🚀 CloudSEK featured in the 2026 Frost Radar™!
Read more
The MITRE ATT&CK Framework is a publicly available knowledge base that continuously documents how real attackers plan, execute, and maintain cyberattacks, built from observed incidents and not from theory. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge, and MITRE Corporation maintains it across three technology domains: Enterprise, Mobile, and ICS.
It organizes attacker behavior into four layers of increasing specificity, which gives security teams a shared, behavior-based vocabulary for detection engineering, threat hunting, incident response, and red and purple teaming.
Check the publication date on any ATT&CK reference before relying on it, because the tactic list changed in 2026. Version 19 retired Defense Evasion and split it into two tactics, and most guidance still in circulation has not caught up.
ATT&CK breaks real intrusions into discrete attacker actions, documented in a consistent structure so similar behavior is recognizable across unrelated attacks. Four layers run from broad intent down to a specific observed implementation.

A worked example runs the full chain. Credential Access is the tactic, OS Credential Dumping is the technique, LSASS Memory is the sub-technique, and a named malware family's specific implementation of that dump is the procedure. This structure lets one alert be traced back to a recognizable category of attacker intent. The same structure sits behind how tactics, techniques, and procedures are described more broadly.
Enterprise ATT&CK now contains 15 tactics, 222 techniques, and 475 sub-techniques. Version 19, released on 28 April 2026, brought the most significant structural change in the framework's history: Defense Evasion was retired and replaced by two tactics scoped to adversary intent.

Treating the split as a rename breaks things quietly. Existing detection mappings, dashboards, and coverage reports that reference the old structure now point at something different, and several technique IDs no longer resolve at all.
Defense Evasion had grown into a catch-all holding two unrelated behaviors. Hiding inside legitimate activity and dismantling the tooling that would spot it call for entirely different responses, and grouping them meant one alert category covered wildly different levels of urgency. Stealth now covers hiding. Defense Impairment covers breaking.
T1562 Impair Defenses was the most significant casualty. MITRE merged T1562, T1562.001, and T1562.006 into a new parent technique, T1685 Disable or Modify Tools. The remaining sub-techniques were revoked and reissued under new IDs inside Defense Impairment. Any rule, report, or coverage map referencing a T1562 sub-technique needs checking against MITRE's published crosswalk.
Most former Defense Evasion techniques landed in Stealth or Defense Impairment. A smaller number left the space entirely, moving to Lateral Movement, Privilege Escalation, or Execution where they fit more accurately. Some techniques now map to both new tactics, because adversary intent is not always clean.
TA0005 still exists as an ID, and it now denotes Stealth, not Defense Evasion. Remapping has to work from technique-to-tactic associations in the v19 data, not from a bulk rename of every rule tagged Defense Evasion. Teams that skip the crosswalk end up with coverage maps that look complete and are not.
ATT&CK is organized into matrices by technology domain, so techniques can be analyzed in the context where they are actually used.
Covers techniques used against corporate IT environments: credential access, lateral movement, command execution, and data exfiltration against operating systems, identity services, email, and enterprise applications. Platforms include Windows, macOS, Linux, Office Suite, Identity Provider, SaaS, IaaS, Network Devices, Containers, and ESXi.
Mobile ATT&CK addresses compromise of smartphones and tablets. It documents application-based attacks, device exploitation, surveillance, and persistence mechanisms suited to mobile sandboxing constraints.
ICS ATT&CK addresses industrial and operational technology environments. It documents manipulation of control logic, disruption of physical processes, and interference with safety systems, focusing on reliability, availability, and physical impact over data theft.
Cloud does not form a separate top-level domain, despite plenty of published guidance saying so. MITRE defines Enterprise, Mobile, and ICS as the three technology domains, and represents cloud attacker behavior through platforms inside Enterprise ATT&CK such as SaaS, IaaS, Identity Providers, and Office Suite.
Each technique below shows how an ID translates into a detection opportunity and a mitigation.
Day-to-day use clusters into eight applications, and they share one property. Each replaces a tool-specific metric with a behavior-based one.
Mapping turns ATT&CK from a reference document into an ongoing measurement of posture. CISA publishes best practice guidance for ATT&CK mapping. One detail there is worth adopting immediately: use versioned permalinks for every technique reference, so links survive framework changes like the v19 restructure.
Navigator works as a free visualization tool, overlaying security data onto ATT&CK's tactics and techniques. Detections, adversary activity, and simulation results become color-coded layers, which makes coverage gaps and overlaps far easier to spot than reviewing raw logs or spreadsheets.
Teams create a layer for an assessment, select the relevant scope, color-code techniques by detection status, then export or share the result. Layered views communicate posture to both technical teams and leadership using attacker behavior as the reference point, not tool-specific metrics. That is why Navigator appears in most threat modeling and purple-team exercises.
These four models get compared constantly, and they answer different questions. Choosing between them is the wrong framing, since most mature programs run more than one.
The Kill Chain comparison matters most in practice. Kill Chain describes a sequence and assumes attacks progress through it in order. ATT&CK describes a catalog of behaviors that appear in any order, repeat, or get skipped, which reflects how advanced persistent threat campaigns actually unfold.
An indicator of compromise (IOC) is an artifact the attacker leaves behind: a file hash, a command-and-control address, a suspicious domain. ATT&CK describes behavior, meaning the tactics and techniques used whatever tools or infrastructure the attacker rotates through.
Deployment is fast for indicators, and they expire just as fast. Behavior-based detections take longer to build and stay relevant as infrastructure changes. The two work together and not in competition, with indicators handling immediate triage and ATT&CK supporting durable detection inside a threat detection and response program.
Adoption runs close to universal across security operations, so the limitations deserve stating as plainly as the benefits.
Adoption is nearly universal across security operations, and that ubiquity hides five constraints worth stating plainly before a program is built around the framework.
A technique ID becomes useful when it is attached to somebody actually using it against a given sector. CloudSEK Threat Intelligence tracks threat actors, their tactics and procedures, exploited vulnerabilities, and active campaigns, then scopes that activity to an organization's industry and region. Mapped to ATT&CK, the output answers a narrower question than the matrix alone can. Which of these 222 techniques are in use right now by the groups targeting this sector?
Yes. ATT&CK is publicly available at no cost, and the underlying data is published under a license permitting commercial use with attribution.
MITRE Corporation, a not-for-profit that operates federally funded research and development centers in the United States. MITRE is a name, not an acronym.
Twice a year in major releases, with interim updates between them. Each major version can add, revoke, or restructure techniques and tactics.
No. No regulation mandates it directly, and several frameworks and auditors reference it as evidence of threat-informed defense.
A companion knowledge base cataloging defensive countermeasures. ATT&CK describes attacker behavior, while D3FEND describes the controls that counter it.
Yes. Scoping to the techniques relevant to one industry and threat model makes it workable without the resources of a large SOC.
No. Engenuity runs vendor product evaluations using ATT&CK techniques. The framework itself is vendor-neutral and separate from those tests.
