MITRE ATT&CK
Last updated
Last updated
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is a comprehensive knowledge base that organizes and categorizes various cyber threats based on observed adversary behaviors. It was developed by MITRE Corporation, a not-for-profit organization that operates federally funded research and development centers (FFRDCs) to support multiple government agencies.
The framework provides a structured model to understand the tactics, techniques, and procedures (TTPs) used by adversaries during cyberattacks. It covers a wide range of threat actors, from advanced persistent threats (APTs) to less sophisticated attackers.
MITRE ATT&CK is organized into several matrices, each focusing on a different platform or aspect of cyber defense, such as Enterprise, Mobile, PRE-ATT&CK (pre-exploitation), and Cloud. Each matrix includes a list of tactics (the adversary's goals during an attack) and techniques (the specific methods they use to achieve those goals), along with detailed descriptions and examples.
Security professionals and organizations use the MITRE ATT&CK framework to enhance their cybersecurity posture by understanding potential threats, identifying gaps in their defenses, and developing more effective detection and mitigation strategies. Additionally, it serves as a common language for discussing and sharing information about cyber threats and defensive techniques within the cybersecurity community.