MITRE ATT&CK
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Detection Engineering and Data Sources - MITRE ATT&CK
Implement detection engineering and threat hunting using ATT&CK Data Sources and detection content. Each technique includes Detection guidance + Data Sources required + analytic queries. Data Sources (DS-IDs) provide categorisation of logs and telemetry: DS0009 Process + DS0017 Command Execution + DS0029 Network Traffic + DS0011 Module + DS0016 Drive + DS0022 File + DS0033 Network Share + others. v16 (October 2024) introduced structured detection content with analytic platforms metadata. Detection content includes vendor-agnostic Sigma rules + platform-specific Splunk SPL + Microsoft Kusto Query Language (KQL) + Yara malware signatures + Snort/Suricata network rules + ElasticSearch DSL + AWS CloudWatch + Azure Sentinel KQL + Google Chronicle YARA-L. Integration with SIEM platforms (Splunk + Microsoft Sentinel + IBM QRadar + Elastic SIEM + Google Chronicle + Sumo Logic + Devo + Securonix
- Data Sources (DS-IDs) coverage inventory per Process + Command Execution + Network Traffic + Module + File + Drive + Network Share
- Sigma rules library mapped to techniques
- Splunk SPL / KQL / YARA-L analytic queries with technique IDs
- v16 structured detection content with analytic platforms metadata
- SIEM + EDR + NDR integration documentation
- Detection coverage report by technique
- Process telemetry (DS0009) only partial (missing command-line arguments + image hash)
- Network Traffic (DS0029) limited to perimeter only (no E-W)
- Sigma rules not mapped to techniques
- EDR detection content not refreshed for v16 structured format
Integration and Ecosystem - MITRE ATT&CK
Integrate ATT&CK with broader cybersecurity ecosystem and frameworks. MITRE Engenuity ATT&CK Evaluations - rigorous evaluations of cybersecurity vendor solutions against real adversary tradecraft (APT3 + APT29 + Carbanak/FIN7 + Wizard Spider + Sandworm + Turla + DPRK scenarios + ICS Triton evaluation). Annual evaluation cycle. MITRE Engenuity Center for Threat-Informed Defense (CTID) - public-private collaboration advancing ATT&CK + research projects + Sensor Mappings + Atomic Red Team + ATT&CK Insights. CALDERA automated adversary emulation platform for security team testing. ATT&CK Navigator visualisation tool. Atomic Red Team library of executable security tests (Red Canary). Integration with NIST Cybersecurity Framework 2.0 (mapping to Identify + Protect + Detect + Respond + Recover + Govern functions) + NIST 800-53 + NIST 800-61 + NIST 800-115 + ISO 27001 Annex A + ISO 27035 inciden
- NIST CSF 2.0 + NIST 800-53 + ISO 27001 + CIS v8 cross-walks
- MITRE Engenuity ATT&CK Evaluation participation (vendor procurement evidence)
- CALDERA adversary emulation engagement
- Atomic Red Team test library use
- Lockheed Cyber Kill Chain + Diamond Model integration
- STIX 2.x / TAXII 2.x exchange with industry ISAC
- BAS (Breach and Attack Simulation) - SafeBreach + AttackIQ + Cymulate + XM Cyber + Pentera + Picus Security
- No vendor procurement requirement to participate in MITRE Engenuity Evaluations
- CALDERA + Atomic Red Team not in red team programme
- STIX 2.x exchange not operationalised
- Compliance framework cross-walks (SOC 2 + PCI DSS + HIPAA + GDPR + 23 NYCRR 500) not maintained
Matrices and Platforms - MITRE ATT&CK
Select and apply appropriate ATT&CK matrix for target environment. ATT&CK FOR ENTERPRISE primary matrix covers Windows + macOS + Linux + Office Suite + IaaS + SaaS + Identity Provider + Network platforms. ATT&CK FOR CLOUD sub-matrix for AWS + Azure + Google Cloud Platform (GCP) + Office 365 + SaaS + IaaS + Network. ATT&CK FOR MOBILE for iOS + Android covering 12 tactics including app-specific adversary behaviours + mobile malware + mobile device management bypass. ATT&CK FOR ICS (Industrial Control Systems) for operational technology environments + Schneider Electric + Rockwell Automation + Siemens + ABB + Honeywell systems + DCS + PLC + SCADA + HMI + historians + safety-instrumented systems + level 0-3 Purdue model. CONTAINER matrix (added v10 2021) for Docker + Kubernetes + container orchestration. Selection criteria: target platform + threat model + attack surface + adversary capabili
- Selected matrices (Enterprise + Cloud + Mobile + ICS + Container) per environment
- Platform-specific coverage (Windows + macOS + Linux + IaaS + SaaS + Identity + Network + Office Suite + Container)
- ATT&CK Navigator JSON heat maps per environment
- Cloud sub-matrix selection (AWS + Azure + GCP + Office 365)
- Container matrix application for Kubernetes / Docker
- Cloud sub-matrix not selected for cloud workloads
- Container matrix not applied to Kubernetes environments
- ICS matrix not applied where OT environments exist
- Identity Provider platform coverage missing
Mitigations and Controls - MITRE ATT&CK
Apply ATT&CK Mitigations (M-IDs) for prevention and risk reduction. M1015 Active Directory Configuration + M1018 User Account Management + M1027 Password Policies + M1056 Account Use Policies + M1017 User Training + M1036 Account Use Policies + M1042 Disable or Remove Feature or Program + M1045 Code Signing + M1049 Antivirus/Antimalware + M1031 Network Intrusion Prevention + M1032 Multi-factor Authentication + M1041 Encrypt Sensitive Information + M1044 Restrict Library Loading + M1046 Boot Integrity + M1047 Audit + M1048 Application Isolation and Sandboxing + M1049 Antivirus/Antimalware + M1050 Exploit Protection + M1051 Update Software + M1052 User Account Control + M1053 Data Backup + M1054 Software Configuration + M1055 Do Not Mitigate (informational) + M1057 Data Loss Prevention. Mitigation prioritisation by Technique mappings. Risk-based application using ATT&CK Navigator + CIS Con
- Mitigation (M-ID) implementation matrix mapped to controls
- M1032 MFA + M1018 User Account Management + M1027 Password Policies evidence
- M1049 Antivirus/EDR + M1031 Network Intrusion Prevention deployment
- M1041 Encryption + M1053 Backups + M1051 Patch Management + M1054 Software Configuration
- ATT&CK Navigator mitigation overlay + CIS Controls v8 + NIST CSF 2.0 mapping
- Compensating controls documentation where direct mitigation not feasible
- MFA not enforced for all administrative paths (M1032)
- User Account Management lacks PAM (M1018 + M1056)
- Backups not air-gapped or immutable (M1053)
- Application Isolation/Sandboxing (M1048) not implemented
Scope and Foundation - MITRE ATT&CK
Establish the scope of MITRE ATT&CK (Adversarial Tactics Techniques and Common Knowledge) - globally accessible knowledge base of adversary tactics and techniques based on real-world observations. Developed by MITRE Corporation (non-profit Federally Funded Research and Development Center FFRDC chartered by US Department of Defense and other federal agencies + headquartered McLean Virginia and Bedford Massachusetts). Initially released by MITRE 2013 + Enterprise + ATT&CK for Mobile + ATT&CK for ICS (Industrial Control Systems) + Cloud matrices (AWS + Azure + Google Cloud + SaaS + Office 365 + IaaS + Network) + Container matrix (added v10 2021). Released as open standard under Creative Commons Attribution 4.0 International (CC BY 4.0). Maintained by MITRE Engenuity Center for Threat-Informed Defense (CTID) and global cybersecurity community. v15 published 30 April 2024 with significant ICS
- ATT&CK version in use (v15/v16/v17) documented + change log cross-walk
- Creative Commons Attribution 4.0 license adherence evidence
- MITRE Engenuity CTID research engagement
- Federal usage cross-walk (CISA + NSA + FBI + DOD)
- Allied nation cross-walk (NCSC UK + ACSC + CSE + ANSSI + BSI)
- Using outdated ATT&CK version without refresh
- CC BY 4.0 attribution missing from derivative work
- Federal/allied cross-walk not maintained
Tactics - MITRE ATT&CK Enterprise Kill Chain
Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations. TA0042 Resource Development - establishing resources to support operations. TA0001 Initial Access - getting into target network. TA0002 Execution - running adversary-controlled code. TA0003 Persistence - maintaining footholds across restarts and credential changes. TA0004 Privilege Escalation - gaining higher-level permissions. TA0005 Defense Evasion - avoiding detection. TA0006 Credential Access - stealing account names and passwords. TA0007 Discovery - gaining knowledge about target environment. TA0008 Lateral Movement - moving through environment. TA0009 Collection - gathering information of interest. TA0011 Command and Control - communicating with compromised systems. TA0010 Exfiltration - steal
- ATT&CK Navigator heat map showing tactic coverage
- Detection coverage per tactic (TA0001-TA0043)
- ICS vs Enterprise tactic differentiation (12 vs 14 tactics)
- Threat model with prioritised tactics based on adversary group profile
- Tactic-level red team / purple team exercise records
- Reconnaissance TA0043 and Resource Development TA0042 (added v8 2020) not in detection scope
- Lateral Movement TA0008 visibility limited to EDR
- Impact TA0040 detection (ransomware) reactive only
Techniques and Sub-Techniques - MITRE ATT&CK
Catalogue and analyse adversary techniques and sub-techniques. ATT&CK Enterprise contains 200+ techniques + 600+ sub-techniques as of v16 (October 2024). Each technique has unique ID (T-NNNN) + Name + Description + Tactics + Procedure Examples + Mitigations + Detection guidance + Platforms + Data Sources. Key technique examples: T1078 Valid Accounts (legitimate credentials abuse) + T1059 Command and Scripting Interpreter (PowerShell + Bash + Python + JavaScript + AppleScript) + T1566 Phishing (Spearphishing Attachment + Link + Service) + T1190 Exploit Public-Facing Application (CVE exploitation) + T1486 Data Encrypted for Impact (ransomware) + T1110 Brute Force + T1003 OS Credential Dumping (LSASS + SAM + DCSync) + T1218 System Binary Proxy Execution (Living off the Land) + T1055 Process Injection + T1071 Application Layer Protocol (DNS + HTTPS + IRC + DNS C2) + T1567 Exfiltration Over W
- Technique-level detection inventory (200+ Enterprise techniques + 600+ sub-techniques)
- Sub-technique granularity per detection rule (e.g. T1078.001-004 sub-technique coverage)
- Procedure Example documentation by adversary group
- Living Off The Land Binaries (LOLBins) detection T1218 + T1059
- Defense Evasion T1027 obfuscation detection capabilities
- Detection at parent technique level only (sub-techniques missed)
- T1078 Valid Accounts (legitimate credential abuse) detection weak
- T1218 LOLBins detection limited
- T1486 ransomware detection reactive vs preventive
Threat Groups and Software - MITRE ATT&CK
Track adversary tradecraft via ATT&CK Groups (G-IDs) and Software (S-IDs). 130+ threat groups documented including APT1 (PLA Unit 61398) + APT28 Fancy Bear (Russia GRU) + APT29 Cozy Bear/Midnight Blizzard (Russia SVR) + APT38 Lazarus financial (DPRK) + APT41 Wicked Panda (China Civilian/PLA) + FIN7 financial crime + Conti ransomware + LockBit + ALPHV BlackCat + Scattered Spider + Sandworm (Russia GRU disruptive) + Volt Typhoon (China ICS prepositioning) + Salt Typhoon (China telco) + Storm-0501 + Charming Kitten APT35 + Pioneer Kitten + MuddyWater + APT34 + Equation Group + Turla + Comment Crew. 700+ Software tools including dual-use (Cobalt Strike + Mimikatz + Empire + Metasploit + ProcDump + WMIExec + PsExec + Sliver + Brute Ratel C4 + Havoc) + malware (Emotet + TrickBot + Qakbot + Pikabot + Latrodectus + WikiLoader + Akira + RansomEXX + BlackByte + AsyncRAT + Remcos + AgentTesla + Sna
- Threat group (G-ID) profile inventory relevant to sector (APT28 + APT29 + APT38 + APT41 + Conti + LockBit + Volt Typhoon)
- Software (S-ID) detection coverage (Cobalt Strike + Mimikatz + Empire + Metasploit + Sliver + Brute Ratel)
- Sector-specific threat actor prioritisation (Healthcare/Finance/Manufacturing/Energy/Government)
- ATT&CK Navigator overlay per threat actor
- TIP integration (MISP + ThreatConnect + Anomali + Recorded Future + Mandiant)
- STIX 2.x / TAXII 2.x exchange evidence
- Threat profile not sector-aligned
- Cobalt Strike + Mimikatz detection rules missing (dual-use tools)
- STIX exchange not bidirectional with industry ISAC
- Volt Typhoon TTPs (ICS prepositioning) not assessed despite critical infrastructure scope
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.