — highlighting Credential Access (T1003, T1110) as a gap prioritised for new SIEM rule development in Q2.

Threat actor profiling

Threat intelligence report mapping a FinTech-sector threat actor's observed TTPs to ATT&CK techniques, enabling the detection team to identify which techniques are already covered by existing rules and which require new detection logic.



Questions about MITRE ATT&CK

Is MITRE ATT&CK free to use?

Yes — MITRE ATT&CK is publicly available under a Creative Commons Attribution licence. The framework, ATT&CK Navigator (a heatmap visualisation tool), and ATT&CK Workbench (a tool for extending and customising the framework) are all freely available at attack.mitre.org. Commercial threat intelligence platforms add enrichment and automation on top of the public framework.

How do you map SIEM rules to ATT&CK?

Each detection rule should be tagged with the ATT&CK technique(s) it detects at the time of authoring. Sigma (an open detection rule format) includes ATT&CK tags as a standard field. This mapping enables coverage visualisation in ATT&CK Navigator, integration with threat intelligence platforms, and automated gap analysis when new threat intelligence identifies undetected techniques.

Running a system that uses MITRE ATT&CK?

We build production-grade cybersecurity systems for regulated enterprises.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →