MITRE ATT&CK is a freely usable knowledge base of real-world adversary tactics and techniques, derived from publicly observed incidents. Public since 2015 and maintained by the US non-profit MITRE, the framework ships new versions twice a year (April/October) – currently Enterprise v19, released 28 April 2026. It describes what attackers actually do, not what is theoretically possible.
MITRE ATT&CK: adversary knowledge as a common language
Since 2015, MITRE ATT&CK has documented publicly observed tactics, techniques and procedures (TTPs) of real-world adversaries. We show how to use the framework for detection engineering, threat intelligence and red teaming – and where its limits lie.
2015publicly available since this year
15tactics in Enterprise since v19
697Detection Strategies in Enterprise v19
1,700+Analytics in Enterprise v19 (more than 1,700)
MITRE ATT&CK is the world's most widely used knowledge base of real-world adversary tactics, techniques and procedures (TTPs) – compiled from publicly observed incidents, freely available since 2015 and maintained by MITRE. The framework is released twice a year; the current version is Enterprise v19 of 28 April 2026, which splits the Defense Evasion tactic into Stealth and Defense Impairment. ATT&CK provides the common language between SOC, threat intelligence, red team and management: instead of debating abstract risk, everyone talks about the same concrete techniques. This page explains the framework's structure, objects and tooling – and is honest about where its usefulness ends.
The Essentials at a Glance
Nine topic blocks — tap to expand.
The three matrices
Enterprise, Mobile and ICS cover different environments — tap a matrix.
- The most comprehensive matrix: it covers not only Windows, macOS and Linux but also cloud, network infrastructure and containers.
- Since v19 it comprises 15 tactics, as Defense Evasion was split into Stealth and Defense Impairment.
WindowsmacOSLinuxCloudNetwork infrastructureContainersStealthDefense Impairment
- Addresses Android and iOS.
AndroidiOS
- Describes attacks on industrial control systems including the affected assets.
- Gained its first sub-techniques with v19.
Industrial control systemsAssetsSub-techniques
VamiRedteam & Managed Detection
We translate ATT&CK into tests and detection
MITRE ATT&CK only creates value once TTPs are translated into concrete tests and working detection. That is exactly our craft: VamiRedteam maps every finding to ATT&CK techniques, our Managed Detection & Response measures and closes coverage gaps – and in purple teaming we bring both sides to one table.
- VamiRedteam maps every finding to ATT&CK techniques – reports your SOC can translate directly into detection rules.
- Attack detection with coverage mapping: prioritised by the groups and TTPs that actually target your industry.
- Compromise assessments and threat modeling built on real TTPs instead of generic checklists.
- Honeypots and deception based on MITRE Engage make attacker techniques visible before damage is done.
Typical entry point: a purple team workshop – measured current coverage, prioritised gaps, a concrete roadmap.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
MITRE ATT&CK
Primary source: matrices, techniques, groups, software, campaigns
ATT&CK Version History
All releases at a glance – Enterprise v19 current since 28 April 2026
ATT&CK v19 Release Notes (Updates – April 2026)
Defense Evasion split, ICS sub-techniques, Detection Strategies for Mobile
ATT&CK v19: The Defense Evasion Split
Background on the tactic split and the new AI and social engineering techniques
ATT&CK Navigator
Open-source tool for coverage layers and heatmaps
MITRE D3FEND
Defensive counterpart: countermeasure techniques linked to ATT&CK
How much ATT&CK coverage do you really have?
Talk to us about purple teaming, coverage assessments and managed detection – we turn TTPs into measurable detection.