What Is the MITRE ATT&CK Framework? Tactics & Matrix (v19)

The MITRE ATT&CK Framework is a public knowledge base documenting how real attackers operate, organized into tactics, techniques, and sub-techniques.
Published on
Monday, September 21, 2026
Updated on
September 21, 2026

The MITRE ATT&CK Framework is a publicly available knowledge base that continuously documents how real attackers plan, execute, and maintain cyberattacks, built from observed incidents and not from theory. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge, and MITRE Corporation maintains it across three technology domains: Enterprise, Mobile, and ICS.

It organizes attacker behavior into four layers of increasing specificity, which gives security teams a shared, behavior-based vocabulary for detection engineering, threat hunting, incident response, and red and purple teaming.

Check the publication date on any ATT&CK reference before relying on it, because the tactic list changed in 2026. Version 19 retired Defense Evasion and split it into two tactics, and most guidance still in circulation has not caught up.

How Does the MITRE ATT&CK Framework Work?

ATT&CK breaks real intrusions into discrete attacker actions, documented in a consistent structure so similar behavior is recognizable across unrelated attacks. Four layers run from broad intent down to a specific observed implementation.

how mitre attack framework works
  • Tactic: the attacker's objective at a given stage, which answers why an action appears where it does in an intrusion.
  • Technique: the general method used to achieve that objective. One objective is reachable through several techniques, so attackers switch methods when one gets blocked.
  • Sub-technique: how the same behavior varies in execution, such as dumping credentials from memory versus extracting them from system files. These produce different artifacts, and precise detections align to a sub-technique more closely than to the parent.
  • Procedure: the real-world implementation observed in a specific incident or attributed to a specific group. This is the most concrete layer.

A worked example runs the full chain. Credential Access is the tactic, OS Credential Dumping is the technique, LSASS Memory is the sub-technique, and a named malware family's specific implementation of that dump is the procedure. This structure lets one alert be traced back to a recognizable category of attacker intent. The same structure sits behind how tactics, techniques, and procedures are described more broadly.‍

What Are the MITRE ATT&CK Tactics in v19?

Enterprise ATT&CK now contains 15 tactics, 222 techniques, and 475 sub-techniques. Version 19, released on 28 April 2026, brought the most significant structural change in the framework's history: Defense Evasion was retired and replaced by two tactics scoped to adversary intent.

what are mitre attack matrices
  • Reconnaissance: gathering information on targets, exposed services, or users before any direct engagement, commonly from dark web sources.
  • Resource Development: acquiring infrastructure such as domains, servers, or accounts to support later operations.
  • Initial Access: establishing a foothold through phishing, exploitation, or abuse of a trusted relationship.
  • Execution: running malicious code to activate malware payloads or interact directly with compromised systems.
  • Persistence: establishing mechanisms that survive reboots, updates, and credential changes.
  • Privilege Escalation: gaining higher permissions to reach restricted systems or sensitive resources.
  • Stealth (TA0005, new in v19): blending in through behavioral camouflage, such as living-off-the-land techniques or masquerading as legitimate processes. Defenses remain running and simply fail to notice.
  • Defense Impairment (TA0112, new in v19): actively disabling or degrading security tools, logging pipelines, and trust controls. MITRE describes it as breaking security mechanisms so defenders cannot see or trust what is happening.
  • Credential Access: stealing authentication material, including leaked credentials, to support broader access and lateral movement.
  • Discovery: mapping the internal environment, including network layout, system roles, and user relationships.
  • Lateral Movement: moving between systems to expand control, which extends the attack path through the environment.
  • Collection: gathering valuable data such as documents, databases, or proprietary information.
  • Command and Control: maintaining communication with attacker infrastructure for coordination and data transfer.
  • Data Exfiltration: moving collected data out of the environment.
  • Impact: disrupting, destroying, or manipulating systems and data to achieve strategic or operational goals.

What ATT&CK v19 Changes and What It Breaks

Treating the split as a rename breaks things quietly. Existing detection mappings, dashboards, and coverage reports that reference the old structure now point at something different, and several technique IDs no longer resolve at all.

The Distinction Behind the Split

Defense Evasion had grown into a catch-all holding two unrelated behaviors. Hiding inside legitimate activity and dismantling the tooling that would spot it call for entirely different responses, and grouping them meant one alert category covered wildly different levels of urgency. Stealth now covers hiding. Defense Impairment covers breaking.

Technique IDs That No Longer Resolve

T1562 Impair Defenses was the most significant casualty. MITRE merged T1562, T1562.001, and T1562.006 into a new parent technique, T1685 Disable or Modify Tools. The remaining sub-techniques were revoked and reissued under new IDs inside Defense Impairment. Any rule, report, or coverage map referencing a T1562 sub-technique needs checking against MITRE's published crosswalk.

Techniques That Moved Elsewhere

Most former Defense Evasion techniques landed in Stealth or Defense Impairment. A smaller number left the space entirely, moving to Lateral Movement, Privilege Escalation, or Execution where they fit more accurately. Some techniques now map to both new tactics, because adversary intent is not always clean.

What This Means in Practice

TA0005 still exists as an ID, and it now denotes Stealth, not Defense Evasion. Remapping has to work from technique-to-tactic associations in the v19 data, not from a bulk rename of every rule tagged Defense Evasion. Teams that skip the crosswalk end up with coverage maps that look complete and are not.

What Is the MITRE ATT&CK Matrix?

ATT&CK is organized into matrices by technology domain, so techniques can be analyzed in the context where they are actually used.

Enterprise

Covers techniques used against corporate IT environments: credential access, lateral movement, command execution, and data exfiltration against operating systems, identity services, email, and enterprise applications. Platforms include Windows, macOS, Linux, Office Suite, Identity Provider, SaaS, IaaS, Network Devices, Containers, and ESXi.

Mobile

Mobile ATT&CK addresses compromise of smartphones and tablets. It documents application-based attacks, device exploitation, surveillance, and persistence mechanisms suited to mobile sandboxing constraints.

ICS

ICS ATT&CK addresses industrial and operational technology environments. It documents manipulation of control logic, disruption of physical processes, and interference with safety systems, focusing on reliability, availability, and physical impact over data theft.

Where Cloud Fits

Cloud does not form a separate top-level domain, despite plenty of published guidance saying so. MITRE defines Enterprise, Mobile, and ICS as the three technology domains, and represents cloud attacker behavior through platforms inside Enterprise ATT&CK such as SaaS, IaaS, Identity Providers, and Office Suite.

MITRE ATT&CK Framing Examples

Each technique below shows how an ID translates into a detection opportunity and a mitigation.

  • T1003.001, OS Credential Dumping: LSASS Memory: an attacker extracts credentials from LSASS process memory on a Windows host. Detection comes from unusual process access to lsass.exe. Mitigation is Credential Guard and restricted debug privileges.
  • T1566, Phishing: a spoofed email carries a malicious link or attachment to gain initial access, and an adversary-in-the-middle variant relays the login live. Detection comes from gateway analysis, user reports, and anomalous link-click telemetry. Mitigation is awareness training, attachment sandboxing, and DMARC enforcement.
  • T1059.001, Command and Scripting Interpreter: PowerShell: an attacker runs commands or downloads payloads post-compromise. Detection comes from script-block logging and command-line telemetry. Mitigation is constrained language mode and execution policy enforcement.
  • T1021, Remote Services: valid credentials, obtained through a brute force attack, move an attacker between systems over RDP, SSH, or SMB. Detection comes from correlating authentication logs across hosts. Mitigation is segmentation, credential hygiene, and MFA on internal services.

How Do Security Teams Use the MITRE ATT&CK Framework?

Day-to-day use clusters into eight applications, and they share one property. Each replaces a tool-specific metric with a behavior-based one.

  • Detection engineering: ATT&CK highlights behaviors that should be observable, which helps engineers prioritize detections covering multiple threats with minimal overlap.
  • Threat hunting: hunters search for attacker behavior that exists without triggering alerts, which is where threat analysis work begins.
  • Incident response: responders track attacker progress through tactics and anticipate likely next steps, coordinated through the security operations workflow.
  • Threat intelligence: analysts map actor behavior to a shared taxonomy, which lets campaigns and adversaries be compared using the same reference points. Threat intelligence feeds ship ATT&CK mappings commonly for this reason.
  • Adversary emulation: red teams replay techniques associated with known groups to model realistic threats in place of generic penetration tests.
  • Purple teaming: offensive and defensive teams use one reference during simulated attacks, which focuses exercises on validating detection against real behavior.
  • Coverage mapping: controls are compared against ATT&CK so behavioral blind spots become visible where common attacker actions lack monitoring.
  • Control validation: teams verify whether tools detect the behaviors they claim to cover, which shifts evaluation from vendor feature lists to measured outcomes.

How to Map Security Controls to the MITRE ATT&CK Framework

Mapping turns ATT&CK from a reference document into an ongoing measurement of posture. CISA publishes best practice guidance for ATT&CK mapping. One detail there is worth adopting immediately: use versioned permalinks for every technique reference, so links survive framework changes like the v19 restructure.

  1. Identify relevant techniques. Prioritize techniques associated with the organization's industry, threat model, and known adversaries, not the full matrix.
  2. Inventory available telemetry. Establish which logs, alerts, and data sources exist for each technique before assessing coverage.
  3. Map existing detections. Tie current rules and alerts to specific technique IDs, using the parent technique alongside any sub-technique reference.
  4. Classify the gaps. Separate techniques with no detection, techniques with weak telemetry, techniques detected but never investigated, and techniques with no mitigation in place. These four categories call for different fixes.
  5. Prioritize by exposure. Focus first on high-risk techniques relevant to the actual environment and threat landscape, not on filling the matrix evenly.
  6. Validate and do not assume. Confirm coverage actually fires as expected. A mapped technique does not equal an effective detection, and this step is where most coverage claims fail.

What Is MITRE ATT&CK Navigator?

Navigator works as a free visualization tool, overlaying security data onto ATT&CK's tactics and techniques. Detections, adversary activity, and simulation results become color-coded layers, which makes coverage gaps and overlaps far easier to spot than reviewing raw logs or spreadsheets.

Teams create a layer for an assessment, select the relevant scope, color-code techniques by detection status, then export or share the result. Layered views communicate posture to both technical teams and leadership using attacker behavior as the reference point, not tool-specific metrics. That is why Navigator appears in most threat modeling and purple-team exercises.

MITRE ATT&CK vs Cyber Kill Chain vs NIST CSF vs D3FEND

These four models get compared constantly, and they answer different questions. Choosing between them is the wrong framing, since most mature programs run more than one.

Aspect MITRE ATT&CK Cyber Kill Chain NIST CSF D3FEND
Main Focus Adversary behavior Attack stages Cybersecurity risk Defensive techniques
Structure Matrix-based, non-linear Linear and sequential Functions and categories Countermeasure taxonomy
Orientation Detection and response Prevention, mostly pre-compromise Governance and risk Defensive engineering
Granularity Deep, down to sub-techniques Broad stages only Program level Technique level
Post-Compromise View Strong across the full intrusion Limited Not applicable Mitigation-focused
Typical Users SOC teams, hunters, detection engineers Executives, risk planners, architects Whole security program Security architects

The Kill Chain comparison matters most in practice. Kill Chain describes a sequence and assumes attacks progress through it in order. ATT&CK describes a catalog of behaviors that appear in any order, repeat, or get skipped, which reflects how advanced persistent threat campaigns actually unfold.

MITRE ATT&CK vs Indicators of Compromise

An indicator of compromise (IOC) is an artifact the attacker leaves behind: a file hash, a command-and-control address, a suspicious domain. ATT&CK describes behavior, meaning the tactics and techniques used whatever tools or infrastructure the attacker rotates through.

Deployment is fast for indicators, and they expire just as fast. Behavior-based detections take longer to build and stay relevant as infrastructure changes. The two work together and not in competition, with indicators handling immediate triage and ATT&CK supporting durable detection inside a threat detection and response program.

Benefits and Limitations of the MITRE ATT&CK Framework

Adoption runs close to universal across security operations, so the limitations deserve stating as plainly as the benefits.

Limitations of the MITRE ATT&CK Framework

Adoption is nearly universal across security operations, and that ubiquity hides five constraints worth stating plainly before a program is built around the framework.

  • It is a reference model, not a control framework: ATT&CK documents what attackers do. It prescribes no controls, sets no requirements, and does not constitute a security program on its own.
  • A mapping proves nothing about a detection: tying a rule to a technique ID says the rule exists. Whether it fires against the real behavior is a separate question, and this is where most coverage claims fail.
  • Coverage mapping decays into a checkbox: treated as a one-time project, the map ages out. Treated as a recurring measurement, it stays useful.
  • Techniques need environment-specific context: the same technique looks different across Windows, cloud, and industrial infrastructure, so a generic detection rarely transfers between them.
  • The framework itself changes: the v19 restructure invalidated technique IDs that detection content had referenced for years. Mappings need periodic review against the current version.

Applying the MITRE ATT&CK Framework to Live Threat Intelligence

A technique ID becomes useful when it is attached to somebody actually using it against a given sector. CloudSEK Threat Intelligence tracks threat actors, their tactics and procedures, exploited vulnerabilities, and active campaigns, then scopes that activity to an organization's industry and region. Mapped to ATT&CK, the output answers a narrower question than the matrix alone can. Which of these 222 techniques are in use right now by the groups targeting this sector?

MITRE ATT&CK Framework FAQs

Is the MITRE ATT&CK Framework free to use?

Yes. ATT&CK is publicly available at no cost, and the underlying data is published under a license permitting commercial use with attribution.

Who maintains MITRE ATT&CK?

MITRE Corporation, a not-for-profit that operates federally funded research and development centers in the United States. MITRE is a name, not an acronym.

How often is MITRE ATT&CK updated?

Twice a year in major releases, with interim updates between them. Each major version can add, revoke, or restructure techniques and tactics.

Is MITRE ATT&CK required for compliance?

No. No regulation mandates it directly, and several frameworks and auditors reference it as evidence of threat-informed defense.

What is MITRE D3FEND?

A companion knowledge base cataloging defensive countermeasures. ATT&CK describes attacker behavior, while D3FEND describes the controls that counter it.

Can a small security team use MITRE ATT&CK?

Yes. Scoping to the techniques relevant to one industry and threat model makes it workable without the resources of a large SOC.

Is MITRE ATT&CK the same as the MITRE Engenuity evaluations?

No. Engenuity runs vendor product evaluations using ATT&CK techniques. The framework itself is vendor-neutral and separate from those tests.

Related Posts
What is Malware Sandboxing? How It Works and Its Limits
Malware sandboxing runs suspicious files in an isolated environment to observe their behavior safely. How malware sandboxing works, its types, and evasion.
What is Google Dorking? Operators, Risks, and Defense
Google dorking uses advanced search operators to find sensitive data exposed on the web. How it works, what it exposes, and how to defend against it.
6 Best Digital Risk Protection (DRP) Platforms in 2026
CloudSEK XVigil, Recorded Future, ZeroFox, Rapid7, Group-IB, and Flare cover key DRP needs across external risk, takedown, SOC workflows, scams, and illicit monitoring.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.