Taking the ATT&CK framework out of the weeds. Streamline cybersecurity with clarity and actionable insights. The ATT&CK framework provides a common taxonomy for defenders to share threat intelligence. It also helps defenders understand what to look for in their telemetry to detect adversaries.
It helps teams answer questions such as how an attacker gets in, how they move around and where to look for valuable data. This information helps security operations teams improve post-compromise detection and strengthens cybersecurity vendors.
What is the ATT&CK framework?
The ATT&CK framework defines the tactics threat actors use to perform their attack against an organization. These tactics are grouped into categories such as reconnaissance, initial access, persistence, lateral movement and data exfiltration. Each category has several associated techniques, which describe the specific tools, processes and steps that an adversary might use to perform a tactic.
The framework’s graphical representation of attacker behavior and the sequence of events helps security teams detect and respond to cyber attacks. ATT&CK also helps security teams identify gaps in their defenses. By evaluating their current capabilities against the ATT&CK matrix, they can develop a plan to improve their defenses.
MITRE’s ATT&CK framework is widely used by organizations to plan and build their security strategies. It allows them to assess their existing defenses against the ATT&CK techniques most likely to be employed by their adversaries and then create plans for how to address these vulnerabilities. ATT&CK is also an essential tool for planning and performing red teaming and threat hunting, as it provides a common language to describe adversary behaviors.
A logical mapping of the attacker’s technique to your defenses helps you understand how well your defenses are working. It also makes it easy to compare your detection coverage against that of other defenders using the same ATT&CK framework.
For example, in a recent study, Picus Labs examined 48813 malware samples and mapped them to the ATT&CK framework. We found that the tenth most prevalent tactic was “Impair Defenses,” and the third most prominent was “Utilize Existing Authentication Tokens.” These findings underscore how important it is to make sure your defenses are up to date against the latest threats.
CrowdStrike is a proud member of the MITRE ATT&CK research community and participates in a variety of projects that support the framework. We contribute to the ATT&CK project through our industry leading Falcon platform, which achieved the highest detection coverage in the first-ever closed-book MITRE ATT&CK evaluations for security service providers.
The ATT&CK knowledge base, based on real-world observations, has become the standard for describing adversary behavior and helping cybersecurity teams detect malicious activity. It’s a critical component of the threat intelligence shared with STIX, and it’s used by many cyber-security tools to enhance threat detection and response.
What is the ATT&CK matrix?
The ATT&CK framework describes how an adversary performs an attack, offering security teams insight into attacker behavior. The framework includes tactics and techniques that describe actions malicious actors take during different stages of the hacking lifecycle, from reconnaissance and resource development to initial access, persistence, lateral movement and data exfiltration. The ATT&CK matrix shows these steps in a logical order that reflects the attack progression.
For example, the ATT&CK technique “Researching and Exploiting Credentials” describes the ways attackers may obtain credentials for use in an attack, from gaining administrative access to servers by bypassing authentication tokens to creating a fake user account and stealing information or resources. Attackers may then use the data they have obtained to further execute attacks, including disk wiping or denial of service attacks.
As the ATT&CK knowledge base grows, it becomes easier for organizations to evaluate their security technology against threats. Security teams can map their defenses to the ATT&CK matrix, finding gaps and areas of improvement. In addition, they can use the ATT&CK matrix to understand how their current security products are likely to respond to specific attack patterns.
While ATT&CK is not a replacement for NIST CSF or other security frameworks, it does provide valuable granularity and specificity when describing attack behaviors. Unlike higher-level models like the Lockheed Martin Cyber Kill Chain, which illustrate adversary goals but don’t offer details on how those are accomplished, ATT&CK allows individual steps to be broken down and modeled.
ATT&CK is available as a self-hosted tool, allowing it to be customized for an organization’s unique technology stack. The ATT&CK Navigator tool, for instance, lets users create collections of ATT&CK techniques to match their specific technology needs. Combined with other tools, such as a SIEM or threat intelligence feed, ATT&CK can help security teams better understand the way attackers are attacking them and identify their vulnerabilities before they become exploited.
MITRE has also released a separate matrix for Industrial Control Systems (ICS). While it is based on the ATT&CK Enterprise framework, the ICS matrix provides additional guidance to defend against attacks targeting these types of systems. ICS environments are unique, leveraging technologies that are less common in Enterprise networks and controlling physical processes that could impact human health, safety or environmental impact.
What is the ATT&CK knowledge base?
The ATT&CK knowledge base is a publicly available resource that enables organizations to see how their defenses would fare against the adversary’s tactics and techniques. This can be useful in evaluating and planning for future attacks. However, it can also be a powerful tool to help defenders understand how the defenses they currently have in place work and what gaps exist.
The information contained in the ATT&CK knowledge base is based on real-world observations of malicious behavior and is regularly updated as new intelligence becomes available. The knowledge base is divided into a number of matrices that cover different subject matters, including enterprise, mobile, and industrial control systems (ICS). Each matrix contains a collection of tactics and techniques that malicious actors use to perform an attack, such as reconnaissance, initial access, persistence, lateral movement, and exfiltration.
Each of these matrices is broken down further into sub-categories, which are known as tactics and sub-techniques. For example, a sub-technique of the Persistence category is “use of a backdoor to gain privileges.” The ATT&CK knowledge base provides the tools to be able to understand how these tactics and their sub-techniques work together to allow adversaries to achieve their goals.
MITRE explains that it’s unrealistic for any single defensive product to cover all the threats listed in ATT&CK. This is why it’s important to know which ATT&CK tactics and techniques you have covered, but also to understand the capabilities of your current defenses against those you don’t.
When a data breach occurs, it’s often due to an attacker exploiting gaps in your defenses. The ATT&CK framework helps you evaluate and improve your defenses by providing a common vocabulary for communicating the elements of an attack to other teams and vendors.
Using ATT&CK as the basis for an incident response plan will enable your team to quickly and accurately assess what went wrong with an attack and create an actionable response. It can also be used to identify potential gaps in your security defenses so that you can develop remediation plans and compensating controls. This will reduce your risk of a data breach in the future.
What is the ATT&CK evaluation process?
ATT&CK is an important tool for detecting and triaging a cyber incident after it occurs. But the framework can also help prevent a cyber attack from ever occurring, by helping to identify attacker goals and strategies. In this regard, the framework is particularly useful in ICS environments. In fact, MITRE developed a separate ATT&CK matrix to address these unique challenges, known as the ICS ATT&CK framework. Unlike the Enterprise ATT&CK framework, the ICS version is heavily focused on what is referred to as Levels 0-2 of the Purdue Model. These are system levels closest to the actual devices that control physical processes such as opening and closing connections or increasing temperature or pressure. Because of this, the ICS ATT&CK framework has 11 tactics that are distinct from those in the Enterprise edition.
MITRE’s ATT&CK evaluation process involves the collaboration of MITRE Engenuity and vendor product teams. MITRE Engenuity acts as the red team, while vendors test their products against observed adversary behaviors in the wild based on ATT&CK knowledge. The result is a more comprehensive and accurate testing experience than would be possible with a simple compendium of known malware samples.
Each year, a different set of threat groups are emulated to test security products. For example, in the 2021 ATT&CK evaluation, opportunistic insiders were emulated, including the well-documented attacks of Carbanak and FIN7, which have stolen millions of dollars from banks and thousands of private customers.
The ATT&CK methodology reduces the need for expert judgment in several steps of risk assessment, which lowers the time needed to perform the evaluation and limits the impact of biases on the final risk rating. In addition, the methodology provides a standard set of requirements for mitigations that must be implemented in the security architecture.
In addition, the ATT&CK methodology is designed to work with other existing risk assessment frameworks, such as the Common Vulnerability Scoring System (CVSS) and Bow-Tie. As a result, the evaluation of an IT and OT security architecture using these approaches will provide consistent results and a comparable risk rating across both technologies.


