Skip to content

MITRE ATT&CK for Testing and Defence

A shared language for attacker behaviour, used well as a coverage map rather than a scoreboard.

Editorial team 2 min read

ATT&CK is a catalogue of what attackers actually do, organised by tactic (the goal) and technique (the method). Its value is that red and blue can describe the same event in the same words.

Using it for testing

Pick techniques relevant to your environment and threat model, not all of them. A Windows-heavy enterprise and a cloud-native startup share very little of the matrix. For each chosen technique, ask: can it be performed here, is it prevented, and if not, is it detected?

Using it for detection

The honest version of coverage mapping is a three-column table: technique, what would detect it, and whether that detection has ever fired on a real test. The third column is the one that matters, and the one usually missing.

Beware colouring the matrix green by counting rules. A rule that fires on one trivial variant of a technique does not cover the technique; attackers adapt within a technique constantly.

Where it misleads

ATT&CK describes behaviour seen in the wild, so it is weighted towards what has been reported. It is not a risk model, it does not rank techniques by likelihood for you, and a high coverage score with no incident response capability is a number, not a defence.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025