MITRE ATT&CK
Techniques and Sub-Techniques - MITRE ATT&CK

MITRE ATT&CK MITRE-ATTACK-Techniques-Sub-Techniques-200-600-T1078-T1059-T1566-T1190-T1486-Procedures-Adversary-Behaviour: MITRE ATT&CK Techniques + 200+ + Sub-Techniques + 600+ + T1078 + T1059 + T1566 + T1190 + T1486 + Procedures

Catalogue and analyse adversary techniques and sub-techniques. ATT&CK Enterprise contains 200+ techniques + 600+ sub-techniques as of v16 (October 2024). Each technique has unique ID (T-NNNN) + Name + Description + Tactics + Procedure Examples + Mitigations + Detection guidance + Platforms + Data Sources. Key technique examples: T1078 Valid Accounts (legitimate credentials abuse) + T1059 Command and Scripting Interpreter (PowerShell + Bash + Python + JavaScript + AppleScript) + T1566 Phishing (Spearphishing Attachment + Link + Service) + T1190 Exploit Public-Facing Application (CVE exploitation) + T1486 Data Encrypted for Impact (ransomware) + T1110 Brute Force + T1003 OS Credential Dumping (LSASS + SAM + DCSync) + T1218 System Binary Proxy Execution (Living off the Land) + T1055 Process Injection + T1071 Application Layer Protocol (DNS + HTTPS + IRC + DNS C2) + T1567 Exfiltration Over Web Service + T1027 Obfuscated Files + T1547 Boot or Logon Autostart Execution. Sub-Techniques provide more specific descriptions (e.g. T1078.001 Default Accounts + T1078.002 Domain Accounts + T1078.003 Local Accounts + T1078.004 Cloud Accounts). Procedure Examples document specific real-world implementations by named threat groups (APT28 + APT29 + APT38 + APT41 + FIN7 + Conti + LockBit + Lazarus + Volt Typhoon + Scattered Spider + Sandworm + many others) and tools (Cobalt Strike + Mimikatz + Empire + Metasploit + ProcDump + WMIExec + PsExec). Each technique describes adversary behaviour pattern that defenders can detect + mitigate + hunt for.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 112 controls across 53 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 6 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal
  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification

ISO/SAE 21434 · 6 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification

API 1164 · 4 controls

  • API1164-02 Risk Management Framework
  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management

BSI IT-Grundschutz · 4 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-15 Security categorization

IEC 62443 · 4 controls

  • IEC62443-02 System security categorization
  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 27010:2015 · 4 controls

  • 27010-8.1 Membership Onboarding
  • 27010-8.2 Membership Termination
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27019:2024 · 4 controls

  • ISO27019-02 System security categorization
  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures
  • CFR211-G-122 Section 211.122 - Materials Examination and Usage Criteria
  • CFR211-G-125 Section 211.125 - Labeling Issuance
  • CFR211-G-130 Section 211.130 - Packaging and Labeling Operations

ISO 27799:2025 · 3 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-08 Information access management
  • ISO27799-17 Facility access controls

OWASP ASVS · 3 controls

  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls

ISO/IEC 27011:2024 · 2 controls

  • 27011-5.3 Segregation of duties
  • 27011-8.1 User Endpoint Devices

MITRE D3FEND · 2 controls

OWASP MASVS · 2 controls

  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security
  • IM8-DAT.1 Data Classification
  • IM8-SEC.2 Access Control

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control

APPI · 1 control

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person

Bahrain PDPL · 1 control

  • CA-ITSG33-SC-01 Security Control Catalogue
  • QMSR-820.45 Device labelling and packaging controls (§820.45)
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • IATA-IOSA-Section8-SEC-SecurityManagement-AVSEC IATA IOSA Section 8 - SEC Security Management + Aviation Security Programme (AVSEC) + ICAO Annex 17 Alignment
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • 60601-1.7.1 Equipment identification and marking
  • 62351-8 Role-based access control (RBAC)
  • ISO-14064-1-5.4 Categorization of indirect GHG emissions
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services

ITIL 4 · 1 control

  • ITIL4-15 Access management for services

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing

Mauritius DPA · 1 control

  • MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014
  • MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management

OWASP Top 10:2025 · 1 control

  • AUPRV-4 APP 10-11 Quality, Security of Personal Information

South Korea PIPA · 1 control

  • PIPA-Cross-Border-Transfer-Articles-28-8-28-9-Adequacy-Standard-Contract-Certification-EU Korea PIPA Cross-Border Transfer + Articles 28-8 + 28-9 + Adequacy + EU 2021

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 112 it maps to, and the evidence behind each claim, over MCP and REST.