MITRE ATT&CK
Tactics - MITRE ATT&CK Enterprise Kill Chain

MITRE ATT&CK MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact: MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact

Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations. TA0042 Resource Development - establishing resources to support operations. TA0001 Initial Access - getting into target network. TA0002 Execution - running adversary-controlled code. TA0003 Persistence - maintaining footholds across restarts and credential changes. TA0004 Privilege Escalation - gaining higher-level permissions. TA0005 Defense Evasion - avoiding detection. TA0006 Credential Access - stealing account names and passwords. TA0007 Discovery - gaining knowledge about target environment. TA0008 Lateral Movement - moving through environment. TA0009 Collection - gathering information of interest. TA0011 Command and Control - communicating with compromised systems. TA0010 Exfiltration - stealing data from environment. TA0040 Impact - manipulating + interrupting + destroying systems and data. Mobile matrix uses 12 similar tactics covering iOS + Android. ICS matrix uses 12 tactics including Initial Access + Execution + Persistence + Discovery + Lateral Movement + Collection + Command and Control + Inhibit Response Function + Impair Process Control + Impact covering operational technology environments. Tactics provide tactical-level mapping for threat hunting + detection engineering + red team exercises + purple team exercises + blue team training.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 16 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal

ISO/SAE 21434 · 3 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • CPG-2.A Asset Inventory
  • CPG-2.B Prohibit Connection of Unauthorized Devices

MITRE D3FEND · 2 controls

ISO/IEC 27010:2015 · 1 control

  • 27010-8.1 Membership Onboarding

OWASP ASVS · 1 control

OWASP MASVS · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.