Threat IntelligenceBeginnerFramework4 validated evidence records

MITRE ATT&CK

30 sec

A publicly available knowledge base that organizes observed adversary behaviors into tactics, techniques, sub-techniques, and procedures.

Know

What is MITRE ATT&CK?

MITRE ATT&CK provides a common language for describing how adversaries operate across enterprise, mobile, and industrial-control environments. Defenders use it to map detections, threat intelligence, assessments, emulation, and security coverage.

Why it matters

Security tools use different names for similar behavior. ATT&CK gives teams a shared behavioral model for discussing what an adversary is trying to do and how.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Government / AuthoritativeGovernment advisory

Scattered Spider targeted enterprise help desks and identity controls

2025-07-29FBI, CISA and international partnersCommercial facilities and other sectors

A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.

Why this is evidence

The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.

See the source — CISA / FBI / International Partners: Scattered Spider Joint Cybersecurity Advisory AA23-320A
Government / AuthoritativeGovernment advisory

ALPHV/BlackCat ransomware activity documented through FBI investigations

2024-02-27FBI, CISA and HHSHealthcare and cross-sector

A joint advisory publishes indicators and tactics associated with ALPHV/BlackCat ransomware based on FBI investigations and notes that healthcare was the most commonly victimized sector among recent leaked victims.

Why this is evidence

The advisory connects ransomware terminology to observed campaigns, indicators, tactics, victim impact, and recommended defensive actions.

See the source — CISA / FBI / HHS: #StopRansomware: ALPHV BlackCat Update
Primary / ConfirmedConfirmed incident

SolarWinds confirmed malicious code was inserted into Orion software builds

2020-12-14SolarWindsSoftware supply chain

SolarWinds disclosed to the SEC that a compromise of its software build system inserted a vulnerability into Orion product updates released between March and June 2020.

Why this is evidence

This primary-source disclosure is direct evidence of software supply-chain compromise and the downstream risk created by trusted updates.

See the source — U.S. Securities and Exchange Commission: SolarWinds Form 8-K — December 14, 2020
Technical ValidationStandard / framework

ATT&CK connects techniques to documented adversary procedures

Continuously maintainedMITRECross-sector

MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that includes procedure examples showing how real threat groups and software have used those behaviors.

Why this is evidence

It gives the encyclopedia a neutral behavioral language for connecting definitions to observed adversary activity without relying on one vendor's taxonomy.

See the source — MITRE: MITRE ATT&CK

Understand the mechanics

How it works

  1. 1

    Tactics describe an adversary objective.

  2. 2

    Techniques describe how the objective may be achieved.

  3. 3

    Sub-techniques add more specific behavior.

  4. 4

    Procedures document examples of how real adversaries or software have used the behavior.

  5. 5

    Defenders map telemetry, detections, mitigations, and tests to those behaviors.

Practice

What to watch for

  • Detection gaps for important techniques
  • Coverage claims based only on tool count
  • Technique mappings without required telemetry
  • Procedures relevant to current threat actors

Perform

What to do

  1. 1

    Use ATT&CK to describe observed behavior.

  2. 2

    Validate the actual evidence before assigning a technique.

  3. 3

    Map detection and prevention coverage to relevant techniques.

  4. 4

    Use threat intelligence to prioritize which behaviors matter most.

How to reduce the risk

  • Threat-informed defense
  • Detection engineering
  • Adversary emulation
  • Coverage assessments
  • Telemetry mapping

Business impact

  • Shared language
  • Improved coverage analysis
  • Better testing and prioritization
  • False confidence if mappings are superficial

What different roles should do

SOC

  • Use technique mappings to structure investigation and hunting

Security Leader

  • Measure meaningful detection coverage, not decorative ATT&CK heatmaps

Framework & standards context

  • MITRE ATT&CK

Keep learning

TacticTechniqueProcedureTTPThreat IntelligenceDetection Engineering

Related entries are in the publication queue.

Source transparency

Authoritative sources

Last reviewed: 2026-09-02