Module 4 · MITRE ATT&CK in Operations

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Apr 22, 2026
5 min read
Read as

Last updated: April 29, 2026

ATT&CK taxonomy, tactics and sub-techniques, Navigator for coverage mapping, detection-as-technique, D3FEND.

MITRE ATT&CK is the industry’s shared language for describing how adversaries operate. It is a taxonomy of 14 tactics, 200+ techniques, and 500+ sub-techniques, updated continuously. Used well, it structures CTI reports, maps detection coverage, scopes red-team exercises, and communicates across teams. Used as a checklist to pad reports, it produces noise. This module covers operational use of ATT&CK.

Structure of ATT&CK

  • Tactic — the adversary’s goal (Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact, plus Reconnaissance and Resource Development for the pre-compromise phase)
  • Technique — how they achieve it (T1059 Command and Scripting Interpreter)
  • Sub-technique — specific variant (T1059.001 PowerShell, T1059.003 Windows Command Shell)
  • Procedure — exactly how a specific actor used the technique (free-form text, tied to group / software records)

ATT&CK also tracks Groups (named threat actors) and Software (malware and tools), each linked to the techniques they use.

Want this for your team?

Custom team training + practitioner advisory

Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.

Book team training call Replies in 4 working hrs · India-only · Senior consultants