
When it comes to cybersecurity frameworks, few have had as much impact as the MITRE ATT&CK framework.
MITRE ATT&CK has become the go-to reference for blue teamers trying to sharpen their detection skills, red teamers designing realistic adversary emulations, or simply anyone curious about how modern organizations defend themselves.
Let’s dive into the Enterprise Matrix of the MITRE ATT&CK framework and understand its application.
Think of the Enterprise Matrix as a field guide to adversary behavior. It’s a living catalog of how real attackers operate, organized so defenders can reason about goals (tactics) and the ways those goals are achieved (techniques and sub-techniques). Below is a deeper look with practical takeaways.
In the context of the MITRE ATT&CK Enterprise Matrix, the building blocks are what give the framework its structure and utility. They break down as follows.
Tactics (aka the “why”)
These are the adversary’s high-level objectives. In the Enterprise Matrix, you’ll find 14 tactics.

A tactic defines what the attacker is trying to achieve at that stage.
Techniques (aka the “how”)
Each tactic is supported by a set of techniques, which describe the specific behaviors used by adversaries to achieve the tactical goal. For example, under the Credential Access tactic, you might see “Input Capture: Keylogging (T1056.001)” as a technique.

Sub-techniques
These are finer-granularity variants of techniques, allowing defenders to map more specific behaviors (e.g., a technique might have multiple sub-techniques indicating different methods of accomplishing the same goal).
Procedure examples, data components, and mitigations
Beyond just naming techniques/sub-techniques, the Matrix provides real-world procedure examples (what adversaries actually did in real-world attacks), suggested mitigations and detection/telemetry guidance.
When you’re preparing yourself or your team to face incidents in real life, you don’t just want to know “attackers do bad things.” You want to know which techniques they used, what their goal was, how they did it, what signals should have been observable, and what we should have done. The ATT&CK Matrix organizes all of this, so you can align your detection and response capabilities.
One of the major strengths of the Enterprise Matrix is that it explicitly acknowledges where adversary behaviors take place; that is, on which platforms or environments the techniques apply. According to the official Matrix listing, those platforms include Windows, macOS, Linux, PRE, Office Suite, Identity Provider, SaaS, IaaS, Network Devices, Containers, ESXi.
This platform‐aware design gives several advantages.
The Enterprise Matrix is more than just a two-axis table of tactics and techniques. It also includes a rich set of related objects which broaden its value and applicability.
These related objects bring threat intelligence into the framework. You’re not just seeing “technique T1056.001 exists,” you can see which group uses it, what software they used, which campaign it is part of, and what mitigations are appropriate. That makes the Matrix a truly operational tool for red teaming, hunting, intelligence-led defense, and measurement.
According to the MITRE ATT&CK Enterprise Matrix, the related objects are:
For example, If you see Group X is known to use Software Y which uses Technique Z, you can prioritize implementing detection and mitigation for Z, because you know it’s likely relevant to you.
While ATT&CK focuses on describing how adversaries operate, MITRE D3FEND flips the script. It’s a complementary framework that documents defensive countermeasures and links them to the specific ATT&CK techniques they help mitigate or detect.
For example, if a threat actor uses the technique Input Capture: Keylogging (T1056.001), D3FEND can help you find defensive techniques that specifically address this, such as input device monitoring or process integrity validation. Together, they form a feedback loop between threat intelligence and defensive engineering.
If you’ve been following MITRE ATT&CK for a while, you might remember MITRE PRE‑ATT&CK as its own domain. It covered adversarial activities before a breach, things like researching targets, registering domains, or building malware. However, since version 8, PRE‑ATT&CK has been integrated directly into the Enterprise Matrix as two pre-compromise tactics: Reconnaissance and Resource Development.
That means PRE‑ATT&CK didn’t disappear, it simply evolved. These two tactics now represent the early stages of an attack lifecycle, seamlessly connected to the rest of the framework. When you’re planning detections or training scenarios, think of PRE‑ATT&CK as the prelude to the Enterprise tactics rather than a separate entity.
Framework knowledge becomes truly valuable when it’s experienced, not just studied. Cybersecurity professionals learn best when they can apply ATT&CK concepts in hands-on, realistic environments, and that’s where cyber ranges and experience-based training come into play.
Understanding tactics and techniques on paper is one thing; seeing them unfold in a live network is another. Experience-based training helps bridge the gap between theory and practice, reinforcing skills like:
Advanced cyber ranges simulate enterprise environments, complete with systems, logs, and realistic attacks, allowing teams to train using the same tools and workflows they rely on in production.
To turn training into measurable progress and transform ATT&CK from a static reference into a continuous improvement engine for your SOC, you need to follow a few steps.
The MITRE ATT&CK Framework isn’t meant to live on a PowerPoint slide. It’s meant to be used! The Enterprise Matrix provides the perfect foundation for scenario design. So, instead of random exercises, range operators can build threat-informed scenarios based on real adversary behavior.
Below, we outline three realistic scenarios you can use to bring the MITRE ATT&CK Enterprise Matrix to life in your organization or training environment.
Scenario 1
Input Capture: Keylogging (T1056.001)
Attackers often install keyloggers to steal credentials or sensitive data. In a controlled exercise, simulate the use of a keylogger and challenge your blue team to detect unusual keyboard hooks, process injections, or input device access events. Review your EDR data and map findings to ATT&CK’s Detection Strategies and D3FEND countermeasures.
Scenario 2
Email Collection (T1114)
From phishing rule manipulation to unauthorized mailbox exports, attackers use various methods to collect email data. Run a simulation that mimics email exfiltration or mailbox scraping. Train analysts to spot anomalies in mailbox activity logs, API calls, and rule creation events.
Scenario 3
Automated Collection (T1119)
Data collection doesn’t always happen manually. Attackers automate the process to gather large volumes of data quickly. Practice detecting bulk file access patterns or unusual data staging activity, then apply the lessons to improve your real-world monitoring.
Each scenario aligns with a specific technique ID, allowing defenders to document which detections and mitigations they validated, and update their coverage map accordingly.
[embedded video: https://www.youtube.com/watch?v=-F3-zynbIsk&t=89s]
The MITRE ATT&CK framework is constantly evolving, and the most recent release, version 18, brought some major structural updates.
Treat the Enterprise Matrix as your operational backbone for threat‑informed defence, a shared map that connects real attacker behavior to the exact telemetry, analytics, and mitigations your teams run every day.
So, if your training materials or detections still reference the old data model, now’s the time to update them. Aligning your exercises and documentation with this new structure ensures your content remains current and actionable.
Threats exist within a specific sophistication level, which is defined as how much effort the threat actor is willing to put into a specific target. Defining threats this way enables us to set an important scope around what types of actions they are capable of, and thus what types of defensive actions need to be built. It is often also helpful to combine related threats into threat categories, which helps security organizations understand their current and future maturity.
Within each threat category (e.g. Ransomware), there are specific levels of threats based on threat sophistication level, defined as the amount of time they are willing to put into each engagement.

Threat sophistication level has a profound impact on the ATT&CK capabilities available to the organization, and thus, on which D3FEND capabilities your organization needs to effectively mitigate the threat.
The Cyberbit skill labs and defensive team threat exercises are mapped to these categories, providing a comprehensive understanding of the cyber threat landscape while enabling targeted upskilling of security personnel. This threat-centric methodology empowers organizations to prioritize the threats most pertinent to their operations.
This strategic combination ensures that security professionals are equipped with the most relevant and up-to-date skills needed to tackle evolving cyber threats. This model applies to organizations of all sizes, from those with a single security practitioner to those with hundreds.
The MITRE ATT&CK Enterprise Framework represents a mindset. It encourages us to think like adversaries, build defences that anticipate their moves, and validate our controls through realistic testing.
Training around ATT&CK is about building a shared understanding. When every analyst, engineer, and incident responder speaks the same language of tactics and techniques, coordination improves dramatically.
Encouraging teams to map incidents, detections, and playbooks to ATT&CK reinforces analytical thinking and builds intuition about attacker behavior. Pair that with hyper-realistic range training, and you create defenders who can think, adapt, and act like real adversaries.
Stay curious, stay informed, and make ATT&CK part of your daily defensive rhythm!
