Cyber Threat Intelligence
MITRE ATT&CK Framework Explained: A Practical Guide
MITRE ATT&CK is a knowledge base of adversary tactics and techniques based on real-world observations. It organizes attack behaviors into 14 tactics (the "why" — goals like Initial Access, Lateral Movement, Exfiltration) containing hundreds of techniques (the "how" — specific methods like Phishing, Pass-the-Hash). Organizations use ATT&CK for detection gap analysis, threat intelligence mapping, and security assessment.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
What Is MITRE ATT&CK?
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base of adversary behaviors based on real-world observations. Created by MITRE Corporation, it catalogs the tactics and techniques that attackers use across the entire attack lifecycle.
ATT&CK has become the common language of cybersecurity — used by defenders, vendors, intelligence analysts, and red teams worldwide. When a security team says "we detected T1059.001," everyone in the industry knows they detected PowerShell execution.
Structure: Tactics and Techniques
Tactics (The "Why")
Tactics represent the adversary's goal — the reason for performing an action. ATT&CK Enterprise includes 14 tactics, roughly following the attack lifecycle:
- Reconnaissance — Gathering information about the target
- Resource Development — Establishing infrastructure for the attack
- Initial Access — Gaining first entry to the environment
- Execution — Running malicious code
- Persistence — Maintaining access across restarts
- Privilege Escalation — Gaining higher-level permissions
- Defense Evasion — Avoiding detection
- Credential Access — Stealing credentials
- Discovery — Understanding the environment
- Lateral Movement — Moving through the network
- Collection — Gathering target data
- Command and Control — Communicating with compromised systems
- Exfiltration — Stealing data out of the environment
- Impact — Destroying, disrupting, or manipulating systems
Techniques (The "How")
Each tactic contains multiple techniques — specific methods attackers use to achieve the tactical goal. For example, Initial Access includes techniques like:
- T1566: Phishing (with sub-techniques: Spearphishing Attachment, Link, Service)
- T1190: Exploit Public-Facing Application
- T1133: External Remote Services
- T1195: Supply Chain Compromise
- T1078: Valid Accounts
ATT&CK Enterprise currently catalogs 200+ techniques and 400+ sub-techniques, each with detailed descriptions, procedure examples, detection guidance, and mitigations.
Procedures
Procedures are specific implementations of techniques by real threat groups. For example, APT28 uses T1566.001 (Spearphishing Attachment) by sending malicious Word documents with embedded macros to targeted government officials.
Practical Applications
Detection Engineering
ATT&CK's detection guidance for each technique tells you what data sources to collect and what patterns to look for. Use this to:
- Build detection rules that map directly to ATT&CK techniques
- Measure coverage — which techniques can your SIEM/EDR detect?
- Identify gaps — which techniques used by relevant threat groups lack detection?
- Prioritize investments — focus detection engineering on techniques your adversaries actually use
Threat Intelligence
ATT&CK provides a standard language for describing adversary behavior:
- Map threat actor TTPs to the ATT&CK matrix to understand their capabilities
- Compare threat groups to identify common techniques across multiple adversaries
- Track technique evolution as groups adopt new methods
- Communicate precisely — "They use T1055 Process Injection" is unambiguous
Security Assessment
- Purple teaming — Red teams execute ATT&CK techniques while blue teams attempt detection
- Maturity assessment — map your detection and prevention capabilities against the full matrix
- Vendor evaluation — assess security tools against their ATT&CK coverage claims
- Compliance mapping — some frameworks reference ATT&CK for technical control validation
Incident Response
During incident response, mapping observed attacker activity to ATT&CK techniques:
- Provides structured documentation of the attack
- Predicts likely next steps based on known TTP sequences
- Identifies systems and data potentially affected
- Enables post-incident detection improvements
Getting Started with ATT&CK
- Identify your top threat groups using threat intelligence
- Map their known techniques on the ATT&CK matrix
- Assess your current detection for those specific techniques
- Prioritize gaps — techniques your adversaries use that you can't detect
- Build detections using ATT&CK's guidance on data sources and patterns
- Test with purple teaming — validate detections against real technique execution
How SeqOps fits
SeqOps keeps its vulnerability data current, so newly published CVEs are matched against the software on your servers. It doesn't replace a threat intelligence platform; it shows the weaknesses in your cloud and servers that attackers commonly exploit.