MITRE ATT&CK Framework: Practical Application
The SolarWinds intrusion spanned at least 8 ATT&CK techniques across 5 tactics --- from supply chain compromise (T1195.002) through signed binary proxy execution (T1218) to data staged for exfiltration via encrypted C2 channels (T1560/T1071.001). Organizations that had mapped their detection coverage to the ATT&CK matrix knew within hours exactly where their gaps were: they could see that their detections covered execution and persistence but had nothing on supply chain initial access or the specific defense evasion techniques UNC2452 favored. The organizations that had not done this mapping spent weeks asking the same question the framework would have answered in minutes: "Could this have happened to us?"
Why Now
ATT&CK v16, released in October 2024, restructured cloud coverage to reflect how attacks actually land in modern environments, and MITRE continues to expand the technique catalog with every six-month release. More significantly, federal continuous-monitoring expectations increasingly reference technique-based detection --- agencies are pushed to demonstrate detection capability mapped to specific technique IDs, not just generic "we have a SIEM" assertions. For defense contractors, assessors increasingly expect technique-level detection evidence when evaluating monitoring controls (NIST 800-171 3.14.6-3.14.7 and their 800-53 SI-4/AU-6 equivalents). The framework has moved from "useful reference" to "assessment baseline."
What ATT&CK Actually Is (and Is Not)
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a knowledge base of adversary behavior based on real-world observations. It catalogs the tactics (goals) and techniques (methods) that attackers use at each stage of an intrusion.
ATT&CK is not a compliance framework, not a maturity model, and not a product evaluation checklist. It is a common language for describing how attacks work, which makes it invaluable for:
- Mapping your detection coverage against known attack techniques
- Communicating threat intelligence in a standardized vocabulary
- Evaluating security products against specific adversary behaviors
- Planning red team and purple team exercises with measurable outcomes
- Prioritizing detection engineering investment against your actual threat landscape
The ATT&CK Matrix: 14 Tactics
The Enterprise ATT&CK matrix organizes adversary behavior into 14 tactics that represent the attacker's sequential goals:
| Tactic | Goal | Example Technique |
|---|---|---|
| Reconnaissance | Gather information about the target | Active scanning, phishing for information |
| Resource Development | Establish infrastructure for the attack | Acquire domains, develop capabilities |
| Initial Access | Get into the target environment | Phishing, supply chain compromise, valid accounts |
| Execution | Run malicious code | PowerShell, scheduled tasks, WMI |
| Persistence | Maintain access across restarts | Registry run keys, scheduled tasks, implant |
| Privilege Escalation | Get higher-level permissions | Token manipulation, exploitation for priv esc |
| Defense Evasion | Avoid detection | Masquerading, timestomping, process injection |
| Credential Access | Steal credentials | Kerberoasting, credential dumping, brute force |
| Discovery | Learn about the environment | Network scanning, AD enumeration, file discovery |
| Lateral Movement | Move through the environment | RDP, SMB, pass-the-hash |
| Collection | Gather target data | Screen capture, keylogging, data from local system |
| Command and Control | Communicate with compromised systems | DNS tunneling, HTTPS beaconing, proxy |
| Exfiltration | Steal data | Exfil over C2, exfil over alternative protocol |
| Impact | Disrupt, destroy, or manipulate | Ransomware, wiper, defacement |
Each tactic contains multiple techniques (the specific methods attackers use to achieve the goal), and many techniques have sub-techniques for more granular classification. The Enterprise matrix contains 200+ techniques and 400+ sub-techniques, with counts growing each release.
The Coverage Percentage Trap
Here is the contrarian opinion that matters: coverage percentage is vanity --- what matters is whether you detect the 20 techniques your actual adversaries use, not whether you can theoretically detect 60% of all 200+ techniques.
A CISO who reports "72% ATT&CK coverage" is communicating almost nothing useful. That number could mean excellent detection of techniques nobody uses against their industry while completely missing the 5 techniques that APT groups targeting their sector rely on daily. Coverage must be weighted by relevance to your threat model, or it becomes a metric that optimizes for the wrong outcome.
The correct approach: identify the threat groups that target your industry and geography, extract their documented TTPs, and measure coverage specifically against those technique sets. An organization in the defense industrial base with 40% overall ATT&CK coverage but 95% coverage of APT28/APT29/Lazarus Group techniques has a dramatically better security posture than one with 80% overall coverage and 30% coverage of those same groups.
Practical Application: Detection Coverage Mapping
Map your detection rules and SIEM content to ATT&CK techniques. This produces a heat map showing:
- Green --- Techniques you detect with high confidence and acceptable false positive rates
- Yellow --- Techniques you partially detect (e.g., only certain sub-techniques) or detect with high false positive rates that reduce analyst trust
- Red --- Techniques you have no detection for and no log data to support detection
This coverage map immediately reveals where detection gaps exist and enables prioritized rule development. But the map is only useful if it reflects tested, validated detections --- not theoretical coverage based on what a tool could detect if properly configured.
Validating Coverage Claims
A detection rule that has never fired on a real or simulated attack is an untested hypothesis. Before marking a technique green:
- Has the rule been triggered by a controlled test (purple team, atomic red team, or adversary simulation)?
- When it triggered, did it produce enough context for an analyst to investigate?
- What is the false positive rate in your specific environment?
- Does the rule depend on a log source that has actually been validated as flowing continuously?
Organizations that skip validation routinely discover during real incidents that rules they believed were functional were silently broken --- a log source stopped flowing, a field mapping changed, or the rule logic had a typo that made it overly broad (fires on everything, analysts ignore it) or overly narrow (never fires at all).
Practical Application: Threat Intelligence Integration
When your threat intelligence feeds report a campaign targeting your industry, map the campaign's TTPs to ATT&CK technique IDs. Then check your coverage map to determine if you can detect those specific techniques. This turns abstract threat reports ("APT group targeting defense sector with novel techniques") into actionable detection priorities ("we have no detection for T1055.012 Process Hollowing, which this group uses for defense evasion").
The Citrix Bleed vulnerability (CVE-2023-4966) illustrates this well. Exploitation gave attackers authenticated sessions, after which they consistently used a narrow set of techniques: T1021 Remote Services for lateral movement, T1003 OS Credential Dumping for privilege escalation, and T1486 Data Encrypted for Impact (ransomware). Organizations that mapped this campaign and confirmed coverage of those three techniques knew their risk was bounded. Organizations that did not had to assume worst-case exposure.
Practical Application: Purple Team Exercises
Use ATT&CK to structure purple team exercises that produce measurable outcomes:
- Select techniques relevant to your threat model (not random techniques for coverage padding)
- Red team executes those techniques against your production environment using tools like Atomic Red Team or Caldera
- Blue team attempts to detect and respond using existing tools and runbooks
- Map results back to ATT&CK to update your coverage assessment with ground-truth data
- Close gaps by writing detection rules for techniques that were executed but not detected
The CrowdStrike outage in July 2024 exposed a secondary risk: organizations that relied on a single EDR for the majority of their ATT&CK coverage discovered that one product going offline eliminated detection across dozens of techniques simultaneously. Purple team exercises should include scenarios where primary detection tools are unavailable, validating that secondary or compensating detections exist.
Practical Application: Product Evaluation
When evaluating EDR, SIEM, or other security products, ask vendors to demonstrate detection of specific ATT&CK techniques relevant to your threat model. Do not accept "we cover 90% of ATT&CK" as an answer --- ask which techniques, with what detection type (real-time alert vs. telemetry only vs. enriched context), and what the false positive rate is in production environments.
MITRE's own ATT&CK Evaluations program tests major EDR products against specific threat group behaviors (Wizard Spider, Sandworm, Turla). These evaluations distinguish between "detected with high confidence" and "telemetry was present if an analyst knew exactly where to look" --- a distinction that matters enormously in operations.
Building an ATT&CK-Based Detection Program
Step 1: Identify Relevant Threat Groups
ATT&CK catalogs threat groups with their documented TTPs. For the defense industrial base: APT28, APT29, Lazarus Group, Turla, and Kimsuky are primary concerns. For healthcare: FIN12 (ransomware), Storm-0501, and Scattered Spider. For financial services: FIN7, Carbanak, and Cobalt Group.
Identify 3-5 groups most likely to target your industry, geography, and organization size.
Step 2: Extract and Prioritize TTPs
List the techniques used by your relevant threat groups. Identify the intersection --- techniques that appear across multiple relevant groups are highest priority because they represent the most likely attack paths regardless of which specific actor targets you.
A technique used by 4 of your 5 relevant threat groups is a higher priority than one used by only 1, even if the single-group technique is more sophisticated.
Step 3: Assess Current Coverage
For each priority technique, determine:
- Do you have the log data required to detect this technique? (If not, detection is impossible regardless of rules.)
- Do you have a detection rule that targets this technique?
- Has the rule been tested and validated against simulation?
- What is the false positive rate in your environment?
- Can an analyst act on this alert without 30 minutes of manual pivoting?
Step 4: Close Gaps Systematically
For techniques with no detection:
- Identify the required data source (e.g., process creation logs with command-line arguments for T1059)
- Enable the data source if not already collected (this is often the real blocker --- not the rule, but the log source)
- Write and test a detection rule using SIGMA or your SIEM's native format
- Validate with controlled execution (Atomic Red Team tests exist for most techniques)
- Deploy, tune, and set a review cadence
Step 5: Measure and Report
Track detection coverage as a percentage of relevant techniques (weighted by threat group overlap) over time. Report quarterly to demonstrate detection engineering ROI:
- "Coverage of APT29 techniques improved from 55% to 78% this quarter"
- "Our largest remaining gap is Credential Access --- we detect 4 of 9 relevant techniques"
- "After deploying process creation logging, we closed 6 detection gaps in a single sprint"
ATT&CK for ICS, Mobile, and Cloud
Beyond the Enterprise matrix, MITRE maintains:
- ATT&CK for ICS --- Techniques specific to industrial control systems and operational technology. Critical for defense organizations operating weapons systems, utilities, or manufacturing.
- ATT&CK for Mobile --- Techniques targeting iOS and Android devices. Relevant when mobile devices access organizational data or when MDM is in scope.
- ATT&CK for Cloud --- Integrated into the Enterprise matrix, covering IaaS, identity provider, and SaaS-specific techniques.
Organizations with OT environments, significant mobile workforces, or cloud-native architectures should map detection coverage against these specialized technique sets in addition to the Enterprise baseline.
Key Takeaways
- ATT&CK is a common language for adversary behavior, not a compliance framework --- use it to prioritize detection, not to check boxes
- Coverage percentage without threat-model weighting is a vanity metric; measure against the techniques your actual adversaries use
- Detection rules must be validated through controlled testing; untested rules are hypotheses, not coverage
- Log source availability is the prerequisite for detection --- you cannot write a rule for data you do not collect
- Purple team exercises with ATT&CK structure produce measurable gap closure and ground-truth coverage data
- Product evaluations should demand technique-specific demonstrations, not percentage claims
Frequently Asked Questions
How often should I update my ATT&CK coverage map?
Update after every detection rule change (addition, modification, or retirement), every purple team exercise, and every real incident. At minimum, conduct a full reassessment quarterly. MITRE releases major ATT&CK updates approximately every six months --- each release should trigger a review of whether new techniques are relevant to your threat model and whether existing technique definitions have changed in ways that affect your rules.
Is ATT&CK relevant if my organization is small and unlikely to face APT groups?
Yes. ATT&CK is not only for nation-state threats. Ransomware operators (FIN12, Scattered Spider, LockBit affiliates) use documented ATT&CK techniques that are identical whether they target a Fortune 500 or a 200-person manufacturer. The techniques for credential access, lateral movement, and data encryption are the same --- only the initial access vector and the ransom demand change. Use ATT&CK to prioritize against ransomware TTPs if APT groups are not your primary concern.
What is the relationship between ATT&CK and SIGMA rules?
SIGMA is a detection rule format that can be converted to any SIEM's native query language. Many SIGMA rules are tagged with their corresponding ATT&CK technique IDs. This creates a direct pipeline: identify a technique gap in your coverage map, find the SIGMA rule that detects it, convert to your SIEM's format, and deploy. The SIGMA repository contains 3,000+ community rules mapped to ATT&CK, providing a starting point for most common techniques.
How does ATT&CK relate to compliance requirements like NIST 800-171 or CMMC?
NIST 800-53 SI-4 (System Monitoring) and AU-6 (Audit Record Review, Analysis, and Reporting) --- mirrored in NIST 800-171 requirements 3.14.6-3.14.7 and 3.3.3 --- require organizations to detect and respond to security events. ATT&CK provides the structure for demonstrating what you detect. During a CMMC assessment, showing an ATT&CK coverage map that demonstrates detection capability against relevant threat group techniques is significantly more persuasive than claiming "we have a SIEM with detection rules." The framework makes abstract control requirements concrete and measurable.
Should I aim for 100% ATT&CK coverage?
No. 100% coverage is neither achievable nor desirable. Some techniques (T1195 Supply Chain Compromise, T1189 Drive-by Compromise) are inherently difficult to detect with certainty. Others may be irrelevant to your environment (ICS techniques if you have no OT, mobile techniques if you have no BYOD). Aim for high coverage of your relevant technique set and accept that some techniques require compensating controls (network segmentation, least privilege) rather than detection rules.
How Advisedly Helps
Advisedly maps your detection rules, security controls, and SIEM content to the MITRE ATT&CK matrix automatically, producing a coverage map weighted by the threat groups most relevant to your industry and compliance obligations. The platform identifies gaps between your current detections and the techniques used by your prioritized adversaries, then recommends specific detection rules and log sources to close those gaps --- with each improvement simultaneously mapped to the compliance controls it satisfies across 500+ frameworks. Contact begin@advisedly.ai to assess your ATT&CK detection coverage against your actual threat landscape.
<!-- LI hook: Your ATT&CK coverage map says 72% but misses the 5 techniques your adversaries actually use -->