MITRE ATT&CK Framework
A knowledge base of adversary tactics (the goal) and techniques (how it is achieved), built from real-world observations.
Why It Matters
ATT&CK gives defenders a shared vocabulary for attacker behavior. It is how I map what I see in an incident to what usually comes next, how I check which techniques my detections cover, and how hunts and playbooks stay focused on behavior attackers actually use.
Reference
Tactics
| ID |
Tactic |
Attacker Goal |
| TA0043 |
Reconnaissance |
Gather information to plan the attack |
| TA0042 |
Resource Development |
Set up infrastructure, accounts, and tools |
| TA0001 |
Initial Access |
Get into the network |
| TA0002 |
Execution |
Run malicious code |
| TA0003 |
Persistence |
Keep access across restarts and credential changes |
| TA0004 |
Privilege Escalation |
Gain higher permissions |
| TA0005 |
Defense Evasion |
Avoid detection |
| TA0006 |
Credential Access |
Steal account names and passwords |
| TA0007 |
Discovery |
Learn the environment |
| TA0008 |
Lateral Movement |
Move through the environment |
| TA0009 |
Collection |
Gather data of interest |
| TA0011 |
Command and Control |
Communicate with compromised systems |
| TA0010 |
Exfiltration |
Steal data |
| TA0040 |
Impact |
Disrupt, destroy, or manipulate systems and data |
Techniques are added and revised in each ATT&CK release. The tables below cover common techniques, not the full matrix.
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
| Technique |
Notes |
| T1562 Impair Defenses |
Disabling or modifying security tools, Windows event logging, firewalls, and command history logging (for example HISTCONTROL on Linux) |
| T1070 Indicator Removal |
Clearing Windows event logs (Event ID 1102), clearing Linux logs and command history, deleting files, timestomping |
Credential Access
| Technique |
What to Look For |
Mitigation |
| T1003 OS Credential Dumping |
Process access to lsass.exe (Sysmon Event ID 10); reads of /etc/shadow (auditd) |
Credential Guard, LSA protection, Protected Users, removing local admin rights |
| T1110 Brute Force |
Failed logons across many accounts or one account; see the Password Spray runbook |
MFA, lockout and smart lockout, strong passwords |
| T1558.003 Kerberoasting |
RC4 service tickets (4769, 0x17); see the Kerberoasting hunt |
gMSAs, long service account passwords, AES-only Kerberos |
Offline cracking of stolen hashes uses tools like Hashcat and John the Ripper.
Discovery
| Technique |
Common Commands |
Notes |
| T1087 Account Discovery |
net user, net localgroup, net user /domain, net group "Domain Users" /domain (Windows); id, groups, cat /etc/passwd (Linux); dscacheutil -q group (macOS); ldapsearch |
Disabling "Enumerate administrator accounts on elevation" by Group Policy stops UAC prompts from listing admin accounts |
| T1046 Network Service Discovery |
Port scanners, nmap |
Internal scanning from a workstation is unusual |
| T1083 File and Directory Discovery |
dir, tree, find, locate |
Heavy use in a short time can indicate staging |
Lateral Movement
| Technique |
Notes |
| T1021 Remote Services |
RDP, SMB/admin shares, DCOM, SSH, VNC, WinRM. Mitigate with MFA and limits on which hosts can reach these services; watch for logons from unusual source hosts |
| T1534 Internal Spearphishing |
Phishing sent from a compromised internal mailbox; scan internal mail, not just inbound |
Collection
Command and Control
Exfiltration
Impact
How I Use It
During an incident, I map each confirmed attacker action to a technique and look at the tactics around it: if I find credential dumping, I go looking for lateral movement and persistence next. Outside of incidents, I use ATT&CK Navigator layers to compare what my detections cover against the techniques most relevant to the environment, and that comparison decides which hunts and detections come next.
Resources