ATT&CK
Adversarial Tactics, Techniques, and Common Knowledge
The MITRE knowledge base of real-world attacker behaviors used for detection and mapping.
ATT&CK is a MITRE-maintained, openly available knowledge base that catalogs real-world adversary tactics, the goals, and techniques, the methods, observed across the attack lifecycle. Security teams use it to map detections, assess coverage gaps, plan threat hunts, and communicate adversary behavior with shared vocabulary. Contrast it with the Cyber Kill Chain, which depicts a linear sequence of phases, whereas ATT&CK is a detailed matrix of specific behaviors that does not assume a strict order, making it valuable for detection engineering.
Looking ATT&CK up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
