MITRE ATT&CK Series

The MITRE ATT&CK framework is a globally recognised knowledge base of adversary tactics and techniques, drawn from real-world observations. Our series works through all fourteen Enterprise tactics — the “why” behind each stage of an attack — in kill-chain order, with the key techniques and practical mitigations for each.

Use it as a reference for understanding how intrusions unfold and where to focus your defences. If you’re responding to an active incident.

The fourteen Enterprise tactics

  1. Reconnaissance (TA0043) — gathering information to plan an operation.
  2. Resource Development (TA0042) — establishing infrastructure, accounts and tooling to support the attack.
  3. Initial Access (TA0001) — gaining the first foothold in the environment.
  4. Execution (TA0002) — running malicious code on a target system.
  5. Persistence (TA0003) — maintaining access across reboots and credential changes.
  6. Privilege Escalation (TA0004) — gaining higher-level permissions.
  7. Defense Evasion (TA0005) — avoiding detection.
  8. Credential Access (TA0006) — stealing account names and passwords.
  9. Discovery (TA0007) — learning about the environment and what’s worth targeting.
  10. Lateral Movement (TA0008) — moving through the environment toward objectives.
  11. Collection (TA0009) — gathering data of interest to the adversary.
  12. Command and Control (TA0011) — communicating with compromised systems to direct them.
  13. Exfiltration (TA0010) — stealing data out of the network.
  14. Impact (TA0040) — disrupting, destroying or manipulating systems and data.

Facing an incident?

Understanding the tactics is one thing; responding under pressure is another. If you’re dealing with a live breach, ransomware, or a suspected compromise, get in touch.