It describes why adversaries act through tactics, how they pursue those goals through techniques and sub-techniques, and specific observed implementations through procedures. Separate ATT&CK domains cover enterprise, mobile, and industrial control system environments.
Defenders use the common language to structure threat intelligence, inform detection and hunting, plan authorized adversary emulation, and discuss control evidence. Technique identifiers help connect work across teams and tools, but mappings should retain scope, platform, version, evidence, and confidence.
Key points
Model structureTactics express objectives; techniques and sub-techniques describe behaviors; procedures document concrete observed uses by groups, campaigns, or software.
PrioritizationSelect behavior relevant to the organization’s systems, exposures, intelligence, and risk rather than treating every matrix cell as equally important.
ValidationFor each claimed detection or mitigation, test realistic variations and confirm the necessary telemetry, analytic logic, control placement, and response path.
Important limitationATT&CK is not a compliance standard, complete catalog of adversary behavior, or ready-made detection checklist. A mapped control does not prove reliable coverage, and pursuing 100 percent matrix coverage can misdirect effort.