What is the MITRE ATT&CK framework? Definition & uses
The MITRE ATT&CK framework is a globally accessible, continuously updated knowledge base of real-world adversary tactics and techniques, organized so defenders can map, detect, and respond to attacker behavior.
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) gives the security industry a shared language for describing how attackers operate. Instead of vague terms, everyone can reference the same catalog of observed behavior, drawn from real intrusions.
How is ATT&CK structured?
- Tactics are the attacker's goals, such as initial access, privilege escalation, lateral movement, and exfiltration.
- Techniques and sub-techniques are the specific ways those goals are achieved, each with a unique ID.
- Procedures are concrete real-world examples of techniques in use.
The framework spans several matrices, including Enterprise, Mobile, and ICS.
What is the MITRE ATT&CK framework used for?
- Detection engineering: map alerts to techniques to find coverage gaps.
- Threat intelligence: describe and compare adversary groups consistently.
- Red and purple teaming: plan, execute, and validate emulated attacks.
- Risk and reporting: communicate exactly what an attacker did.
Defenders often visualize coverage with the ATT&CK Navigator, and the related D3FEND project catalogs defensive countermeasures.
How to practice with MITRE ATT&CK hands-on
On Purple Edge the purple-team learning hub ties exercises to ATT&CK techniques, so as you run attacks and build detections in live labs you learn to map every action to the framework the industry actually uses.
Practice this in the Learn Purple Teaming learning path.
Put this into practice
Spin up real Kali, Ubuntu and Windows labs in your browser and learn by doing. Guided, hands-on, no setup.
Last updated: 2026-06-16