Security · 6 modules

MITRE ATT&CK Tactics and Techniques

The vocabulary defenders actually argue in. Learn how ATT&CK models real adversary behaviour — tactics, techniques, mitigations and detection strategies — and remember the IDs instead of re-Googling them.

flashcards
95
flashcards
per day
~10 min
per day
level
Beginner → Intermediate
level
modules
6
modules
About this topic

What is MITRE ATT&CK?

MITRE ATT&CK is a curated knowledge base of how adversaries actually behave, built from public reporting on real intrusions. Its core distinction is tactics (the adversary's goal — the "why") versus techniques (how that goal is achieved), with sub-techniques refining a technique and procedure examples grounding it in observed activity.

Because it describes behaviour rather than atomic indicators, ATT&CK is what detection engineers, threat-intel analysts and red teams use as a shared vocabulary. A detection tagged T1566 means the same thing to everyone in the room, which is exactly why coverage maps, adversary emulation plans and vendor evaluations are all expressed in ATT&CK terms.

The framework moves. ATT&CK ships roughly twice a year, and recent releases changed it structurally: v18 (October 2025) replaced per-technique detection notes with Detection Strategies and Analytics and deprecated Data Sources, and v19 (April 2026) split Defense Evasion into Stealth and Defense Impairment — so Enterprise now has 15 tactics, not 14. This track is written against v19.

What you'll learn

6 modules, seed to bloom

Each module is a set of flashcards — 95 in total. Answer, review, and watch your knowledge grow from seed to full bloom.

Framework Fundamentals

What ATT&CK is, who maintains it, and its core vocabulary — tactics, techniques, sub-techniques, procedures, platforms, matrices, and the Navigator.

15 cards

Tactics — the "Why"

The 15 enterprise tactics: the adversary's goals, from Reconnaissance and Initial Access through Lateral Movement, Exfiltration, and Impact — including the Stealth / Defense Impairment split introduced in v19.

18 cards

Techniques & Sub-techniques

Notable techniques by ID — Phishing, Valid Accounts, Process Injection, LOLBins, Remote Services, ransomware — and how sub-techniques refine them.

16 cards

Mitigations & Detection

The defensive side: mitigations (M-series), the v18 detection model — Detection Strategies, Analytics, Data Components, Log Sources — plus CAR and D3FEND.

16 cards

Threat-Intel Objects

Groups (intrusion sets), Software (Malware vs. Tool), and Campaigns — the identifiers, aliases, and relationships that connect actors to techniques.

15 cards

Applying ATT&CK

Putting it to work: threat-informed defense, Navigator gap analysis, adversary emulation, purple teaming, CALDERA, ATLAS, and the framework's limits.

15 cards
Try before you plant

Sample questions

A taste of the real flashcards. Pick an answer, then reveal the explanation.

Sample · MITRE ATT&CK Tactics and Techniques

What does the acronym ATT&CK stand for?

  • AAdversarial Tactics, Techniques, and Common Knowledge
  • BAdvanced Threat Tracking and Cyber Kill-chain
  • CAutomated Testing of Tactics and Countermeasure Knowledge
  • DAdversary Targeting, Triage, and Containment Knowledgebase
Permalink & share
Sample · MITRE ATT&CK Tactics and Techniques

What separates the Stealth tactic from Defense Impairment in ATT&CK?

  • AStealth blends in; Defense Impairment attacks the controls
  • BStealth is pre-compromise; Defense Impairment is post-access
  • CStealth applies to Mobile; Defense Impairment to Enterprise
  • DStealth is a tactic; Defense Impairment is only a mitigation
Permalink & share
Sample · MITRE ATT&CK Tactics and Techniques

What replaced the per-technique Detection notes in ATT&CK v18?

  • ADetection Strategies, each implemented by one or more Analytics
  • BA CVSS-style severity score attached to every technique page
  • CA single vendor-neutral SIEM rule pack published by MITRE
  • DA mandatory mapping from each technique to a named CVE entry
Permalink & share
Sample · MITRE ATT&CK Tactics and Techniques

Which of these software entries does ATT&CK type as Malware rather than Tool?

  • ACobalt Strike (S0154), the commercial C2 framework
  • BPsExec (S0029), the Sysinternals remote executor
  • CMimikatz (S0002), the credential-dumping utility
  • DImpacket (S0357), the Python network-protocol kit
Permalink & share
How Gnoseed works

Learn it once, keep it for good

1

Answer a question

Each card is one practical concept with multiple options. Pick what you think is right.

2

Get the full answer

See the correct option plus a clear explanation, and a link to deeper docs when one is available.

3

Review at the right time

A spaced-repetition engine (SM-2 or FSRS) resurfaces each card just before you would forget it.

Why learn this

Why ATT&CK is worth memorising

A shared vocabulary

Tactic and technique IDs are how detections, threat reports and purple-team exercises are labelled across the whole industry.

Behaviour beats indicators

Hashes and IPs rotate in minutes; tradecraft does not. ATT&CK is built around the part adversaries find expensive to change.

Find your coverage gaps

Mapping your detections to techniques shows what you can and cannot see — the honest version of a security posture review.

Current, not cached

Every card was verified against the live knowledge base, including the v19 tactic split that most ATT&CK material still gets wrong.

FAQ

Common questions

Who is this track for? +

Detection engineers, SOC analysts, threat-intel analysts, red and purple teamers, and any developer or SRE who keeps meeting technique IDs in security tickets and wants them to mean something.

Do I need security experience first? +

No. The track starts from what the framework is and what a tactic, technique, sub-technique and procedure each mean, then builds up to detection strategies, threat-intel objects and how defenders apply it.

Which ATT&CK version does it follow? +

ATT&CK v19 (April 2026). That matters: v19 split Defense Evasion into Stealth and Defense Impairment, taking Enterprise from 14 tactics to 15, and v18 replaced Data Sources with Detection Strategies and Analytics. Every technique, mitigation and software ID was checked against the live site, and each card links to its official MITRE page.

Is it free? +

Yes, completely free. No registration or credit card is required, and all your progress is stored locally in your browser.

Ready to think like the adversary?

Plant your first seed today. Ten minutes a day turns technique IDs from something you look up into something you recall.

Start learning free