Attackers rarely rely on a single tool or vulnerability—they follow patterns. The MITRE ATT&CK framework catalogs these patterns, mapping the tactics, techniques, and procedures (TTPs) adversaries use to compromise systems, move across networks, steal sensitive information, and disrupt business operations. Instead of focusing on malware families or individual vulnerabilities, the framework documents attacker behavior—what adversaries do at each stage of an attack.
Today, the framework has become one of the industry’s most widely adopted resources for threat detection, threat hunting, and security operations. Organizations of all sizes—from enterprise security teams to government agencies—use it to understand attacker behavior, improve defensive coverage, and prioritize cybersecurity investments.
What is the MITRE ATT&CK framework?
The MITRE ATT&CK framework is a publicly available cybersecurity knowledge base that documents real-world adversary behavior through tactics, techniques, and procedures (TTPs). Organizations use it to understand how attackers operate, improve threat detection, identify defensive gaps, and communicate cyber threats using a standardized language.
If you’ve ever wondered what the MITRE ATT&CK framework is and how it differs from a vulnerability database, consider it a playbook that documents how threat actors attack organizations. ATT&CK focuses on attacker behavior—what adversaries do before, during, and after compromising an environment—not on lists of malware families or software vulnerabilities.
ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge. The framework organizes a growing collection of observed attack behaviors into a structured format that security professionals use for threat detection, incident response, security testing, and threat intelligence. As of August 2026, ATT&CK documents include:
- 222 techniques and 475 sub-techniques
- 949 pieces of software used by adversaries
- 178 threat groups
- 59 tracked campaigns
This practical, evidence-based approach makes ATT&CK useful for organizations looking to strengthen their defenses against new and shifting threats.
A brief history and purpose of the MITRE ATT&CK framework
The MITRE ATT&CK framework was developed in 2013 as part of MITRE’s internal research into advanced persistent threats (APTs). Researchers wanted a consistent way to document attacker behavior across different campaigns and organizations. As the project expanded, MITRE made the framework publicly available, allowing security professionals worldwide to contribute observations and benefit from a shared knowledge base.
Today, ATT&CK is updated twice a year with techniques observed in real-world cyberattacks. In that way, it keeps pace with how attackers operate, making it one of the most trusted references in modern cybersecurity.
Why was the framework created?
The primary goals of the MITRE ATT&CK framework include:
- Creating a common language for security teams, researchers, and vendors.
- Improving behavior-based threat detection beyond malware signatures alone.
- Helping organizations identify defensive gaps across their environments.
- Supporting threat hunting and incident response with real-world adversary techniques.
- Improving cybersecurity collaboration through standardized terminology.
One of ATT&CK’s defining characteristics is that it documents observed attacker behavior, not just theoretical attack stages. The framework shifts the core question from “What malware is this?” to “What is the attacker trying to accomplish, and how are they doing it?”
This behavioral perspective allows organizations to detect attacks, even when adversaries change malware families or develop new tools.
How the MITRE ATT&CK framework is structured
Once you know how the framework is structured, it’s much easier to interpret the ATT&CK matrices and use them in everyday security operations. The framework organizes adversary behavior into 3 connected layers: tactics, techniques, and procedures.
Each layer provides answers to different questions about an attack:
- Why is the attacker acting?
- How do they accomplish their goal?
- How has this technique been used in real attacks?
Together, these components create a detailed map of threat actors’ behavior.
Tactics: the attacker’s objective
Within the framework, tactics represent why an attacker performs a particular action. Each tactic describes a specific objective during an intrusion, from gaining initial access to disrupting business operations.
The Enterprise ATT&CK Matrix currently includes tactics such as:
- Reconnaissance
- Resource Development
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Defense Impairment
- Stealth
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Command and Control
- Exfiltration
- Impact
For example, an attacker attempting to steal administrator credentials would be operating under the Credential Access tactic, while ransomware that encrypts files would fall under the Impact tactic.
Because tactics describe an attacker’s objectives, they provide valuable context during investigations. Security teams can better predict an attacker’s next steps based on the tactic they’re currently observing.
Techniques and sub-techniques: how attackers achieve their goals
While tactics explain why an attacker acts, the MITRE ATT&CK framework techniques explain how they accomplish their objectives. Each technique represents a specific method attackers use during an attack and is assigned a unique identifier, such as T1566 (Phishing) or T1003 (OS Credential Dumping).
As cyber threats have grown in scale, many techniques have been further divided into more specific sub-techniques. For example:
Technique: Phishing (T1566)
↓
Sub-techniques: Spearphishing Attachment (T1566.001) and Spearphishing Link (T1566.002)
This additional level of detail helps organizations create more precise detection rules, conduct focused threat hunts, and evaluate defensive coverage against increasingly specialized attack methods.
Procedures: how real attackers use techniques
Procedures represent the practical implementation of ATT&CK techniques during actual cyberattacks. While a technique describes a general method, a procedure shows how a specific threat actor carried it out using particular malware, infrastructure, delivery methods, and social engineering tactics.
The examples below show how 3 well-known groups have executed procedures across the ATT&CK matrix:
- APT29 (Cozy Bear)—attributed to Russia’s SVR; used spearphishing against government and NGO targets, including the 2021 USAID impersonation campaign flagged by CISA.
- FIN7—operated a fake pen-testing company called Combi Security to recruit operators and mailed weaponized USB drives disguised as Amazon and US HHS packages to targeted businesses.
- Lazarus Group—ran Operation Dream Job, using LinkedIn recruiter personas and fake job offers to target defense, aerospace, and (as of 2025) European drone manufacturers.
Documenting these procedures allows defenders to understand not only which techniques attackers prefer but also how they evolve their tactics over time.
Understanding the MITRE ATT&CK matrices
One of the most recognizable parts of the framework is the MITRE ATT&CK framework diagram—known as the matrix—a visual representation of attacker behavior that organizes tactics and techniques into an easy-to-navigate table.
Each column represents a tactic, while each row lists the techniques associated with that objective. Security teams often use the matrix to check defensive coverage, map alerts to attacker behavior, and spot detection gaps.
Rather than working as a linear attack timeline, the MITRE ATT&CK framework matrix reflects the reality that attackers frequently move between tactics, repeat techniques, or skip stages altogether depending on their objectives.

Enterprise Matrix
The Enterprise Matrix is the most widely used domain of the MITRE ATT&CK framework. It covers adversary behaviors targeting modern enterprise environments across:
- Windows
- macOS
- Linux
- Microsoft 365
- Google Workspace
- Cloud platforms
- Containers
- Network infrastructure
- Identity services
Because most organizations operate hybrid environments that combine on-premises systems with cloud infrastructure, the Enterprise Matrix has become a central resource for security operations centers (SOCs), incident responders, and threat hunters.
For example, if a security team detects PowerShell execution followed by credential dumping and lateral movement, each activity can be mapped to the corresponding ATT&CK technique. This provides a clearer picture of the attack progression and helps prioritize response efforts.
Mobile Matrix
The Mobile Matrix focuses on attacks targeting Android and iOS smartphones and tablets. Since these devices store corporate email, authentication tokens, business applications, and sensitive company data, they have become valuable targets for cybercriminals.
The Mobile Matrix documents techniques such as:
- Malicious mobile applications
- SMS phishing (smishing)
- Credential theft
- Abuse of mobile permissions
- Device exploitation
Organizations can use the matrix to strengthen mobile device security, improve mobile threat detection, and better understand attacks targeting remote employees.
ICS Matrix
The MITRE ATT&CK for ICS framework extends ATT&CK principles to industrial control systems (ICS) and operational technology (OT) environments.
ICS environments manage physical processes, such as manufacturing equipment, electrical grids, transportation systems, and water treatment facilities. Therefore, successful attacks can have physical as well as digital consequences.
The ICS Matrix documents techniques observed against:
- Programmable logic controllers (PLCs)
- Supervisory control and data acquisition (SCADA) systems
- Industrial networks
- Engineering workstations
- Field devices
As of April 2026, MITRE also introduced sub-techniques to the ICS Matrix, bringing it in line with the Enterprise and Mobile matrices and giving defenders more granular visibility into how attackers target operational technology.
Organizations responsible for critical infrastructure use this matrix to better understand threats to operational environments and improve cyber resilience across industrial systems.
How organizations use the MITRE ATT&CK framework
The MITRE ATT&CK framework is a practical tool for improving cybersecurity operations. Organizations use it to understand attacker behavior, strengthen their defenses, validate their security controls, and prepare for real-world threats.

Threat detection
Traditional security tools often rely on known malware signatures or predefined rules. The framework encourages a behavior-based approach by helping security teams spot suspicious activities associated with attacker techniques.
For example, an endpoint detection and response (EDR) platform might detect unusual PowerShell execution, credential dumping, and lateral movement across multiple systems. Individually, these events may seem unrelated. When mapped to ATT&CK techniques, however, they reveal a likely attack chain that security analysts can investigate more effectively.
Behavior-based detection also makes it easier to catch previously unseen malware because the focus stays on what attackers are doing, not simply which malware they’re using.
Threat hunting
Threat hunting involves proactively searching for indicators of compromise before automated security tools generate alerts. They investigate systems for behaviors commonly associated with adversaries—without waiting for an attack to trigger an alarm.
The MITRE ATT&CK framework gives threat hunters a structured catalog of techniques to investigate. This lets teams focus on specific behaviors, such as credential access, privilege escalation, or persistence mechanisms during their hunts.
For example, if threat intelligence reports that a ransomware group frequently abuses remote administration tools, defenders can proactively search enterprise systems for unusual usage of those applications—even if no alerts have been triggered.
Threat intelligence
Threat intelligence helps organizations understand who is targeting them, how attacks change, and which threats present the greatest risk.
The framework standardizes how threat intelligence is communicated. Analysts can reference specific ATT&CK tactics and techniques to describe adversary behavior precisely, replacing inconsistent terminology with a shared vocabulary.
For example, if intelligence reports indicate that a threat actor commonly uses Spearphishing Attachment (T1566.001) followed by Credential Dumping (T1003), defenders can immediately assess whether they have detections for these techniques.
This shared language also improves collaboration between organizations, security vendors, and incident response teams.
Adversary emulation and red teaming
Many organizations use the framework to simulate real-world attacks.
Red teams and penetration testers recreate adversary behavior by selecting ATT&CK techniques that reflect current threat activity. Where generic penetration tests probe for weaknesses in general, adversary emulation mimics the tactics of known threat groups to evaluate how well security controls detect and respond to real-world attacks.
For example, a red team may reproduce the techniques associated with a ransomware operation to determine whether endpoint security, identity controls, and incident response procedures can interrupt the attack before encryption occurs.
These exercises help organizations validate their defensive capabilities under realistic conditions.
Detection gap analysis
One of ATT&CK’s most useful applications is identifying security gaps.
Organizations can map their existing detection rules, endpoint security tools, and monitoring capabilities to the ATT&CK techniques to determine which adversary behaviors are currently covered and which are not.
For example, a security team may discover they can detect phishing attempts and malware execution, but lack visibility into credential theft or lateral movement. That insight helps prioritize future security investments and improve their overall defensive coverage.
Incident response
During a security incident, ATT&CK provides valuable context about attacker objectives and their likely next steps.
If investigators identify a technique related to persistence, they know attackers may attempt to regain access after initial containment. Likewise, observing credential access techniques may indicate a greater likelihood of lateral movement or privilege escalation.
Using ATT&CK during investigations helps incident response teams build a more complete picture of an intrusion while supporting faster and more informed remediation decisions.
How to implement the MITRE ATT&CK framework
Putting the framework to work doesn’t require replacing existing security tools. Organizations typically use it to improve how they evaluate, monitor, and strengthen their cybersecurity. The following steps offer a practical starting point.
Take inventory of your security controls
Begin by documenting the security technologies already in place, including endpoint protection, SIEM platforms, identity providers, firewalls, cloud security tools, and vulnerability management solutions.
This will make it easier to map them against ATT&CK techniques later.
Map detections to ATT&CK techniques
Many modern security vendors already align their alerts with the ATT&CK techniques. Organizations can map their detection rules, log sources, and security controls to the framework to understand which attacker behaviors are currently visible across their environment.
This process creates a clear picture of defensive coverage and helps security teams speak a common language when discussing threats.
Identify defensive gaps
After mapping existing detections, identify techniques that currently lack visibility or monitoring. Not every ATT&CK technique presents the same level of risk. Organizations should prioritize those most relevant to their industry, technology stack, and threat landscape.
Gap analysis helps security teams make informed decisions about where additional monitoring or tooling is needed.
Prioritize high-risk techniques
Trying to detect every ATT&CK technique at once will overwhelm most security teams. Start with behaviors associated with the most prevalent threats: credential theft, phishing, ransomware deployment, privilege escalation, and lateral movement.
These remain priorities for many organizations because they appear frequently across modern cyberattacks. Focusing on these high-impact techniques delivers meaningful security improvements while keeping the workload manageable.
Continuously test and improve
Cyber threats change all the time, and so does the ATT&CK framework.
Organizations should regularly review their defensive coverage through threat hunting, purple teaming, red team exercises, tabletop simulations, and incident reviews. These activities help confirm whether existing controls remain effective against new attacker techniques.
MITRE ATT&CK vs. other cybersecurity frameworks
The MITRE ATT&CK framework often complements other cybersecurity models, not replace them. While each framework focuses on a different aspect of cybersecurity, together they provide a more comprehensive understanding of attacks and defensive strategies.
Framework | Primary focus | Best used for |
|---|---|---|
MITRE ATT&CK | Real-world attacker behaviors | Threat detection, threat hunting, defensive validation |
Cyber Kill Chain | Stages of an attack | Understanding attack progression and prevention opportunities |
Diamond Model | Relationships between adversaries, infrastructure, capabilities, and victims | Threat intelligence and adversary analysis |
The Cyber Kill Chain, developed by Lockheed Martin, breaks cyberattacks into sequential stages—from reconnaissance through actions on objectives. It helps defenders understand where attacks can be disrupted before causing significant damage.
The Diamond Model of Intrusion Analysis focuses on the relationships between attackers, victims, infrastructure, and capabilities. Threat intelligence teams frequently use it to analyze campaigns and attribute attacks.
Compared with these models, the MITRE ATT&CK framework provides detailed behavioral information that supports day-to-day security operations.
Many mature security programs combine all 3 approaches: the Cyber Kill Chain explains the attack lifecycle, the Diamond Model helps analyze adversaries, and ATT&CK documents the techniques attackers use throughout an intrusion.
Benefits of the MITRE ATT&CK framework
The MITRE ATT&CK framework has become an industry standard because it offers practical benefits for organizations of all sizes. Some of its key advantages include:
- Establishes a common language for cybersecurity professionals.
- Documents real-world attacker behavior, not theoretical attack models.
- Supports behavior-based threat detection.
- Improves threat hunting by providing structured adversary techniques.
- Helps identify defensive gaps across security controls.
- Strengthens incident response and forensic investigations.
- Supports adversary emulation, penetration testing, and purple teaming.
- Freely available and continuously updated by MITRE.
- Widely supported by security vendors and enterprise security platforms.
- Helps organizations prioritize cybersecurity investments based on real-world threats.
Limitations of the MITRE ATT&CK framework
Although ATT&CK is a highly useful resource, it isn’t a complete cybersecurity solution.
To start, the framework documents attacker behavior but does not prevent attacks on its own. Organizations still need security controls, such as endpoint protection, identity security, network monitoring, and incident response capabilities.
Second, ATT&CK can appear overwhelming for organizations with limited security resources. With hundreds of techniques and sub-techniques, deciding where to begin may require the assistance of experienced professionals.
The framework also requires ongoing maintenance. Because MITRE continuously updates ATT&CK to reflect new adversary behaviors, organizations should regularly review mappings, detections, and defensive coverage.
Finally, ATT&CK works best when combined with other security frameworks, threat intelligence, and risk management practices. Used together, these resources provide a fuller understanding of both attacker behavior and organizational risk.
Request a free trial to see what attackers already know about your organization—from leaked credentials to exposed assets—before they can act on it.
Key takeaways
The MITRE ATT&CK framework gives organizations a practical, behavior-based approach to understanding modern cyber threats. Documenting the tactics, techniques, and procedures used in actual attacks helps security teams improve threat detection, guide threat hunting, strengthen incident response, and identify defensive gaps.
While ATT&CK is not a security solution on its own, it serves as a solid foundation for threat-informed defense. When combined with cyber threat intelligence, continuous monitoring, and proactive security practices, the framework helps organizations better anticipate adversary behavior and build more resilient cybersecurity programs.
