MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a framework developed by MITRE Corporation that provides a comprehensive list of tactics and techniques used by cyber attackers during various stages of a cyber attack. The framework is designed to assist organizations in improving their cyber defence by providing a standard language and knowledge base for discussing and analysing cyber threats.
The MITRE ATT&CK framework is organized into different stages of a cyber attack, including initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, exfiltration, and command and control. Each stage includes a list of tactics and techniques that attackers commonly use.
Tactics are the goals of an attacker during each stage of the attack, while techniques are the specific methods they use to achieve those goals. For example, a common tactic during the initial access stage is “spear phishing” while a technique used for this tactic is “social engineering.”
The framework is regularly updated with new tactics and techniques as cyber threats continue to evolve. Organizations can use the MITRE ATT&CK framework to assess their current security posture, identify potential vulnerabilities, and prioritize security controls to improve their defences against cyber attacks.