# What is MITRE ATT&CK?

> MITRE ATT&CK is a publicly accessible, maintained knowledge base that organizes adversary behavior observed in real-world activity.

- Canonical URL: https://yellowcube.eu/glossary/mitre-att-and-ck-adversarial-tactics-techniques-and-common-knowledge/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It describes why adversaries act through tactics, how they pursue those goals through techniques and sub-techniques, and specific observed implementations through procedures. Separate ATT&CK domains cover enterprise, mobile, and industrial control system environments.

Defenders use the common language to structure threat intelligence, inform detection and hunting, plan authorized adversary emulation, and discuss control evidence. Technique identifiers help connect work across teams and tools, but mappings should retain scope, platform, version, evidence, and confidence.

### Key points

- **Model structure:** Tactics express objectives; techniques and sub-techniques describe behaviors; procedures document concrete observed uses by groups, campaigns, or software.
- **Prioritization:** Select behavior relevant to the organization’s systems, exposures, intelligence, and risk rather than treating every matrix cell as equally important.
- **Validation:** For each claimed detection or mitigation, test realistic variations and confirm the necessary telemetry, analytic logic, control placement, and response path.
- **Important limitation:** ATT&CK is not a compliance standard, complete catalog of adversary behavior, or ready-made detection checklist. A mapped control does not prove reliable coverage, and pursuing 100 percent matrix coverage can misdirect effort.

### Related terms

[Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>) · [Red team](<https://yellowcube.eu/glossary/red-team/>) · [Cyber kill chain](<https://yellowcube.eu/glossary/cyber-kill-chain/>)

### Sources

[MITRE ATT&CK: Get Started](https://attack.mitre.org/resources/) · [MITRE ATT&CK Website Changelog](https://attack.mitre.org/resources/changelog.html)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

