The vocabulary defenders actually argue in. Learn how ATT&CK models real adversary behaviour — tactics, techniques, mitigations and detection strategies — and remember the IDs instead of re-Googling them.
MITRE ATT&CK is a curated knowledge base of how adversaries actually behave, built from public reporting on real intrusions. Its core distinction is tactics (the adversary's goal — the "why") versus techniques (how that goal is achieved), with sub-techniques refining a technique and procedure examples grounding it in observed activity.
Because it describes behaviour rather than atomic indicators, ATT&CK is what detection engineers, threat-intel analysts and red teams use as a shared vocabulary. A detection tagged T1566 means the same thing to everyone in the room, which is exactly why coverage maps, adversary emulation plans and vendor evaluations are all expressed in ATT&CK terms.
The framework moves. ATT&CK ships roughly twice a year, and recent releases changed it structurally: v18 (October 2025) replaced per-technique detection notes with Detection Strategies and Analytics and deprecated Data Sources, and v19 (April 2026) split Defense Evasion into Stealth and Defense Impairment — so Enterprise now has 15 tactics, not 14. This track is written against v19.
Each module is a set of flashcards — 95 in total. Answer, review, and watch your knowledge grow from seed to full bloom.
What ATT&CK is, who maintains it, and its core vocabulary — tactics, techniques, sub-techniques, procedures, platforms, matrices, and the Navigator.
15 cardsThe 15 enterprise tactics: the adversary's goals, from Reconnaissance and Initial Access through Lateral Movement, Exfiltration, and Impact — including the Stealth / Defense Impairment split introduced in v19.
18 cardsNotable techniques by ID — Phishing, Valid Accounts, Process Injection, LOLBins, Remote Services, ransomware — and how sub-techniques refine them.
16 cardsThe defensive side: mitigations (M-series), the v18 detection model — Detection Strategies, Analytics, Data Components, Log Sources — plus CAR and D3FEND.
16 cardsGroups (intrusion sets), Software (Malware vs. Tool), and Campaigns — the identifiers, aliases, and relationships that connect actors to techniques.
15 cardsPutting it to work: threat-informed defense, Navigator gap analysis, adversary emulation, purple teaming, CALDERA, ATLAS, and the framework's limits.
15 cardsA taste of the real flashcards. Pick an answer, then reveal the explanation.
What does the acronym ATT&CK stand for?
What separates the Stealth tactic from Defense Impairment in ATT&CK?
What replaced the per-technique Detection notes in ATT&CK v18?
Which of these software entries does ATT&CK type as Malware rather than Tool?
Each card is one practical concept with multiple options. Pick what you think is right.
See the correct option plus a clear explanation, and a link to deeper docs when one is available.
A spaced-repetition engine (SM-2 or FSRS) resurfaces each card just before you would forget it.
Tactic and technique IDs are how detections, threat reports and purple-team exercises are labelled across the whole industry.
Hashes and IPs rotate in minutes; tradecraft does not. ATT&CK is built around the part adversaries find expensive to change.
Mapping your detections to techniques shows what you can and cannot see — the honest version of a security posture review.
Every card was verified against the live knowledge base, including the v19 tactic split that most ATT&CK material still gets wrong.
Detection engineers, SOC analysts, threat-intel analysts, red and purple teamers, and any developer or SRE who keeps meeting technique IDs in security tickets and wants them to mean something.
No. The track starts from what the framework is and what a tactic, technique, sub-technique and procedure each mean, then builds up to detection strategies, threat-intel objects and how defenders apply it.
ATT&CK v19 (April 2026). That matters: v19 split Defense Evasion into Stealth and Defense Impairment, taking Enterprise from 14 tactics to 15, and v18 replaced Data Sources with Detection Strategies and Analytics. Every technique, mitigation and software ID was checked against the live site, and each card links to its official MITRE page.
Yes, completely free. No registration or credit card is required, and all your progress is stored locally in your browser.
Plant your first seed today. Ten minutes a day turns technique IDs from something you look up into something you recall.