Nexus Void Research

MITRE ATT&CK, Red Team, TTPs, Threat Detection, Adversary Simulation

What Is the MITRE ATT&CK Framework? (2026 Guide)

What is the MITRE ATT&CK framework? A plain-English guide to tactics, techniques, and procedures, the ATT&CK matrices, and how red and blue teams use it.

The MITRE ATT&CK framework is a free, globally used knowledge base of real-world adversary behavior, organized into tactics (the attacker's goals) and techniques (how they achieve them), maintained by MITRE. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge, and it gives defenders a shared language for describing exactly how attacks unfold, from initial access to data exfiltration, based on observed real-world campaigns rather than theory.

Understanding what MITRE ATT&CK is helps because it turns vague notions of "a hack" into a precise map. Instead of saying an attacker "got in and stole data," ATT&CK lets teams say they used a specific technique for initial access, another for privilege escalation, and another for exfiltration, each with an ID, detection guidance, and mitigations.

How is the ATT&CK framework structured?

ATT&CK is organized as a matrix of tactics and techniques. Tactics are the columns, representing the adversary's objective at each phase, and techniques are the entries under each tactic, representing the specific methods used. The Enterprise matrix, the most widely used, is built around 14 tactics.

Concept

Meaning

Example

Tactic

The attacker's goal in a phase

Initial Access, Privilege Escalation

Technique

How the goal is achieved

Phishing, Valid Accounts

Sub-technique

A more specific method

Spearphishing Attachment

Procedure

A real observed implementation

A named group's use of a technique

MITRE maintains separate matrices for Enterprise (Windows, macOS, Linux, cloud, containers), Mobile, and ICS (industrial control systems), so the framework covers most environments defenders care about.

How do red and blue teams use MITRE ATT&CK?

Both sides use it as a common map. Red teams and adversary-simulation engagements use ATT&CK to plan and describe attacks, ensuring they emulate realistic techniques rather than arbitrary ones, and to report findings in terms defenders can act on. Blue teams and detection engineers use it to measure coverage: they map their detections to ATT&CK techniques to find gaps, then prioritize building detection for the techniques most relevant to their threats.

The ATT&CK Navigator, a free tool from MITRE, lets teams visualize this coverage by color-coding techniques, which is why ATT&CK has become the default way to discuss detection completeness. Threat-intelligence reports and CISA advisories now routinely tag adversary behavior with ATT&CK technique IDs.

Why does ATT&CK matter for testing your defenses?

Because it grounds security testing in what attackers actually do. An assessment mapped to ATT&CK answers a sharper question than a vulnerability scan: not just "what is vulnerable" but "which real attacker techniques would succeed against us, and would we detect them." That behavior-based view is exactly what separates a checkbox test from a meaningful measure of resilience.

Frequently asked questions

Is MITRE ATT&CK free? Yes. The knowledge base, the matrices, and the ATT&CK Navigator are all freely available from MITRE.

What is the difference between ATT&CK and the Cyber Kill Chain? The Kill Chain is a high-level linear model of attack phases; ATT&CK is a detailed, non-linear catalog of specific techniques within phases, with far more granularity.

What is MITRE ATLAS? ATLAS is a related MITRE knowledge base focused on adversary techniques against AI and machine-learning systems, complementing ATT&CK for AI security.

Our read

ATT&CK's value is that it makes "are we secure" a testable question instead of a feeling. The strongest programs treat it as a scorecard: emulate real techniques, then measure whether detection and response actually fired. That is the heart of supervised adversary simulation, using the same technique map an attacker would, verifying coverage technique by technique rather than trusting that tools work. A detection you have never exercised against a real ATT&CK technique is a hypothesis, not a control.

Tactics, techniques, and matrix structure per MITRE ATT&CK. Sources linked above.

Related: Red team vs penetration test and AI agent security risks in 2026.

DATA SOURCES

MITRE ATT&CK — https://attack.mitre.org/ ; MITRE — https://www.mitre.org/ ; CISA — https://www.cisa.gov/

Liked this post? Share it:

Related posts

Related posts appear on the live page

VIEW ALL RESEARCH ->

PAGE CONTENTS

Contents appear on the live page

// FROM THE LAB

Pentesting is easy and affordable now.

Continuous VAPT you can run every month, with a report built for AI-built apps.

RUN A VAPT ->

// CYBER NETWORK

Shape the next analysis.

A curated network of security practitioners who help set our research agenda. By application.

APPLY TO JOIN ->

Get new research first

We publish original analysis and experiments on how attackers actually move. Follow along: