Glossary
MITRE ATT&CK
MITRE ATT&CK is like an encyclopedia of how hackers attack. It categorizes every known attack technique so defenders can systematically check if they can detect each one.
What is MITRE ATT&CK?
A knowledge base of adversary tactics and techniques based on real-world observations, used as a framework for threat modeling.
Why Should You Care?
MITRE ATT&CK enables security teams to systematically map their detection and response capabilities against the exact techniques adversaries use in the wild, moving beyond generic risk assessments to measurable coverage gaps. Organizations use it to prioritize which attack techniques pose the greatest risk to their specific environment and to benchmark their defensive maturity against industry peers. Without this framework, teams often focus on preventing threats they've heard about rather than the techniques most likely to target their infrastructure and data.
Is your business exposed?
Real-World Example
When analyzing the 2020 SolarWinds supply-chain compromise, defenders and incident responders mapped the attacker's lateral movement techniques—such as LDAP queries and credential dumping—directly to MITRE ATT&CK IDs, enabling them to identify shared indicators of compromise across thousands of affected organizations and correlate defensive measures needed across the kill chain from persistence to exfiltration.
How to Protect Against MITRE ATT&CK
- 1.
Map your defenses to ATT&CK techniques
- 2.
Identify detection gaps using ATT&CK
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required