MITRE ATT&CK
MITRE ATT&CK is a publicly accessible knowledge base of adversarial tactics and techniques based on real-world observations.
MITRE ATT&CK is a public knowledge base about the behaviour of attackers. It classifies real-world attack techniques by tactics and assigns each a fixed identifier, like T1566 for phishing.
How it works
The US organisation MITRE maintains the database, which is based on documented attacks. It is divided into tactics such as Initial Access, Execution, Persistence, or Exfiltration. Each tactic contains techniques and sub-techniques with examples, data sources and detection guidance. There are separate matrices for enterprise IT, mobile devices, and industrial control systems.
For example, a SOC maps each detection rule to an ATT&CK technique. This creates an overview of which techniques are covered. The analysis might show no rule exists for creating new cloud accounts. The team then adds this rule and tests it in a purple team exercise.
What to look out for
- Coverage does not equal quality. One rule per technique says little about its effectiveness against real attacks.
- Prioritise techniques that are common in your industry.
- Use ATT&CK as a common language between the SOC, red team, and management.
- Avoid heatmaps designed only to look green. It is more useful to display gaps openly.
Everyday use
ATT&CK also helps with incident analysis. Analysts can describe an attack's progression step-by-step using technique identifiers. This allows for incident comparison and highlights recurring security gaps. Threat intelligence reports also use these identifiers, simplifying their adoption into detection rules.
Typical mistakes
Some teams try to cover every single technique. This is neither possible nor sensible. It is better to select techniques that attackers use against similar organisations. This selection should be reviewed annually.
How we implement it
We manage our detection rules as code: versioned, tested and tuned to your environment. Each rule is mapped to ATT&CK techniques.