MITRE ATT&CK

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics, techniques, and procedures observed in real-world attacks, used broadly by security teams as a shared reference for threat modeling, detection engineering, and program assessment.

What MITRE ATT&CK Provides

ATT&CK organizes adversary behavior into a matrix of tactics (why the adversary is doing something) and techniques (how they are doing it). Each technique is documented with description, real-world examples, detection guidance, and mitigation suggestions. Sub-techniques provide finer granularity for specific implementations.

The framework covers multiple domains: Enterprise (traditional IT), Mobile, ICS (industrial control systems), and increasingly, cloud-specific variants. The MITRE ATLAS framework extends the same approach to AI systems.

Why MITRE ATT&CK Became the Standard

Before ATT&CK, security teams described attacks in ad hoc terms. Different teams used different language for the same techniques, making detection engineering, threat sharing, and program assessment inconsistent. ATT&CK gave the community a shared vocabulary.

The knowledge base is continuously updated based on observed real-world activity, which keeps it grounded in actual attacker behavior rather than theoretical threat models.

MITRE ATT&CK in Enterprise Programs

Common uses include mapping detection coverage against ATT&CK techniques to identify gaps, structuring red team and purple team exercises around specific techniques, communicating threat intelligence in a standardized format, and defending program maturity claims against a defensible external reference.

MITRE ATT&CK in Quantified Programs

Quantified programs use ATT&CK-mapped scenarios to model specific attack paths, with technique-level detection and mitigation coverage feeding into modeled loss distributions. Kovrr's CRQ Platform incorporates ATT&CK mapping natively.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.