TheorySOC Foundations · Entry 16 min
Speaking ATT&CK
Three critical alerts are open. Each describes a different attacker goal. To discuss them with anyone else in security you need the ATT&CK vocabulary.
Concept
Read this before opening the workspace
MITRE ATT&CK is the shared vocabulary for attacker behaviour. Tactics are the attacker's goals (execution, credential access, command and control); techniques are the ways they achieve them, each with a stable ID such as T1059.001.
ATT&CK matters operationally because it lets a triage note, a detection rule, a hunt hypothesis and a management coverage report all describe the same behaviour in the same words.
Key terms
- Tactic
- The attacker's objective at a stage of the intrusion.
- Technique
- A specific method used to achieve a tactic, identified as Txxxx.
- Sub-technique
- A narrower variant, e.g. T1059.001 PowerShell under T1059 Command and Scripting Interpreter.
- Coverage
- How much of the relevant ATT&CK surface your detections observe.
Learning objectives
- Distinguish tactic from technique
- Map live alerts to ATT&CK techniques
- Use ATT&CK IDs in analyst notes
Prerequisites
- · FD-2 — telemetry families
- · Telemetry: the data a SOC actually sees (recommended first)