Book an Appointment

MITRE ATT&CK: adversary knowledge as a common language

Since 2015, MITRE ATT&CK has documented publicly observed tactics, techniques and procedures (TTPs) of real-world adversaries. We show how to use the framework for detection engineering, threat intelligence and red teaming – and where its limits lie.

MITRE ATT&CK is the world's most widely used knowledge base of real-world adversary tactics, techniques and procedures (TTPs) – compiled from publicly observed incidents, freely available since 2015 and maintained by MITRE. The framework is released twice a year; the current version is Enterprise v19 of 28 April 2026, which splits the Defense Evasion tactic into Stealth and Defense Impairment. ATT&CK provides the common language between SOC, threat intelligence, red team and management: instead of debating abstract risk, everyone talks about the same concrete techniques. This page explains the framework's structure, objects and tooling – and is honest about where its usefulness ends.

The Essentials at a Glance

01

What is MITRE ATT&CK?

MITRE ATT&CK is a freely usable knowledge base of real-world adversary tactics and techniques, derived from publicly observed incidents. Public since 2015 and maintained by the US non-profit MITRE, the framework ships new versions twice a year (April/October) – currently Enterprise v19, released 28 April 2026. It describes what attackers actually do, not what is theoretically possible.

02

Tactics → Techniques → Procedures

Tactics describe the why: the goal of an attack phase, such as Initial Access or Privilege Escalation. Techniques and sub-techniques describe the how – for example Phishing with the sub-technique Spearphishing Attachment. Procedures finally document how specific groups or malware actually implemented a technique in observed incidents.

03

The three matrices

Enterprise is the most comprehensive matrix, covering not only Windows, macOS and Linux but also cloud, network infrastructure and containers; since v19 it comprises 15 tactics, as Defense Evasion was split into Stealth and Defense Impairment. Mobile addresses Android and iOS. ICS describes attacks on industrial control systems including the affected assets – and gained its first sub-techniques with v19.

04

Groups, Software & Campaigns

ATT&CK links techniques to real actors: Groups documents adversary groups such as APT29 along with their preferred TTPs, Software captures the malware and tools they use, and Campaigns bundles time-bounded waves of attacks. For threat intelligence this is gold: if you know which groups target your industry, you can prioritise their techniques – instead of trying to defend against everything at once.

05

Detection Strategies & Analytics

With v18 (October 2025), MITRE fundamentally rebuilt the detection side: instead of free-text hints, each technique now comes with structured Detection Strategies and platform-specific Analytics – concrete, actionable detection logic per operating system or cloud environment. v19 expands this massively: Enterprise now counts 697 Detection Strategies with more than 1,700 Analytics, and Mobile receives its first Detection Strategies.

06

Mitigations & data sources

Mitigations describe preventive measures that make individual techniques harder or impossible – from hardening and network segmentation to application control. Data sources and data components answer the question that comes first: which telemetry – process events, network traffic, cloud audit logs – do you need to collect to be able to see a technique at all? Without the right data source, every detection rule remains theory.

07

Detection engineering & SOC coverage

The ATT&CK Navigator visualises as coverage layers which techniques your SIEM rules, EDR detections and Sigma rules cover – and where the gaps are. In a gap assessment you match this coverage against the TTPs of the groups relevant to you and prioritise your detection engineering roadmap from it. Via STIX/TAXII feeds and the ATT&CK Workbench, the framework integrates directly into your own tooling.

08

Red/purple teaming & adversary emulation

Adversary emulation builds attack simulations along the documented TTPs of real groups – so the red team tests exactly the behaviour that actually hits your industry. In purple teaming, attackers and defenders verify together, technique by technique, whether telemetry, detection and response actually work. Regulatory threat-led testing such as DORA TLPT or TIBER-EU presupposes exactly this ATT&CK-based approach.

09

Limits & ecosystem

ATT&CK is descriptive: it catalogues observed TTPs, but it is neither a catalogue of controls nor a compliance checklist. Coverage heatmaps can create a false sense of security – 200 weak rules do not beat 20 well-tested ones; quality matters more than the number of covered techniques. Complementary resources include MITRE D3FEND (defensive countermeasures), MITRE ATLAS (attacks on AI systems), CAR, Sigma, Atomic Red Team and Caldera – plus the MITRE ATT&CK Evaluations for vendor comparisons.

VamiRedteam & Managed Detection

We translate ATT&CK into tests and detection

MITRE ATT&CK only creates value once TTPs are translated into concrete tests and working detection. That is exactly our craft: VamiRedteam maps every finding to ATT&CK techniques, our Managed Detection & Response measures and closes coverage gaps – and in purple teaming we bring both sides to one table.

  • VamiRedteam maps every finding to ATT&CK techniques – reports your SOC can translate directly into detection rules.
  • Attack detection with coverage mapping: prioritised by the groups and TTPs that actually target your industry.
  • Compromise assessments and threat modeling built on real TTPs instead of generic checklists.
  • Honeypots and deception based on MITRE Engage make attacker techniques visible before damage is done.

Typical entry point: a purple team workshop – measured current coverage, prioritised gaps, a concrete roadmap.

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

MITRE · 2026

MITRE ATT&CK

Primary source: matrices, techniques, groups, software, campaigns

MITRE · 2026

ATT&CK Version History

All releases at a glance – Enterprise v19 current since 28 April 2026

MITRE · 2026

ATT&CK v19 Release Notes (Updates – April 2026)

Defense Evasion split, ICS sub-techniques, Detection Strategies for Mobile

MITRE ATT&CK Blog (Medium) · 2026

ATT&CK v19: The Defense Evasion Split

Background on the tactic split and the new AI and social engineering techniques

MITRE (GitHub) · 2026

ATT&CK Navigator

Open-source tool for coverage layers and heatmaps

MITRE · 2026

MITRE D3FEND

Defensive counterpart: countermeasure techniques linked to ATT&CK

How much ATT&CK coverage do you really have?

Talk to us about purple teaming, coverage assessments and managed detection – we turn TTPs into measurable detection.