Skip to main content

MITRE ATT&CK

MITRE ATT&CK catalogs observed adversary tactics and techniques that can guide hypotheses, detections, and investigations.

What ATT&CK is

MITRE ATT&CK organizes observed adversary goals as tactics and behaviors as techniques and sub-techniques. It supplies a common vocabulary and references. It is not a control standard, risk score, detection guarantee, or ordered attack recipe.

Use in access systems

Select techniques that match the adversary, assets, identities, credentials, routes, and applications in scope. Turn each into a system-specific hypothesis with required evidence, analytic logic, response, and blind spots.

Evidence mapping

Map identity-provider, endpoint, network, gateway, cloud, Kubernetes, and application records to the facts needed for the hypothesis. Record data gaps separately from coverage. One telemetry source can support several techniques.

Failure and residual risk

Counting mapped techniques rewards broad labels instead of useful detection. A technique can have many procedures. Attackers can use valid access that does not match a selected example. Framework updates do not validate local analytics.

Pomerium boundary

Pomerium evidence can support hypotheses about routed access, policy decisions, and selected fields. It does not cover endpoint execution, identity administration, direct network paths, or final application actions alone.

Evaluation checklist

  • Which adversary behavior and protected consequence does the technique represent locally?
  • Which observable facts, sources, and blind spots support the hypothesis?
  • Has the analytic been tested with known behavior?
  • Does the alert lead to a defined investigation and containment action?
  • Is ATT&CK used as behavior vocabulary rather than a control checklist?

Sources and further reading

Keep learning

Security Engineering FoundationsSecurity Operations and Risk

Adversary Model

State who can attack the system, what they want, what they can do, where they start, and what constrains them.

Learn this term
Security Operations and Risk

Intrusion Detection

An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo