Intelligent Automation MCSP Badge
Intelligent Automation Your Managed Cybersecurity Services Provider
MITRE ATT&CK® ↗
Powered by MITRE ATT&CK® Knowledge Base

MITRE ATT&CK®
Interactive Framework

A simplified, interactive explorer of adversary tactics, techniques, and procedures. Aligned with CIS Controls and CISSP domains — powered by Intelligent Automation's cybersecurity practice.

⚠️ All ATT&CK® content is the intellectual property of  The MITRE Corporation  — used under open license. ATT&CK® is a registered trademark of The MITRE Corporation.
14Tactics
196+Techniques
411+Sub-Techniques
135+Threat Groups
3Platforms
🔍
ATT&CK® Matrix — Enterprise
Showing all techniques
Techniques — List View
ID Technique Name Tactic Sub-Techniques
Framework Alignment
CIS
CIS Controls v8
Center for Internet Security — 18 Critical Security Controls
CIS Control 1 — Inventory & Control of Enterprise Assets
CIS Control 3 — Data Protection
CIS Control 4 — Secure Configuration of Enterprise Assets
CIS Control 5 — Account Management
CIS Control 6 — Access Control Management
CIS Control 7 — Continuous Vulnerability Management
CIS Control 8 — Audit Log Management
CIS Control 9 — Email & Web Browser Protections
CIS Control 13 — Network Monitoring & Defense
CIS Control 17 — Incident Response Management
ISC²
CISSP Domains
Certified Information Systems Security Professional — 8 Domains
Domain 1 — Security & Risk Management
Domain 2 — Asset Security
Domain 3 — Security Architecture & Engineering
Domain 4 — Communication & Network Security
Domain 5 — Identity & Access Management (IAM)
Domain 6 — Security Assessment & Testing
Domain 7 — Security Operations
Domain 8 — Software Development Security
About ATT&CK® Tactics
🕵️

Reconnaissance (TA0043)

Gathering information to plan future adversary operations — scanning, phishing for info, OSINT. Maps to CIS Control 7 & CISSP Domain 6.

🛠️

Resource Development (TA0042)

Establishing resources to support operations — acquiring infrastructure, malware development. Maps to CIS Control 4 & CISSP Domain 3.

🚪

Initial Access (TA0001)

Gaining a foothold in the network — phishing, exploiting public-facing apps, supply chain. Maps to CIS Controls 9,10 & CISSP Domain 4.

Execution (TA0002)

Running malicious code — scripts, WMI, scheduled tasks, user execution. Maps to CIS Controls 2,4 & CISSP Domain 7.

🔗

Persistence (TA0003)

Maintaining a foothold across restarts — boot/logon autostart, account manipulation. Maps to CIS Control 5 & CISSP Domain 5.

⬆️

Privilege Escalation (TA0004)

Gaining higher-level permissions — abuse elevation control, process injection. Maps to CIS Control 6 & CISSP Domain 5.

🛡️

Defense Evasion (TA0005)

Avoiding detection — obfuscation, disabling security tools, masquerading. Maps to CIS Controls 8,10 & CISSP Domain 7.

🔑

Credential Access (TA0006)

Stealing credentials — brute force, credential dumping, keylogging. Maps to CIS Controls 4,5 & CISSP Domain 5.

🔎

Discovery (TA0007)

Environment reconnaissance post-compromise — account discovery, network scanning. Maps to CIS Control 13 & CISSP Domain 4.

↔️

Lateral Movement (TA0008)

Pivoting through the environment — remote services, pass-the-hash. Maps to CIS Controls 4,13 & CISSP Domain 4.

📦

Collection (TA0009)

Gathering data of interest — clipboard data, email, screen capture. Maps to CIS Controls 3,13 & CISSP Domain 2.

📡

Command & Control (TA0011)

Communicating with compromised systems — encrypted channels, domain fronting. Maps to CIS Control 13 & CISSP Domain 4.

📤

Exfiltration (TA0010)

Stealing data — over C2, cloud storage, physical medium. Maps to CIS Controls 3,13 & CISSP Domain 2.

💥

Impact (TA0040)

Disrupting availability or integrity — ransomware, defacement, data destruction. Maps to CIS Control 11 & CISSP Domain 7.

Overview

Key Topics

Mitigations & Recommendations

Framework Mappings