GLOBAL · Framework

MITRE ATT&CK — MITRE ATT&CK Framework

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used as a foundation for developing threat models and methodologies.

What it is

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used as a foundation for developing threat models and methodologies.

Global (knowledge base) · Continuously updated by MITRE

Who it binds

Voluntary; used by security teams worldwide for red-team exercises, detection engineering, vulnerability assessment and board reporting.

Key obligations

  • Map attack tactics to your threat profile
  • Assess detection coverage per technique
  • Conduct red-team exercises based on real adversary behaviour
  • Report and remediate coverage gaps

How CCI addresses it

PenTeva simulates ATT&CK techniques in a controlled environment; CySSURANCE maps your detection coverage against the matrix so you know precisely which techniques your defences do not cover.

PenTeva → CySSURANCE platform →

Official source

MITRE ATT&CK Enterprise Matrix

https://attack.mitre.org/

The linked text is the authoritative legal or standards source. CCI maps to it; it is not a CCI publication.

← All frameworks