MITRE ATT&CK Framework Explained for Beginners
MITRE ATT&CK is a free, globally accessible knowledge base of adversary tactics and techniques. Learn how it works and why it's a vital tool for security.
By Priya Nair · Published · 11 min read

The MITRE ATT&CK framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations of cyberattacks. It provides a common language for cybersecurity professionals to describe and understand how attackers operate. This allows organizations to build a 'threat-informed defense' by focusing their security efforts on the specific methods used by real-world adversaries.
What Is MITRE and What Does ATT&CK Mean?
Before diving into the framework itself, it helps to understand its origins. MITRE is a U.S. government-funded, not-for-profit organization that manages Federally Funded Research and Development Centers (FFRDCs). It tackles complex challenges in various sectors, including aviation, healthcare, and national security. In cybersecurity, MITRE acts as an impartial entity dedicated to improving security for everyone.
The name ATT&CK is an acronym that breaks down the framework's core components:
- Adversarial: The framework is built from the perspective of the attacker or adversary. It’s not about your systems or defenses; it’s about their goals and methods.
- Tactics: These represent the 'why' of an attack. A tactic is the adversary's immediate tactical objective, the goal they are trying to achieve at a particular stage. Examples include *Initial Access*, *Privilege Escalation*, and *Exfiltration*.
- Techniques: These represent the 'how' an adversary achieves a tactic. For every tactic, there are multiple techniques an attacker might use. For example, to achieve *Initial Access*, an adversary might use the Phishing technique.
- Common Knowledge: This signifies that ATT&CK is a shared, community-driven repository. Security teams, researchers, and vendors worldwide use it and contribute to it, ensuring it remains current and comprehensive.
In essence, ATT&CK is a massive, organized encyclopedia of hacking behaviors, freely available to help defenders understand their enemy.
The Structure of the ATT&CK Matrix
The most recognizable part of the ATT&CK framework is the matrix. It’s a large table that visually organizes attacker behavior. Understanding its layout is key to using the framework effectively.
The matrix is structured with tactics as the column headers and techniques listed below them.
- Tactics (The Columns): These are the high-level objectives that span the top of the matrix. They follow a logical, albeit not strictly linear, progression of a typical attack. The 14 tactics in the Enterprise matrix are: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact.
- Techniques (The Rows): Below each tactic are the specific techniques used to achieve that goal. For instance, under the Credential Access tactic, you'll find techniques like *Brute Force*, *OS Credential Dumping*, and *Kerberoasting*. Each technique is assigned a unique ID, such as T1110 for *Brute Force*.
- Sub-techniques (The Details): Many techniques are further broken down into more specific sub-techniques. These provide a greater level of detail. For example, the *Phishing* technique (T1566) has sub-techniques like *Spearphishing Attachment* (T1566.001) and *Spearphishing Link* (T1566.002). This granularity helps defenders pinpoint the exact behavior they need to detect or prevent.
Here’s a simplified example of how these elements relate:
| Tactic (The Why) | Technique (The How) | Sub-technique (The Specifics) |
|---|---|---|
| Initial Access | Phishing (T1566) | Spearphishing Attachment (T1566.001) |
| Credential Access | Brute Force (T1110) | Password Spraying (T1110.003) |
| Execution | Command and Scripting Interpreter (T1059) | PowerShell (T1059.001) |
| Exfiltration | Exfiltration Over C2 Channel (T1041) | (No sub-techniques for this one) |
Why the ATT&CK Framework Is So Important
ATT&CK has become an industry standard because it solves several fundamental problems in cybersecurity. Its value extends far beyond just being a list of bad things attackers can do.
A Common Vocabulary One of the biggest benefits is providing a shared lexicon. A security analyst in one country can use an ATT&CK technique ID to communicate a complex attacker behavior to a colleague across the world, and both will understand precisely what is meant. When a threat intelligence report details a campaign from an APT group, mapping their methods to ATT&CK makes the information instantly digestible and actionable. For example, a report might describe [how Russia's Star Blizzard operates](/posts/star-blizzard-redflick-cosmicpulse) by detailing its use of specific T-numbers, which teams can then use to check their defenses.
Enables Threat-Informed Defense ATT&CK shifts the defensive mindset from being reactive to proactive. Instead of just waiting for a security tool to generate an alert, teams can adopt a 'threat-informed defense.' This means aligning defensive capabilities and security controls against known adversary behaviors. You're no longer just protecting against generic malware; you're actively defending against the specific technique of *PowerShell abuse* (T1059.001) or *LSASS Memory Dumping* (T1003.001).
Identifies Security Gaps By mapping your security controls—like antivirus, EDR (Endpoint Detection and Response), and firewall rules—to the ATT&CK matrix, you can perform a gap analysis. This process, often visualized with a heatmap, clearly shows which techniques you have good coverage for and, more importantly, where your blind spots are. This allows for data-driven decisions on where to invest security resources, whether that's in new tools, better configurations, or more training.
Benchmarks Security Tools When evaluating a new security product, the ATT&CK framework provides a powerful benchmark. Instead of relying on vague marketing claims, an organization can ask a vendor, "Which ATT&CK techniques does your product provide detection or prevention for?" Many vendors now provide their own coverage maps, and independent evaluations use the ATT&CK framework to test products against simulated adversary behaviors.
Different ATT&CK Matrices for Different Domains
Cyberattacks don't just happen in corporate networks. To address this, MITRE has developed several distinct ATT&CK matrices tailored to different technology domains.
- ATT&CK for Enterprise: This is the most widely known matrix. It covers traditional enterprise IT environments, including Windows, macOS, and Linux operating systems. It also has dedicated sections for cloud platforms like AWS, Google Cloud, and Azure, as well as for network devices and containers.
- ATT&CK for Mobile: This matrix focuses on adversary behavior on mobile devices. It includes tactics and techniques specific to Android and iOS, addressing threats like spyware, malicious applications, and exploitation of mobile-specific services. Some tactics differ from the Enterprise matrix to better reflect the mobile landscape, such as *Network Effects* and *Remote Service Effects*.
- ATT&CK for ICS (Industrial Control Systems): This is a specialized matrix for Operational Technology (OT) environments. It addresses the unique threat landscape of industrial settings like power grids, water treatment facilities, and manufacturing plants. The tactics and techniques are tailored to attacks that can disrupt or manipulate physical processes, with tactics like *Impair Process Control* and *Inhibit Response Function*.
Knowing which matrix to use is crucial for applying the framework correctly to your specific environment.
How Security Teams Use ATT&CK in Practice
On a day-to-day basis, security professionals use ATT&CK in several practical ways.
- Detection Engineering: Security engineers write detection rules for their SIEM (Security Information and Event Management) or EDR platforms based on ATT&CK techniques. Instead of a rule that just says "malware detected," they can create a more specific rule that alerts on behaviors associated with a technique, such as the creation of a new service to establish persistence (T1543.003).
- Threat Hunting: Threat hunters use ATT&CK to form hypotheses for proactive searches. For example, a hunter might assume an attacker is already inside the network and ask, "What are the common ways adversaries move laterally?" They can then consult the *Lateral Movement* tactic in ATT&CK and hunt for evidence of techniques like *Remote Desktop Protocol* (T1021.001) or *Windows Admin Shares* (T1021.002). This is a more focused approach than randomly searching through logs.
- Adversary Emulation and Red Teaming: Red teams simulate the behavior of real-world threat actors. ATT&CK provides the perfect playbook. A red team can choose to emulate a specific group by stringing together the techniques that group is known to use, providing a realistic test of the blue team's detection and response capabilities.
- Incident Response: During and after an incident, ATT&CK helps responders understand the scope of the attack. By mapping observed activity to the framework, they can better understand what the attacker has done and predict what they might do next. This helps contextualize disparate alerts and provides a clearer picture of how data breaches happen.
Getting Started with ATT&CK
The MITRE ATT&CK matrix can be intimidating at first glance due to its sheer size and density. The key is to not try and boil the ocean. You don't need to be an expert on all 200+ techniques overnight.
A practical way to begin is to start small and focus on what's most relevant to you.
- Pick a Tactic: Start with a single tactic that is a major concern for your organization. Initial Access is a great starting point for most.
- Explore Techniques: Look at the techniques listed under that tactic. For *Initial Access*, this includes familiar methods like using a phishing email to get initial access (T1566) or exploiting a public-facing application (T1190).
- Ask Key Questions: For each technique, ask simple questions: What defenses do we have against this? How would we detect it if it happened? Do our logs even capture this kind of activity? The answers will quickly reveal your strengths and weaknesses.
- Use the Resources: The official MITRE ATT&CK website is an interactive, well-documented resource. Every technique has a detailed page with descriptions, examples, mitigation advice, and detection guidance. It's the definitive source of truth. As you mature, you can also begin to correlate ATT&CK techniques with specific Indicators of Compromise from your threat intelligence feeds.
By taking this iterative approach, any organization can begin leveraging the power of MITRE ATT&CK to build a more resilient and threat-aware security posture.



