
MITRE ATT&CK is a knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations of how attackers actually behave. It catalogues what adversaries do once they’re inside your environment — from initial access through to data exfiltration.
The framework is organised as a matrix: tactics run across the top (the attacker’s goals at each stage), and techniques sit beneath each tactic (the specific methods they use to achieve those goals). This gives your team a structured, shared vocabulary for describing threats and measuring your defensive coverage.
Most organisations collect threat intelligence but struggle to act on it. ATT&CK bridges that gap by giving you a structured way to map what you know about adversaries to the specific controls and detections you need. The result: your defensive investment goes where it counts.
Threat intelligence feeds deliver structured data about threats — indicators of compromise, threat actor profiles, vulnerability details, and more. If you’re new to CTI feeds, the number of providers and data types can feel overwhelming. The good news is you don’t need to buy everything at once. Start with your biggest risks, define what you need to know, and build from there. We’ll help you work out what matters for your organisation and find the feeds that match.
Book an ATT&CK engagement

The best starting point is attack.mitre.org, which hosts the full ATT&CK knowledge base including all tactics, techniques, and threat group profiles. The ATT&CK documentation covers how the framework is structured and maintained. For hands-on exploration, the ATT&CK Navigator tool lets you create custom heatmaps and coverage layers.
CAPEC (Common Attack Pattern Enumeration and Classification) catalogues attack patterns at a higher abstraction level — describing general categories of attack. ATT&CK focuses on observed adversary behaviour and TTPs in real-world intrusions, providing much more specific and actionable detail about how attackers operate in practice.
CVE identifies specific vulnerabilities in software, while CWE classifies types of software weaknesses. ATT&CK describes what attackers do after exploiting vulnerabilities — the tactics and techniques they use to move through your environment, escalate privileges, and achieve their objectives. They’re complementary, not competing: CVE/CWE tell you what’s vulnerable, ATT&CK tells you what adversaries do next.
The Cyber Kill Chain describes attack phases at a high level across seven stages — from reconnaissance through to actions on objectives. ATT&CK provides much more granular detail within each phase, with hundreds of specific techniques mapped to real threat groups. Think of the Kill Chain as a high-level narrative and ATT&CK as the detailed playbook beneath it.
The Diamond Model describes the relationships between four core features of an intrusion: adversary, capability, infrastructure, and victim. It’s a framework for structuring intelligence analysis. ATT&CK provides the detailed technique taxonomy that you’d map into a Diamond Model analysis — specifically populating the “capability” vertex with granular, observed adversary behaviours.

Tell us about your environment and goals, and we’ll show you how ATT&CK mapping can strengthen your defences.
Pipedrive form will go here.