Skip to content

standard

MITRE ATT&CK

MITRE ATT&CK is a publicly maintained knowledge base of real-world adversary tactics and techniques used to classify cyberattack behavior.

Known aliases

  • ATT&CK
  • ATT&CK framework
  • Enterprise ATT&CK
  • MITRE ATT&CK Enterprise
  • MITRE ATT&CK framework
  • MITRE ATT&CK Matrix for Enterprise
  • MITRE ATT&CK v18
  • MITRE Enterprise ATT&CK
  • T1068
  • T1574.002

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

How Gunra actors got into a network through a default SSL VPN admin password

Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security5 publishers

CISA ran the same tradecraft at two organisations; only the water utility caught it

Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.

Perspective Coverage

5 publishers
Builder
Builder 39%
Operator
Operator 53%
Investor
Investor 8%

Reality

Evidence76
Adoption
Insufficient
Hype gap+12
Incentives35
Confidence72
security5 publishers

CISA now tells critical infrastructure to plant fake credentials for attackers to trip over

The federal cyber agency now recommends planting fake records, credentials and files across critical infrastructure networks, and its pitch to understaffed teams is that an alert on a decoy needs no analyst to interpret it.

Perspective Coverage

5 publishers
Builder
Builder 46%
Operator
Operator 47%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+15
Incentives30
Confidence75

Earlier coverage

  1. Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours

    Science · September 5, 2026 · 2 publishers

  2. Unit 42's ten-hour intrusion forces a choice about who may disable an account without asking

    Leadership · September 5, 2026 · 1 publisher

  3. Deception.Pro logged an operator pairing hands-on ScreenConnect with XLoader in one 54-hour chain

    Security · August 31, 2026 · 1 publisher

  4. Zabbix's Windows agent installer loads DLLs from a directory low-privileged users can write

    Build · August 28, 2026 · 1 publisher

  5. The 2026 LLM Top 10 lands: prompt injection still first, hidden context now its own line item

    Security · August 26, 2026 · 1 publisher

  6. AWS says GuardDuty catches the universal attacks. The rest is your detection engineering.

    Build · August 26, 2026 · 1 publisher

  7. AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild

    Build · August 24, 2026 · 1 publisher

  8. Talos tells the story instead of the matrix, and BEC's new economics fall out

    Security · August 20, 2026 · 1 publisher

  9. The AI security line item to fund first is log coverage, not another agent

    Security · August 18, 2026 · 2 publishers

  10. Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now

    Security · August 18, 2026 · 1 publisher

  11. Storm-0501's first move is deleting your resource locks, not encrypting your disks

    Security · August 18, 2026 · 1 publisher

  12. Microsoft is generating its detection test logs, and admitting what they do not prove

    Build · August 17, 2026 · 1 publisher

  13. CrowdStrike's own triage numbers make AI auto-close a calibration contract, not a headcount cut

    Build · August 17, 2026 · 1 publisher

  14. Seven agentic AI incidents, one front door: the identity metadata you publish on purpose

    Security · August 14, 2026 · 2 publishers

  15. Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel

    Security · August 15, 2026 · 2 publishers