Glossary · simply explained

MITRE ATT&CK

MITRE ATT&CK is a freely available, continuously maintained knowledge base about the behaviour of real attackers: tactics describe the goal of a step (such as initial access, privilege escalation, exfiltration), techniques the concrete methods for it — substantiated with observed cases and known groups.

The practical value lies in the shared language: when detection rules, reports and exercises reference the same technique IDs, gaps become visible and discussions precise.

How do you use ATT&CK in practice?

Defenders lay their detection and protection measures over the matrix: which techniques do we cover, where are we blind? This coverage view prioritises investments better than any gut feeling. Threat intelligence teams describe attacker groups by their typical techniques; red teams build realistic exercise scenarios from them.

The right expectation matters: ATT&CK is a catalogue, not an action plan. Complete coverage is neither possible nor necessary — the point is to consciously address the techniques relevant to your own risk profile.

What teams use ATT&CK for

  • Gap analysis: assess and prioritise detection coverage per technique.
  • Threat-informed defence: align protection with attacker methods observed in the wild.
  • Purple team exercises: simulate attacks and verify detection technique by technique.
  • Classify reports and incidents consistently — internally and with providers.

Frequently asked questions about MITRE ATT&CK

What distinguishes tactics and techniques in ATT&CK?

Tactics are the goals of an attack step — gaining access, escalating privileges, exfiltrating data. Techniques are the concrete methods attackers use to achieve those goals, often refined with sub-techniques and substantiated with real cases.

Is ATT&CK the same as the cyber kill chain?

No: the kill chain describes the idealised sequence of an attack in phases, ATT&CK catalogues concrete techniques independent of a fixed order. The kill chain tells the story, ATT&CK provides the detailed vocabulary.

How does ATT&CK help with tool selection?

Vendors of EDR, NDR and SIEM increasingly map their detections to ATT&CK techniques. That makes offerings comparable: instead of marketing promises you can ask which techniques a product actually detects — and how to test that.

Can small teams use ATT&CK meaningfully?

Yes — pragmatically: identify the ten to twenty techniques most relevant to your environment (from reports about your industry, say) and verify detection and hardening for those. That is more valuable than attempting full coverage.

What is ATT&CK for ICS?

A dedicated matrix for industrial control systems: it describes techniques against OT environments — from manipulating control logic to suppressing alarms. For production environments it is the right frame of reference, not the enterprise matrix alone.

Want to put this into practice in your own network? Talk to KAEMI, aligned to your requirements and with a managed service from a single source.