Last updated: April 29, 2026
MITRE ATT&CK is the de-facto common language. Operationalising it requires discipline.
The structure
- Tactics (14) — adversary goals (Initial Access, Execution, Persistence, etc.)
- Techniques (~200) — how the goal is achieved
- Sub-techniques — specific variants
- Procedures — actor-specific implementation
ATT&CK Navigator
Free tool for visualising layers. Use cases:
- Coverage map — which techniques have detections
- Threat-actor overlay — which techniques does a specific actor use
- Engagement plan — red team selects techniques to test
Threat-group profiling
For your industry, identify likely threat actors. ATT&CK has profiles. Overlay actor TTPs vs your coverage. Gaps = priority.
Gap analysis
Most environments cover Initial Access well, miss Lateral Movement and Defense Evasion. Plan accordingly.
Module Quiz · 6 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.