Know
What is MITRE ATT&CK?
MITRE ATT&CK provides a common language for describing how adversaries operate across enterprise, mobile, and industrial-control environments. Defenders use it to map detections, threat intelligence, assessments, emulation, and security coverage.
Why it matters
Security tools use different names for similar behavior. ATT&CK gives teams a shared behavioral model for discussing what an adversary is trying to do and how.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Scattered Spider targeted enterprise help desks and identity controls
A joint advisory describes Scattered Spider tactics obtained through investigations, including targeting IT help desks, social engineering, identity abuse, and the need for phishing-resistant MFA.
The advisory validates how modern intrusions can begin with human and identity-control failures and maps observed behavior to MITRE ATT&CK techniques.
ALPHV/BlackCat ransomware activity documented through FBI investigations
A joint advisory publishes indicators and tactics associated with ALPHV/BlackCat ransomware based on FBI investigations and notes that healthcare was the most commonly victimized sector among recent leaked victims.
The advisory connects ransomware terminology to observed campaigns, indicators, tactics, victim impact, and recommended defensive actions.
SolarWinds confirmed malicious code was inserted into Orion software builds
SolarWinds disclosed to the SEC that a compromise of its software build system inserted a vulnerability into Orion product updates released between March and June 2020.
This primary-source disclosure is direct evidence of software supply-chain compromise and the downstream risk created by trusted updates.
ATT&CK connects techniques to documented adversary procedures
MITRE ATT&CK is a public knowledge base of adversary tactics and techniques that includes procedure examples showing how real threat groups and software have used those behaviors.
It gives the encyclopedia a neutral behavioral language for connecting definitions to observed adversary activity without relying on one vendor's taxonomy.
Understand the mechanics
How it works
- 1
Tactics describe an adversary objective.
- 2
Techniques describe how the objective may be achieved.
- 3
Sub-techniques add more specific behavior.
- 4
Procedures document examples of how real adversaries or software have used the behavior.
- 5
Defenders map telemetry, detections, mitigations, and tests to those behaviors.
Practice
What to watch for
- Detection gaps for important techniques
- Coverage claims based only on tool count
- Technique mappings without required telemetry
- Procedures relevant to current threat actors
Perform
What to do
- 1
Use ATT&CK to describe observed behavior.
- 2
Validate the actual evidence before assigning a technique.
- 3
Map detection and prevention coverage to relevant techniques.
- 4
Use threat intelligence to prioritize which behaviors matter most.
How to reduce the risk
- Threat-informed defense
- Detection engineering
- Adversary emulation
- Coverage assessments
- Telemetry mapping
Business impact
- Shared language
- Improved coverage analysis
- Better testing and prioritization
- False confidence if mappings are superficial
What different roles should do
SOC
- Use technique mappings to structure investigation and hunting
Security Leader
- Measure meaningful detection coverage, not decorative ATT&CK heatmaps
Framework & standards context
- MITRE ATT&CK
Source transparency
Authoritative sources
Last reviewed: 2026-09-02