MITRE ATT&CK® is a globally accessible knowledge base that provides information about adversary tactics and techniques based on real-world observations. It is a foundation for developing specific threat models and methodologies in various sectors, including the private sector, government, and the cybersecurity product and service community.
The ATT&CK knowledge base comprises matrices, tactics, techniques, data sources, mitigations, and groups. The matrices represent the tactics and techniques for platforms like Windows, macOS, Linux, Azure AD, and Office 365. Each tactic represents an adversary's goal or reason for acting, while techniques represent how an adversary achieves their tactical goal. Data sources in ATT&CK refer to the various subjects or topics of information that can be collected to detect different techniques or sub-techniques. Mitigations in the knowledge base suggest security concepts and technologies that can be used to prevent the successful execution of a technique or sub-technique. Finally, the group's section tracks adversary activity clusters and their associations.
The MITRE ATT&CK knowledge base provides a comprehensive and collaborative resource for understanding adversary behavior and enabling effective threat detection and prevention strategies. It is widely utilized by professionals in the cybersecurity field.
------
TryHackMe
Pyramid of Pain
MITRE ATT&CK