MITRE ATT&CK
MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) derived from real-world observations.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Detection Engineering and Data Sources - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering | MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + Splunk + KQL + Yara + Snort + SIEM + Hunt |
Integration and Ecosystem - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Integration-Engenuity-Evaluations-CALDERA-NIST-CSF-CIS-Lockheed-Kill-Chain-Diamond-Model-STIX-TAXII | MITRE ATT&CK Integration + MITRE Engenuity + ATT&CK Evaluations + CALDERA + NIST CSF + CIS + STIX + TAXII |
Matrices and Platforms - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Matrices-Enterprise-Mobile-ICS-Cloud-AWS-Azure-Google-Office-365-Container-Platform-Specific | MITRE ATT&CK Matrices + Enterprise + Mobile + ICS + Cloud + AWS + Azure + Google + Office 365 + Container |
Mitigations and Controls - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Mitigations-M-IDs-Active-Directory-User-Account-Management-Password-Policies-Network-Segmentation | MITRE ATT&CK Mitigations + M-IDs + Active Directory + User Account + Password + Network Segmentation + Application Control |
Scope and Foundation - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Scope-Adversarial-Tactics-Techniques-MITRE-Corporation-2013-v15-v16-Enterprise-Mobile-ICS-Cloud | MITRE ATT&CK Scope + MITRE Corporation 2013 + v15 + v16 + Enterprise + Mobile + ICS + Cloud + Container |
Tactics - MITRE ATT&CK Enterprise Kill Chain
| Code | Title |
|---|---|
| MITRE-ATTACK-Tactics-14-Enterprise-Kill-Chain-Reconnaissance-Initial-Access-Discovery-Lateral-Movement-Impact | MITRE ATT&CK 14 Enterprise Tactics + Reconnaissance + Initial Access + Discovery + Lateral Movement + Impact |
Techniques and Sub-Techniques - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Techniques-Sub-Techniques-200-600-T1078-T1059-T1566-T1190-T1486-Procedures-Adversary-Behaviour | MITRE ATT&CK Techniques + 200+ + Sub-Techniques + 600+ + T1078 + T1059 + T1566 + T1190 + T1486 + Procedures |
Threat Groups and Software - MITRE ATT&CK
| Code | Title |
|---|---|
| MITRE-ATTACK-Threat-Groups-Software-APT28-APT29-APT38-APT41-FIN7-Conti-LockBit-Lazarus-Cobalt-Strike-Mimikatz | MITRE ATT&CK Threat Groups + Software + APT28 + APT29 + APT41 + FIN7 + Conti + Lazarus + Cobalt Strike + Mimikatz |
Your Compliance Coverage
If you comply with MITRE ATT&CK, you already cover:
OWASP MASVS
75%
6 controls mapped
Compare →OWASP ASVS
75%
6 controls mapped
Compare →MITRE D3FEND
75%
6 controls mapped
Compare →+ 143 more: NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices (75%), ISO 27043 (75%)
See all 146 mapped frameworks ↓Maps to 146 other frameworks
Frequently Asked Questions
What is MITRE ATT&CK?
MITRE ATT&CK is a compliance framework from International with 8 domains and 8 controls. MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) derived from real-world observations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does MITRE ATT&CK have?
MITRE ATT&CK has 8 controls organised across 8 domains. The largest domains are Detection Engineering and Data Sources - MITRE ATT&CK (1 controls), Integration and Ecosystem - MITRE ATT&CK (1 controls), Matrices and Platforms - MITRE ATT&CK (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does MITRE ATT&CK map to?
MITRE ATT&CK maps to 146 other compliance frameworks. The top mapping partners are OWASP MASVS (75% coverage), OWASP ASVS (75% coverage), MITRE D3FEND (75% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with MITRE ATT&CK compliance?
Start your MITRE ATT&CK compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about MITRE ATT&CK requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required