O Oluma Cyber Security Framework Files · No. 13 Knowledge Base · Threat Intelligence MITRE ATT&CK A free, living encyclopedia of how real attackers operate — the shared language defenders use to map, detect, and test against actual adversary behavior. By MITRE 3 Matrices 200+ Techniques Free & open ATT&CK how attackers operate How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem Everyone described attacks differently When a breach happened, every team described it in their own words. One analyst’s “lateral movement” was another’s “pivoting.” There was no shared vocabulary for how attackers actually behave — which made it nearly impossible to compare incidents, measure detection coverage, or learn across organizations. Defenders knew attacks happened, but couldn’t easily answer: “Which specific attacker techniques can we actually detect — and which are we blind to?” 02 Why It Was Created A common, evidence-based map of attacker behavior MITRE ATT&CK is a free knowledge base that catalogs the real-world tactics and techniques attackers use, based on observed behavior. It gives the whole security community one shared language for describing — and defending against — how adversaries operate. The core ideaStop describing attacks in vague terms. Map them to a documented technique with a name and ID, so defenders everywhere can compare notes and measure coverage. 03 The Story Behind It From a research experiment to a global standard 2013Born from researchATT&CK began inside MITRE as a project to document the behaviors seen in real intrusions. 2015Released publiclyMITRE made the knowledge base free and open, and adoption spread fast across the industry. GrowthThree matricesIt expanded to cover Enterprise IT and cloud, Mobile, and Industrial Control Systems. 2026Always evolvingIt’s continuously updated; recent releases added behavior-driven detection guidance and refined how evasion techniques are organized. 04 How It Works Tactics across the top, techniques beneath ATT&CK is laid out as a matrix. The columns are tactics — the attacker’s goals at each stage of an intrusion. Under each sit the techniques: the specific ways adversaries achieve that goal. The tactics roughly trace an attack’s lifecycle: ReconnaissanceInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand & ControlExfiltrationImpact Each technique links to real threat groups, the software they use, and suggested mitigations. There are three matrices — Enterprise, Mobile, and ICS — and a free tool called Navigator for visualizing your coverage. 05 Real-World Example A SOC measures what it can actually see A security operations team suspects it has blind spots but can’t prove where. They use ATT&CK as a measuring stick. Turning a hunch into a mapCoverage you can see and improve Map every existing detection rule to an ATT&CK technique Color a Navigator chart — green for covered, red for gaps Have the red team emulate a real threat group’s techniques Prioritize new detections for the riskiest blind spots Brief leadership in one shared, precise language “We got hacked” becomes “the adversary used these specific techniques — and here’s our coverage.” 06 Who Uses It The whole defensive community 🛡️SOC & blue teamsDetection engineering, triage, and coverage mapping. 🎯Red & purple teamsEmulating real adversaries to test defenses. 🔍Threat intelTracking which groups use which techniques, in a shared format. Security vendors map their products to it, and it pairs naturally with defensive catalogs and detection tooling. complements MITRE D3FENDused in threat intelmaps to detections 07 Career Relevance The lingua franca of threat work For SOC, detection engineering, threat hunting, and incident response roles, ATT&CK fluency is expected. Job postings list it by name, and analysts speak in technique IDs daily. Even in GRC, understanding ATT&CK helps you connect controls to the actual threats they’re meant to stop — turning compliance from box-ticking into real risk reduction. 08 Strengths & Challenges Honest trade-offs ✦ StrengthsFree, open, and continuously updatedGrounded in real-world observationsA common language for the whole industryPinpoints detection gaps precisely ⚠ ChallengesLarge and complex — hundreds of techniquesDescriptive, not prescriptive (it won’t tell you what to buy)Takes real effort to operationalizeCoverage mapping can create a false sense of safety 09 Final Takeaway ATT&CK is the shared map of how attackers operate.It turns vague talk of “getting hacked” into a precise, comparable language of tactics and techniques — letting defenders measure what they can see, test against real adversaries, and finally speak the same words as the people trying to break in.