Skip to content
Oluma Cyber Security Awareness
Oluma Cyber Security
Framework Files · No. 13
Knowledge Base · Threat Intelligence

MITRE ATT&CK

A free, living encyclopedia of how real attackers operate — the shared language defenders use to map, detect, and test against actual adversary behavior.

By MITRE 3 Matrices 200+ Techniques Free & open
01 The Problem

Everyone described attacks differently

When a breach happened, every team described it in their own words. One analyst’s “lateral movement” was another’s “pivoting.” There was no shared vocabulary for how attackers actually behave — which made it nearly impossible to compare incidents, measure detection coverage, or learn across organizations.

Defenders knew attacks happened, but couldn’t easily answer: “Which specific attacker techniques can we actually detect — and which are we blind to?”

02 Why It Was Created

A common, evidence-based map of attacker behavior

MITRE ATT&CK is a free knowledge base that catalogs the real-world tactics and techniques attackers use, based on observed behavior. It gives the whole security community one shared language for describing — and defending against — how adversaries operate.

The core idea

Stop describing attacks in vague terms. Map them to a documented technique with a name and ID, so defenders everywhere can compare notes and measure coverage.

03 The Story Behind It

From a research experiment to a global standard

2013
Born from research
ATT&CK began inside MITRE as a project to document the behaviors seen in real intrusions.
2015
Released publicly
MITRE made the knowledge base free and open, and adoption spread fast across the industry.
Growth
Three matrices
It expanded to cover Enterprise IT and cloud, Mobile, and Industrial Control Systems.
2026
Always evolving
It’s continuously updated; recent releases added behavior-driven detection guidance and refined how evasion techniques are organized.
04 How It Works

Tactics across the top, techniques beneath

ATT&CK is laid out as a matrix. The columns are tactics — the attacker’s goals at each stage of an intrusion. Under each sit the techniques: the specific ways adversaries achieve that goal. The tactics roughly trace an attack’s lifecycle:

ReconnaissanceInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand & ControlExfiltrationImpact

Each technique links to real threat groups, the software they use, and suggested mitigations. There are three matrices — Enterprise, Mobile, and ICS — and a free tool called Navigator for visualizing your coverage.

05 Real-World Example

A SOC measures what it can actually see

A security operations team suspects it has blind spots but can’t prove where. They use ATT&CK as a measuring stick.

Turning a hunch into a map
Coverage you can see and improve
  • Map every existing detection rule to an ATT&CK technique
  • Color a Navigator chart — green for covered, red for gaps
  • Have the red team emulate a real threat group’s techniques
  • Prioritize new detections for the riskiest blind spots
  • Brief leadership in one shared, precise language

“We got hacked” becomes “the adversary used these specific techniques — and here’s our coverage.”

06 Who Uses It

The whole defensive community

🛡️
SOC & blue teams
Detection engineering, triage, and coverage mapping.
🎯
Red & purple teams
Emulating real adversaries to test defenses.
🔍
Threat intel
Tracking which groups use which techniques, in a shared format.

Security vendors map their products to it, and it pairs naturally with defensive catalogs and detection tooling.

complements MITRE D3FENDused in threat intelmaps to detections
07 Career Relevance

The lingua franca of threat work

For SOC, detection engineering, threat hunting, and incident response roles, ATT&CK fluency is expected. Job postings list it by name, and analysts speak in technique IDs daily.

Even in GRC, understanding ATT&CK helps you connect controls to the actual threats they’re meant to stop — turning compliance from box-ticking into real risk reduction.

08 Strengths & Challenges

Honest trade-offs

✦ Strengths

  • Free, open, and continuously updated
  • Grounded in real-world observations
  • A common language for the whole industry
  • Pinpoints detection gaps precisely

⚠ Challenges

  • Large and complex — hundreds of techniques
  • Descriptive, not prescriptive (it won’t tell you what to buy)
  • Takes real effort to operationalize
  • Coverage mapping can create a false sense of safety
09 Final Takeaway
ATT&CK is the shared map of how attackers operate.

It turns vague talk of “getting hacked” into a precise, comparable language of tactics and techniques — letting defenders measure what they can see, test against real adversaries, and finally speak the same words as the people trying to break in.

Rising together.Oluma Cyber Security · Framework Files
More frameworks in the series → the full catalogue