Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Security Operations & Monitoring

ATT&CK

Adversarial Tactics, Techniques, and Common Knowledge

The MITRE knowledge base of real-world attacker behaviors used for detection and mapping.

ATT&CK is a MITRE-maintained, openly available knowledge base that catalogs real-world adversary tactics, the goals, and techniques, the methods, observed across the attack lifecycle. Security teams use it to map detections, assess coverage gaps, plan threat hunts, and communicate adversary behavior with shared vocabulary. Contrast it with the Cyber Kill Chain, which depicts a linear sequence of phases, whereas ATT&CK is a detailed matrix of specific behaviors that does not assume a strict order, making it valuable for detection engineering.

Related terms

Looking ATT&CK up is step one. Getting tested on it is step two.

A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.

Not affiliated with or endorsed by CompTIA.