Skip to content

MITRE ATT&CK Framework

The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is the industry-standard taxonomy for cataloguing attacker behaviour. Every malware type in this encyclopaedia maps to one or more ATT&CK techniques.

#TacticDescriptionGoal
1ReconnaissanceGathering information about the targetPrepare attack
2Resource DevelopmentAcquiring infrastructure and toolsPrepare attack
3Initial AccessGaining the first footholdEnter environment
4ExecutionRunning malicious codeRun code
5PersistenceMaintaining access over timeStay
6Privilege EscalationGaining higher-level permissionsEscalate
7Defence EvasionAvoiding detectionEvade
8Credential AccessStealing account credentialsSteal creds
9DiscoveryUnderstanding the environmentLearn
10Lateral MovementMoving through the networkMove
11CollectionGathering data of interestCollect
12Command and ControlMaintaining communicationCommunicate
13ExfiltrationStealing dataSteal data
14ImpactDisrupting availability or integrityDamage
Malware TypePrimary Tactics
Computer VirusExecution, Persistence, Defence Evasion, Impact
Computer WormInitial Access, Execution, Lateral Movement, Impact
Trojan HorseInitial Access, Execution, Persistence, C2
SpywareCollection, Credential Access, Exfiltration
AdwareExecution, Defence Evasion, Collection
RansomwareImpact, Exfiltration (double extortion)
RootkitDefence Evasion, Persistence, Privilege Escalation
KeyloggerCredential Access, Collection
BackdoorPersistence, C2, Execution
BotnetC2, Impact, Lateral Movement
APT MalwareAll 14 tactics
Fileless MalwareDefence Evasion, Execution, Persistence
CryptominerResource Development, Impact
Wiper MalwareImpact, Defence Evasion
Mobile MalwareInitial Access, Credential Access, Collection
Web ShellPersistence, C2, Execution
AI-PoweredAll (adaptive)
UEFI/FirmwarePersistence, Defence Evasion, Privilege Escalation
Supply ChainInitial Access, Resource Development
OT/ICSImpact, Lateral Movement, Defence Evasion
Polymorphic/MetamorphicDefence Evasion
TechniqueIDCommon in
PhishingT1566Trojan, APT, Ransomware
Exploit Public-Facing AppT1190Worm, APT, Botnet
PowerShellT1059.001Fileless, APT, Ransomware
WMIT1047Fileless, APT
Process InjectionT1055Rootkit, Fileless, APT
Scheduled TaskT1053.005Persistence (many)
Process HollowingT1055.012Fileless, APT
DCSyncT1003.006APT, Ransomware
LSASS MemoryT1003.001Credential theft (many)
Pass the HashT1550.002Lateral Movement
SMB/Windows Admin SharesT1021.002Lateral Movement
Data EncryptedT1486Ransomware, Wiper
Inhibit System RecoveryT1490Ransomware, Wiper
Data Encrypted for ImpactT1486Ransomware
Exfiltration Over C2T1041Spyware, APT, Ransomware
Use CaseApproach
Threat IntelligenceMap IOCs → techniques → tactics
Detection EngineeringBuild detections per technique
Red TeamingEmulate specific APT TTPs
Gap AnalysisMap coverage → find gaps
Threat HuntingHunt for specific techniques
Purple TeamRed executes → Blue detects