What ATT&CK is
MITRE ATT&CK organizes observed adversary goals as tactics and behaviors as techniques and sub-techniques. It supplies a common vocabulary and references. It is not a control standard, risk score, detection guarantee, or ordered attack recipe.
Use in access systems
Select techniques that match the adversary, assets, identities, credentials, routes, and applications in scope. Turn each into a system-specific hypothesis with required evidence, analytic logic, response, and blind spots.
Evidence mapping
Map identity-provider, endpoint, network, gateway, cloud, Kubernetes, and application records to the facts needed for the hypothesis. Record data gaps separately from coverage. One telemetry source can support several techniques.
Failure and residual risk
Counting mapped techniques rewards broad labels instead of useful detection. A technique can have many procedures. Attackers can use valid access that does not match a selected example. Framework updates do not validate local analytics.
Pomerium boundary
Pomerium evidence can support hypotheses about routed access, policy decisions, and selected fields. It does not cover endpoint execution, identity administration, direct network paths, or final application actions alone.
Evaluation checklist
- Which adversary behavior and protected consequence does the technique represent locally?
- Which observable facts, sources, and blind spots support the hypothesis?
- Has the analytic been tested with known behavior?
- Does the alert lead to a defined investigation and containment action?
- Is ATT&CK used as behavior vocabulary rather than a control checklist?
