Book an Appointment

MITRE ATT&CK: adversary knowledge as a common language

Since 2015, MITRE ATT&CK has documented publicly observed tactics, techniques and procedures (TTPs) of real-world adversaries. We show how to use the framework for detection engineering, threat intelligence and red teaming – and where its limits lie.

2015publicly available since this year
15tactics in Enterprise since v19
697Detection Strategies in Enterprise v19
1,700+Analytics in Enterprise v19 (more than 1,700)

MITRE ATT&CK is the world's most widely used knowledge base of real-world adversary tactics, techniques and procedures (TTPs) – compiled from publicly observed incidents, freely available since 2015 and maintained by MITRE. The framework is released twice a year; the current version is Enterprise v19 of 28 April 2026, which splits the Defense Evasion tactic into Stealth and Defense Impairment. ATT&CK provides the common language between SOC, threat intelligence, red team and management: instead of debating abstract risk, everyone talks about the same concrete techniques. This page explains the framework's structure, objects and tooling – and is honest about where its usefulness ends.

The Essentials at a Glance

Nine topic blocks — tap to expand.

The three matrices

Enterprise, Mobile and ICS cover different environments — tap a matrix.

15 tactics
  • The most comprehensive matrix: it covers not only Windows, macOS and Linux but also cloud, network infrastructure and containers.
  • Since v19 it comprises 15 tactics, as Defense Evasion was split into Stealth and Defense Impairment.
WindowsmacOSLinuxCloudNetwork infrastructureContainersStealthDefense Impairment
VamiRedteam & Managed Detection

We translate ATT&CK into tests and detection

MITRE ATT&CK only creates value once TTPs are translated into concrete tests and working detection. That is exactly our craft: VamiRedteam maps every finding to ATT&CK techniques, our Managed Detection & Response measures and closes coverage gaps – and in purple teaming we bring both sides to one table.

  • VamiRedteam maps every finding to ATT&CK techniques – reports your SOC can translate directly into detection rules.
  • Attack detection with coverage mapping: prioritised by the groups and TTPs that actually target your industry.
  • Compromise assessments and threat modeling built on real TTPs instead of generic checklists.
  • Honeypots and deception based on MITRE Engage make attacker techniques visible before damage is done.

Typical entry point: a purple team workshop – measured current coverage, prioritised gaps, a concrete roadmap.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

MITRE · 2026

MITRE ATT&CK

Primary source: matrices, techniques, groups, software, campaigns

MITRE · 2026

ATT&CK Version History

All releases at a glance – Enterprise v19 current since 28 April 2026

MITRE · 2026

ATT&CK v19 Release Notes (Updates – April 2026)

Defense Evasion split, ICS sub-techniques, Detection Strategies for Mobile

MITRE ATT&CK Blog (Medium) · 2026

ATT&CK v19: The Defense Evasion Split

Background on the tactic split and the new AI and social engineering techniques

MITRE (GitHub) · 2026

ATT&CK Navigator

Open-source tool for coverage layers and heatmaps

MITRE · 2026

MITRE D3FEND

Defensive counterpart: countermeasure techniques linked to ATT&CK

How much ATT&CK coverage do you really have?

Talk to us about purple teaming, coverage assessments and managed detection – we turn TTPs into measurable detection.