Apply the 14 Enterprise Tactics representing the adversary tactical goals during cyberattack phases (kill chain). TA0043 Reconnaissance - gathering information for planning future operations. TA0042 Resource Development - establishing resources to support operations. TA0001 Initial Access - getting into target network. TA0002 Execution - running adversary-controlled code. TA0003 Persistence - maintaining footholds across restarts and credential changes. TA0004 Privilege Escalation - gaining higher-level permissions. TA0005 Defense Evasion - avoiding detection. TA0006 Credential Access - stealing account names and passwords. TA0007 Discovery - gaining knowledge about target environment. TA0008 Lateral Movement - moving through environment. TA0009 Collection - gathering information of interest. TA0011 Command and Control - communicating with compromised systems. TA0010 Exfiltration - stealing data from environment. TA0040 Impact - manipulating + interrupting + destroying systems and data. Mobile matrix uses 12 similar tactics covering iOS + Android. ICS matrix uses 12 tactics including Initial Access + Execution + Persistence + Discovery + Lateral Movement + Collection + Command and Control + Inhibit Response Function + Impair Process Control + Impact covering operational technology environments. Tactics provide tactical-level mapping for threat hunting + detection engineering + red team exercises + purple team exercises + blue team training.
This control maps to 16 controls across 10 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 16 it maps to, and the evidence behind each claim, over MCP and REST.