What is MITRE ATT&CK Framework (ATT&CK)?
MITRE ATT&CK Framework: MITRE ATT&CK is a globally accessible, curated knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations.
Detailed Explanation
The MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework categorizes the entire cyberattack lifecycle into specific tactics (the adversary's tactical goal, such as Initial Access or Lateral Movement) and techniques (the exact actions used to achieve the goal). It serves as the universal lingua franca for threat hunters, red teams, and incident responders.
Why ATT&CK Matters for Enterprise Security
- Provides an objective matrix to evaluate the coverage and efficacy of defensive security controls.
- Enables standard threat actor profiling and cross-organizational intelligence sharing.
- Guides proactive threat hunting by mapping high-probability adversary techniques against internal telemetry.
Core Components & Architecture
Tactics Matrix
The 14 enterprise tactical categories spanning Initial Access to Impact.
Techniques & Sub-Techniques
Granular documentation of exact attacker methodologies and execution commands.
Mitigations & Detections
Recommended defensive controls and log data sources required to detect each technique.
The VayuX Systems Approach
All VayuX DFIR and SOC investigations map directly to MITRE ATT&CK matrices. This standardized tagging accelerates telemetry ingestion in our R&D lab, driving automated behavioral detection models.