MITRE ATT&CK Framework
Overview
Section titled “Overview”The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is the industry-standard taxonomy for cataloguing attacker behaviour. Every malware type in this encyclopaedia maps to one or more ATT&CK techniques.
The 14 Tactics
Section titled “The 14 Tactics”| # | Tactic | Description | Goal |
|---|---|---|---|
| 1 | Reconnaissance | Gathering information about the target | Prepare attack |
| 2 | Resource Development | Acquiring infrastructure and tools | Prepare attack |
| 3 | Initial Access | Gaining the first foothold | Enter environment |
| 4 | Execution | Running malicious code | Run code |
| 5 | Persistence | Maintaining access over time | Stay |
| 6 | Privilege Escalation | Gaining higher-level permissions | Escalate |
| 7 | Defence Evasion | Avoiding detection | Evade |
| 8 | Credential Access | Stealing account credentials | Steal creds |
| 9 | Discovery | Understanding the environment | Learn |
| 10 | Lateral Movement | Moving through the network | Move |
| 11 | Collection | Gathering data of interest | Collect |
| 12 | Command and Control | Maintaining communication | Communicate |
| 13 | Exfiltration | Stealing data | Steal data |
| 14 | Impact | Disrupting availability or integrity | Damage |
Malware-to-Tactic Mapping
Section titled “Malware-to-Tactic Mapping”| Malware Type | Primary Tactics |
|---|---|
| Computer Virus | Execution, Persistence, Defence Evasion, Impact |
| Computer Worm | Initial Access, Execution, Lateral Movement, Impact |
| Trojan Horse | Initial Access, Execution, Persistence, C2 |
| Spyware | Collection, Credential Access, Exfiltration |
| Adware | Execution, Defence Evasion, Collection |
| Ransomware | Impact, Exfiltration (double extortion) |
| Rootkit | Defence Evasion, Persistence, Privilege Escalation |
| Keylogger | Credential Access, Collection |
| Backdoor | Persistence, C2, Execution |
| Botnet | C2, Impact, Lateral Movement |
| APT Malware | All 14 tactics |
| Fileless Malware | Defence Evasion, Execution, Persistence |
| Cryptominer | Resource Development, Impact |
| Wiper Malware | Impact, Defence Evasion |
| Mobile Malware | Initial Access, Credential Access, Collection |
| Web Shell | Persistence, C2, Execution |
| AI-Powered | All (adaptive) |
| UEFI/Firmware | Persistence, Defence Evasion, Privilege Escalation |
| Supply Chain | Initial Access, Resource Development |
| OT/ICS | Impact, Lateral Movement, Defence Evasion |
| Polymorphic/Metamorphic | Defence Evasion |
Key Technique Highlights
Section titled “Key Technique Highlights”| Technique | ID | Common in |
|---|---|---|
| Phishing | T1566 | Trojan, APT, Ransomware |
| Exploit Public-Facing App | T1190 | Worm, APT, Botnet |
| PowerShell | T1059.001 | Fileless, APT, Ransomware |
| WMI | T1047 | Fileless, APT |
| Process Injection | T1055 | Rootkit, Fileless, APT |
| Scheduled Task | T1053.005 | Persistence (many) |
| Process Hollowing | T1055.012 | Fileless, APT |
| DCSync | T1003.006 | APT, Ransomware |
| LSASS Memory | T1003.001 | Credential theft (many) |
| Pass the Hash | T1550.002 | Lateral Movement |
| SMB/Windows Admin Shares | T1021.002 | Lateral Movement |
| Data Encrypted | T1486 | Ransomware, Wiper |
| Inhibit System Recovery | T1490 | Ransomware, Wiper |
| Data Encrypted for Impact | T1486 | Ransomware |
| Exfiltration Over C2 | T1041 | Spyware, APT, Ransomware |
Using ATT&CK for Defence
Section titled “Using ATT&CK for Defence”| Use Case | Approach |
|---|---|
| Threat Intelligence | Map IOCs → techniques → tactics |
| Detection Engineering | Build detections per technique |
| Red Teaming | Emulate specific APT TTPs |
| Gap Analysis | Map coverage → find gaps |
| Threat Hunting | Hunt for specific techniques |
| Purple Team | Red executes → Blue detects |
Resources
Section titled “Resources”Related
Section titled “Related”- Universal Defence — Defence pillars
- Threat Hunting — ATT&CK-based hunting
- APT Malware — Full tactic coverage