MITRE ATT&CK
What is MITRE ATT&CK?
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) derived from real-world observations.. It comprises 8 controls organised across 8 domains, and applies in International.
How MITRE ATT&CK maps to other frameworks
All 8 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 8 domains MITRE ATT&CK groups its controls into
Where MITRE ATT&CK overlaps with the standards you already hold
Where to get trained on MITRE ATT&CK
4 courses in the catalogue cover MITRE ATT&CK directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What MITRE ATT&CK means in your sector
What MITRE ATT&CK means for your job
Questions people ask about MITRE ATT&CK
What is MITRE ATT&CK?
How many controls does MITRE ATT&CK have?
Where does MITRE ATT&CK apply?
What frameworks does MITRE ATT&CK map to?
How do I get started with MITRE ATT&CK compliance?
Query MITRE ATT&CK programmatically
MITRE ATT&CK, its 8 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
MITRE ATT&CK API reference and MCP config →What MITRE ATT&CK requires, control by control
Each page carries the requirement text for one MITRE ATT&CK control and what an assessor expects to see as evidence.
- MITRE-ATTACK-DETECTION-DATA-SOURCES-ANALYTICS-SIGMA-SPLUNK-KQL-YARA-SNORT-SIEM-HUNT-ENGINEERING MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + Splunk + KQL + Yara + Snort + SIEM + Hunt
- MITRE-ATTACK-MATRICES-ENTERPRISE-MOBILE-ICS-CLOUD-AWS-AZURE-GOOGLE-OFFICE-365-CONTAINER-PLATFORM-SPECIFIC MITRE ATT&CK Matrices + Enterprise + Mobile + ICS + Cloud + AWS + Azure + Google + Office 365 + Container
- MITRE-ATTACK-MITIGATIONS-M-IDS-ACTIVE-DIRECTORY-USER-ACCOUNT-MANAGEMENT-PASSWORD-POLICIES-NETWORK-SEGMENTATION MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control
- MITRE-ATTACK-SCOPE-ADVERSARIAL-TACTICS-TECHNIQUES-MITRE-CORPORATION-2013-V15-V16-ENTERPRISE-MOBILE-ICS-CLOUD MITRE ATT&CK Scope + MITRE Corporation 2013 + v15 + v16 + Enterprise + Mobile + ICS + Cloud + Container
- MITRE-ATTACK-TACTICS-14-ENTERPRISE-KILL-CHAIN-RECONNAISSANCE-INITIAL-ACCESS-DISCOVERY-LATERAL-MOVEMENT-IMPACT MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact
- MITRE-ATTACK-TECHNIQUES-SUB-TECHNIQUES-200-600-T1078-T1059-T1566-T1190-T1486-PROCEDURES-ADVERSARY-BEHAVIOUR MITRE ATT&CK Techniques + 200+ + Sub-Techniques + 600+ + T1078 + T1059 + T1566 + T1190 + T1486 + Procedures
How ready are you for MITRE ATT&CK?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.