MITRE ATT&CK
Techniques and Sub-Techniques - MITRE ATT&CK

MITRE ATT&CK MITRE-ATTACK-Techniques-Sub-Techniques-200-600-T1078-T1059-T1566-T1190-T1486-Procedures-Adversary-Behaviour: MITRE ATT&CK Techniques + 200+ + Sub-Techniques + 600+ + T1078 + T1059 + T1566 + T1190 + T1486 + Procedures

Catalogue and analyse adversary techniques and sub-techniques. ATT&CK Enterprise contains 200+ techniques + 600+ sub-techniques as of v16 (October 2024). Each technique has unique ID (T-NNNN) + Name + Description + Tactics + Procedure Examples + Mitigations + Detection guidance + Platforms + Data Sources. Key technique examples: T1078 Valid Accounts (legitimate credentials abuse) + T1059 Command and Scripting Interpreter (PowerShell + Bash + Python + JavaScript + AppleScript) + T1566 Phishing (Spearphishing Attachment + Link + Service) + T1190 Exploit Public-Facing Application (CVE exploitation) + T1486 Data Encrypted for Impact (ransomware) + T1110 Brute Force + T1003 OS Credential Dumping (LSASS + SAM + DCSync) + T1218 System Binary Proxy Execution (Living off the Land) + T1055 Process Injection + T1071 Application Layer Protocol (DNS + HTTPS + IRC + DNS C2) + T1567 Exfiltration Over Web Service + T1027 Obfuscated Files + T1547 Boot or Logon Autostart Execution. Sub-Techniques provide more specific descriptions (e.g. T1078.001 Default Accounts + T1078.002 Domain Accounts + T1078.003 Local Accounts + T1078.004 Cloud Accounts). Procedure Examples document specific real-world implementations by named threat groups (APT28 + APT29 + APT38 + APT41 + FIN7 + Conti + LockBit + Lazarus + Volt Typhoon + Scattered Spider + Sandworm + many others) and tools (Cobalt Strike + Mimikatz + Empire + Metasploit + ProcDump + WMIExec + PsExec). Each technique describes adversary behaviour pattern that defenders can detect + mitigate + hunt for.

What else in your programme already covers this

This control maps to 120 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27043 · 6 controls

ISO/SAE 21434 · 6 controls

API 1164 · 4 controls

BSI IT-Grundschutz · 4 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-15 Security categorization

IEC 62443 · 4 controls

ISO 27019 · 4 controls

ISO/IEC 27010:2015 · 4 controls

  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO 13485 · 3 controls

ISO 27799 · 3 controls

OWASP ASVS · 3 controls

ISO/IEC 27011:2024 · 2 controls

MITRE D3FEND · 2 controls

OWASP MASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

South Korea ISMS-P · 2 controls

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)

ISO 20000-1 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ITIL 4 · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • 3.10 Encrypt Sensitive Data in Transit
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea PIPA · 1 control

Turkey KVKK · 1 control

  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 120 it maps to, and the evidence behind each claim, over MCP and REST.