What Is MITRE ATT&CK? — The Framework Every SOC Analyst Needs to Know
What is MITRE ATT&CK? A plain-language guide to the 14 Tactics and 200+ Techniques framework, plus how SOC Analysts use it with SIEM to catch real attacks.
What Is MITRE ATT&CK? — The Framework Every SOC Analyst Needs to Know
If you've read a cyber threat report, you've probably run into the term MITRE ATT&CK more than once. But what actually is it? Why does every SOC Analyst need to know it? And how does it connect to a SIEM?
Here's a plain-language walkthrough.
What Is MITRE ATT&CK? (The Simple Version)
Picture yourself as a detective — the hacker is a burglar breaking into a house. MITRE ATT&CK is like "the burglar's playbook", a catalog of every method a burglar uses, from:
- How they climb the fence to get in (Initial Access)
- How they stay hidden from the homeowner (Stealth)
- How they carry the loot out (Exfiltration)
Formally, MITRE ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge — a knowledge base cataloging real-world cyberattack techniques used by actual adversaries, built and maintained by the MITRE Corporation (a U.S. nonprofit).
Tactics vs. Techniques — What's the Difference?
This is where most people get confused. The easy way to remember it:
- Tactic = "why" (the goal) — e.g., "gain access to the system"
- Technique = "how" (the method) — e.g., "use a phishing email"
MITRE ATT&CK defines 15 core Tactics:
| # | Tactic | Goal | Example |
|---|
| 1 | Reconnaissance | Scope out the target | Port scanning, gathering info from LinkedIn |
| 2 | Resource Development | Prepare the tools | Buying a domain, building a phishing kit |
| 3 | Initial Access | Get the first foothold | Phishing, exploiting a vulnerability |
| 4 | Execution | Run code | PowerShell, macros, scripts |
| 5 | Persistence | Stay embedded | Creating a service, a scheduled task |
| 6 | Privilege Escalation | Gain higher-level access | Kernel exploits, token manipulation |
| 7 | Stealth | Avoid detection while operating | Obfuscation, process injection, indicator removal |
| 8 | Defense Impairment | Disable or degrade security controls | Disabling antivirus/EDR, modifying security infrastructure |
| 9 | Credential Access | Steal passwords | Brute force, Kerberoasting |
| 10 | Discovery | Map the internal environment | Enumerating network shares, finding domain admins |
| 11 | Lateral Movement | Move to other machines | RDP, PsExec, WMI |
| 12 | Collection | Gather data | Screenshots, keyloggers |
| 13 | Command & Control | Communicate with the attacker | DNS tunneling, HTTPS-based C2 |
| 14 | Exfiltration | Send data out | Uploading to cloud storage, FTP |
| 15 | Impact | Cause damage | Ransomware, wipers |
How Is MITRE ATT&CK Used in Practice?
For SOC Analysts
- Review an alert in the SIEM → map it to the matching Technique
- Sequence alerts along the kill chain to see the full shape of an attack
- Use it as a reference when writing incident reports
For Security Teams
- Assess how many of the 220+ Techniques the organization can actually detect
- Identify detection gaps and build new detection rules to close them
- Use it as a benchmark against other organizations
For Executives
- Understand, at a high level, how attackers operate
- See what percentage of known techniques the organization can defend against
- Direct security investment at the gaps that actually matter
MITRE ATT&CK and SIEM
A good SIEM maps alerts to MITRE ATT&CK automatically — giving the SOC Analyst a clear view of which stage of the kill chain an attacker is in, so they can prioritize correctly.
Example:
Alert: Multiple Failed Login (T1110 - Brute Force)
→ Tactic: Credential Access
→ Risk: HIGH
→ Next likely move: Lateral Movement (T1021)
→ Recommendation: Reset password + enable MFA
⭐ zcrLog + MITRE ATT&CK
zcrLog connects to MITRE ATT&CK for real:
- ✅ Auto-Mapping — every alert is automatically classified into a Technique
- ✅ Technique Cards — see detected Techniques at a glance, with an event count per Technique
- ✅ Attack Map — a visual map of the attack path
🎯 See zcrLog →
📞 Free Consultation
Sources
- MITRE ATT&CK — Enterprise Matrix, MITRE Corporation, accessed 2026-09-15. Confirms the current tactic list, including the April 2026 (v19) split of Defense Evasion into Stealth and Defense Impairment.
- MITRE ATT&CK v19 release notes, MITRE Corporation, accessed 2026-09-15. Source for the current 15-tactic, 222-technique count and the Defense Evasion split.
Related articles
Continue with these related guides for the comparison and operating detail:
Related product
See zcrSIEM for the product scope, the pricing page for published prices, and the inputs to confirm with your delivery partner