MITRE ATT&CK Framework


The MITRE Adversarial Tactics, Techniques, & Common Knowledge (ATT&CK) framework is a collection of knowledge about attackers based on real-world observations.

  • https://attack.mitre.org/
  • provide access to a database of known tactics, techniques, and procedures (TTPs)
  • tags each technique with a unique ID and places it in one or more tactic categories
  • sequence in which attackers may deploy any tactic is not defined
    • analysts must interpret each attack lifecycle from local evidence
  • allows analysts to compare the TTPs used by different threat groups