The MITRE ATT&CK framework is a globally recognised knowledge base of adversary tactics and techniques, drawn from real-world observations. Our series works through all fourteen Enterprise tactics — the “why” behind each stage of an attack — in kill-chain order, with the key techniques and practical mitigations for each.
Use it as a reference for understanding how intrusions unfold and where to focus your defences. If you’re responding to an active incident.
The fourteen Enterprise tactics
- Reconnaissance (TA0043) — gathering information to plan an operation.
- Resource Development (TA0042) — establishing infrastructure, accounts and tooling to support the attack.
- Initial Access (TA0001) — gaining the first foothold in the environment.
- Execution (TA0002) — running malicious code on a target system.
- Persistence (TA0003) — maintaining access across reboots and credential changes.
- Privilege Escalation (TA0004) — gaining higher-level permissions.
- Defense Evasion (TA0005) — avoiding detection.
- Credential Access (TA0006) — stealing account names and passwords.
- Discovery (TA0007) — learning about the environment and what’s worth targeting.
- Lateral Movement (TA0008) — moving through the environment toward objectives.
- Collection (TA0009) — gathering data of interest to the adversary.
- Command and Control (TA0011) — communicating with compromised systems to direct them.
- Exfiltration (TA0010) — stealing data out of the network.
- Impact (TA0040) — disrupting, destroying or manipulating systems and data.
Facing an incident?
Understanding the tactics is one thing; responding under pressure is another. If you’re dealing with a live breach, ransomware, or a suspected compromise, get in touch.