Common · Literature
ATT&CK
Knowledge base of cyber threats and tactics maintained by the Mitre Corporation
The Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) is a guideline for classifying and describing cyberattacks and intrusions. It was created by the Mitre Corporation and released in 2013.
From Wikipedia
The Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) is a guideline for classifying and describing cyberattacks and intrusions. It was created by the Mitre Corporation and released in 2013. The MITRE ATT&CK framework is widely used within cybersecurity, because it is a public catalog of known attacker techniques, where every technique has an ID, such as "T1566-Phishing". It gives the industry a shared vocabulary: an analyst can write the ID in a report and every reader will know exactly what is meant. The US Cybersecurity and Infrastructure Security Agency's (CISA) formally recognised the importance of this framework in "Best practices for Mitre ATT&CK mapping", cementing its status as government-endorsed for the standardization of threat intelligence work. Rather than examining the results of an attack (also known as indicators of compromise (IoCs)), it identifies tactics that indicate an attack is in progress. Tactics are the “why” of an attack technique. The framework consisted in 2022 of 14 tactic categories, which encompass the methods of an adversary. Examples include privilege escalation and command and control. These categories are then broken down further into specific techniques and sub-techniques. In the latest release of the framework, ATT&CK version 19 released in April 2026, there are now 15 Tactic categories. The previous "Defense Evasion" category has been split in 2: "Stealth" where defenses appear intact depite having been broken by adversaries and "Defense Impairment" capturing behavior where Defenses are actively and visibly broken. The framework is an alternative to the cyber kill chain developed by Lockheed Martin.
Text: Wikipédia, CC BY-SA 4.0. ·
Related cards
-
C★
Charming Kitten
Iranian cyberwarfare group
-
★★
Cyberattack
Any attempt to expose, alter, disable, destroy, steal or gain unauthorized access to or make unauthorized use of a computer system
-
N★
NIST Cybersecurity Framework
U.S. government-sponsored framework for cybersecurity
-
M★
Multiple Threat Alert Center
Multiple Threat Alert Center is responsible for collecting, analyzing, and disseminating information regarding criminal, terrorist, foreign intelligence, cyber, and other threats
-
★
Titan Security Key
Defend against account takeovers from phishing attacks
-
★★★
Man-in-the-middle attack
Form of active eavesdropping in which the attacker makes connections with the victims and relays messages between them