MITRE ATT&CK
Tactics - MITRE ATT&CK Enterprise Kill Chain

MITRE ATT&CK MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact: MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact

Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations. TA0042 Resource Development - establishing resources to support operations. TA0001 Initial Access - getting into target network. TA0002 Execution - running adversary-controlled code. TA0003 Persistence - maintaining footholds across restarts and credential changes. TA0004 Privilege Escalation - gaining higher-level permissions. TA0005 Defense Evasion - avoiding detection. TA0006 Credential Access - stealing account names and passwords. TA0007 Discovery - gaining knowledge about target environment. TA0008 Lateral Movement - moving through environment. TA0009 Collection - gathering information of interest. TA0011 Command and Control - communicating with compromised systems. TA0010 Exfiltration - stealing data from environment. TA0040 Impact - manipulating + interrupting + destroying systems and data. Mobile matrix uses 12 similar tactics covering iOS + Android. ICS matrix uses 12 tactics including Initial Access + Execution + Persistence + Discovery + Lateral Movement + Collection + Command and Control + Inhibit Response Function + Impair Process Control + Impact covering operational technology environments. Tactics provide tactical-level mapping for threat hunting + detection engineering + red team exercises + purple team exercises + blue team training.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.