Sign in

MITRE ATT&CK

@attack.mitre.org
7.5K followers 17 following 159 posts

MITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Reposting ≠ endorsement.

PostsRepliesMedia
MITRE ATT&CK @attack.mitre.org · 29/09/2026
Excited to share our full ATT&CKcon 7.0 agenda. We cannot wait to welcome the ATT&CK community both in person and virtually on October 27. Virtual tickets are now available. Check out our full set of talks and register today! na.eventscloud.com/website/93925/
161
MITRE ATT&CK @attack.mitre.org · 29/06/2026
It's the final countdown for the ATT&CKcon CFP Friendly reminder that our CFP closes 7/2 at 8PM ET. If your entry is still 3 bullet points in Notes, or a fully formed concept you've been "letting marinate," this is your sign. Be a hero, hitting submit is underrated www.openconf.org/ATTACKcon202...
010
MITRE ATT&CK @attack.mitre.org · 24/06/2026
On Cat World Domination Day, it feels only right to acknowledge the obvious (cats run everything). Even if you don't answer to a 🐈 overlord, a reminder that the ATT&CKcon 7.0 CFP closes 7/2 at 8pm ET. Take back a bit of control and submit before next Thursday: www.openconf.org/ATTACKcon202....
030
MITRE ATT&CK @attack.mitre.org · 26/05/2026
The ATT&CKcon 7.0 CFP is open! Want to join us on stage in McLean, VA, 10/28-29? We'd love to hear your best talk ideas with some relation to ATT&CK so we can bring to the wider ATT&CK community. To submit to go www.openconf.org/ATTACKcon2026/ before 8pm ET on July 2nd.
121
MITRE ATT&CK @attack.mitre.org · 30/03/2026
ATT&CK v19 is coming 4/28! Along with our usual updates, the big change this release is the replacement of the Defense Evasion tactic in Enterprise ATT&CK with new Stealth and Impair Defenses tactics. Cat Self talked about what's changing back at ATT&CKcon 6.0 (www.youtube.com/watch?v=0rQQ...).
160
MITRE ATT&CK @attack.mitre.org · 09/03/2026
Pencil in Oct 27-28, 2026 for ATT&CKcon 7.0! We'll be live for both in-person in McLean, VA and live online. Drop us a line at attackcon@mitre.org if you're interested in sponsoring, watch for our CFP to open in May, and grab a ticket when they go on sale this summer. See you in October!
022
MITRE ATT&CK @attack.mitre.org · 03/09/2025
Virtual registration for ATT&CKcon 6.0 is open! We hope you'll chose to join us in person at ATT&CK's home in McLean, VA October 14-15... But if you can't, catch the action for free online by registering at na.eventscloud.com/attackcon6/. Catch all of our talks & some exclusive online only content.
030
MITRE ATT&CK @attack.mitre.org · 26/08/2025
The ATT&CKcon 6.0 talk lineup is now live! Check out our fabulous group of speakers, or pick up a ticket to join us October 14-15 in McLean, VA at na.eventscloud.com/attackcon6. Only able to join us virtually? Hang tight, virtual registration opens September 3rd.
031
MITRE ATT&CK @attack.mitre.org · 19/08/2025
Are you ready to celebrate National Chocolate Day this October 28th? We will be by releasing ATT&CK v18, our next version of MITRE ATT&CK! We'll be releasing our usual updates to Techniques and Groups, but check out some big defensive changes on the way in this release (medium.com/mitre-attack...).
A chocolate ampersand
130
MITRE ATT&CK @attack.mitre.org · 07/07/2025
We are excited to announce our ATT&CKcon 6.0 keynote, Lillian Teng! Lillian's worn numerous hats in cyber at NCIS, FBI, Yahoo, and Capital One and has served with the KC7 Foundation, GirlSecurity, and LEAP. Want to also join us on stage? CFP closes Wed night! www.openconf.org/ATTACKCON2025.
160
MITRE ATT&CK @attack.mitre.org · 03/06/2025
The MITRE ATT&CKcon 6.0 CFP is now open! Are you interested in joining us on the ATT&CKcon stage in McLean, VA October 14-15, 2025? Pitch us on your best ATT&CK related talk! Our CFP will close on July 9th at 8pm ET sharp, so get those proposals started. www.openconf.org/ATTACKCON202...
ATT&CKcon 6.0 Hero graphic
142
MITRE ATT&CK @attack.mitre.org · 24/04/2025
An adversary who finds a vulnerable target but wants to be the only threat actor on that machine might take similar actions like disabling vulnerable services or removing malware already on the device www.f-secure.com/v-descs/nets...
100
MITRE ATT&CK @attack.mitre.org · 24/04/2025
Exclusive Control is a persistence technique in which an adversary prevents other threat actors from accessing or maintaining a foothold on the same system as them.
110
MITRE ATT&CK @attack.mitre.org · 02/04/2025
Find mitigation and detection strategies from ATT&CK: attack.mitre.org/techniques/T...
110
MITRE ATT&CK @attack.mitre.org · 02/04/2025
There’s a lot of meat on the bone in this report. While we’re focusing on the deployment of the backdoor, it’s also worth reading the section on FamousSparrow and Salt Typhoon for an interesting and important look at the intricacies — and sometimes the frustrating opacity — in CTI attribution
110
MITRE ATT&CK @attack.mitre.org · 01/04/2025
Today we're launching a new system where the public can help us develop the next ATT&CK release through Macrotechnique Refinement. To start refining FUZZYSNUGGLYDUCK, click here: attack.mitre.org/macro-techni.... Fabulous prizes await success.
An ampersand eating a waffle. As one does.
2135
MITRE ATT&CK @attack.mitre.org · 04/03/2025
Celebrate April 22nd with ATT&CK v17! The next version of ATT&CK is almost here, with new content related to the ESXi hypervisor, broad improvements to defenses, and updates to techniques, groups, and software across the framework.
Earth with ampersand
086
MITRE ATT&CK @attack.mitre.org · 27/01/2025
October 2023 🙂 At least if you’re using Mobile ATT&CK.
010
MITRE ATT&CK @attack.mitre.org · 23/10/2024
ATT&CKcon 5.0 is back up and running with day 2 keynote, CISA's Mark Singer. Mark's kicking off the day with some tales of CISA's view of threats. Join us for a packed day of ATT&CK insights at mitre.brandlive.com/ATTACKCon-5-0. #attackcon
162
MITRE ATT&CK @attack.mitre.org · 28/08/2024
Threat actors gain cover by using popular services like OneDrive especially if the network is already communicating with the service and if security tools already permit traffic going there. This of course goes way beyond OneDrive: Check out attack.mitre.org/techniques/T...
110
MITRE ATT&CK @attack.mitre.org · 28/08/2024
This maps right to T1567.002 attack.mitre.org/techniques/T... Taking this route is advantageous for numerous reasons including that the ready-built C2 often looks familiar compared to a threat actor’s primary command and control infrastructure.
100
MITRE ATT&CK @attack.mitre.org · 28/08/2024
So, APT41 is in a network, they’ve accessed sensitive data, and now they want to exfiltrate. How? Why not just use what the rest of us already use?: APT41 copies data and then smuggles it out via Microsoft OneDrive.
100
MITRE ATT&CK @attack.mitre.org · 28/08/2024
We’re looking at the recent Mandiant report on APT41 successfully targeting multiple industries, countries, and regions in a lengthy campaign enabling them to extract sensitive data over an extended period. Phew. cloud.google.com/blog/topics/...
100
MITRE ATT&CK @attack.mitre.org · 25/07/2024
In-person ticket sales for ATT&CKcon 5.0 are now live! Looking to join us in McLean, VA October 22-23? Tickets are $359. Virtual registration opens September 24th. na.eventscloud.com/website/76470/
011
MITRE ATT&CK @attack.mitre.org · 23/04/2024
you wouldn’t last an hour in the asylum where they raised us ATT&CK v15 is now streaming from your favorite TAXII servers or wherever STIX is served. Check out our post about our latest era at medium.com/mitre-attack... or visit the changelog at attack.mitre.org/resources/up...
010
MITRE ATT&CK @attack.mitre.org · 10/04/2024
We’re highlighting this because it’s a great way to see subtle but significant differences in how a real world actor behaves versus what you see today in an ATT&CK technique. Sometimes it’s like trying to fit a round peg in a square hole.
100
MITRE ATT&CK @attack.mitre.org · 10/04/2024
We love a good patch but threat actors aren’t out here trying to help. T1601.001 is scoped to be about introducing new capabilities or weaken existing defenses. But it looks like this actor has a different idea: Patching exploited systems just to close the door behind them. Thanks but no thanks?
100
MITRE ATT&CK @attack.mitre.org · 01/04/2024
Stay tuned over the coming weeks as we launch additional MITRE bootcamp games such as Techniqudle. Can you figure out the technique ID in 6 tries or less?
000
MITRE ATT&CK @attack.mitre.org · 01/04/2024
Our first two games might be a bit too easy for those MITRE masters out there, so we're also launching ATT&CKY BIRD bit.ly/ATTbirb. Can you avoid the adversaries for more than a couple seconds? Demonstrate your true & mastery.
100
MITRE ATT&CK @attack.mitre.org · 01/04/2024
Next: Learn the framework through finding its connections. We're launching a daily puzzle, ATT&CKions, to help you see the patterns in the Matrix bit.ly/ATTions.
110
MITRE ATT&CK @attack.mitre.org · 11/03/2024
This is a technique with a storied history including the Sandworm’s NotPetya attack and the SolarWinds compromise. Mitigations and detections can be especially difficult for defenders but patch management, vulnerability scanning, and verification of distributed binaries all play crucial roles.
100
MITRE ATT&CK @attack.mitre.org · 11/03/2024
You guessed it: We’re spotlighting the “Compromise Software Supply Chain” technique today attack.mitre.org/techniques/T...
110
MITRE ATT&CK @attack.mitre.org · 11/03/2024
This was accomplished in several ways including that they compromised the supply chain of a software developer of Tibetan language translation apps. Read the report: www.welivesecurity.com/en/eset-rese...
100
MITRE ATT&CK @attack.mitre.org · 05/03/2024
Remote Services, T1021 and its eight sub-techniques, shows how adversaries abuse services that accept remote connections such as SSH and RDP. If the services aren’t absolutely required, remove or disable them. attack.mitre.org/techniques/T...
100
MITRE ATT&CK @attack.mitre.org · 05/03/2024
The CISA report dives deep on this particular set of incidents while Valid Accounts, T1078, has excellent general guidance to mitigate against abuse of valid accounts including strong account use policies attack.mitre.org/techniques/T...
100
MITRE ATT&CK @attack.mitre.org · 05/03/2024
It’s worth spotlighting Valid Accounts (attack.mitre.org/techniques/T...) and Remote Services (attack.mitre.org/techniques/T...) as multiple adversaries leveraged compromised accounts to laterally move within internal systems via RDP and SSH.
100
MITRE ATT&CK @attack.mitre.org · 27/02/2024
This was defended against in some instances when the network was configured with device enrollment policies. It’s important to ensure device enrollment policies are set to permit authorized devices only, to use zero-touch enrollment, and to be aware of and defend against phishing and MFA bombing.
110
MITRE ATT&CK @attack.mitre.org · 27/02/2024
Let’s look at Account Manipulation: Device Registration (attack.mitre.org/techniques/T...). This is important but it's also an easy one for defenders to overlook. Recent reporting shows how APT29 is registering their own devices as new devices on cloud tenants in order to gain access to networks.
111
MITRE ATT&CK @attack.mitre.org · 08/02/2024
It’s important to detect this technique by monitoring for the use of commands used to access these logs and mitigate the risk by limiting the ability to access and export the logs. Check out the CISA report: www.cisa.gov/news-events/...
021
MITRE ATT&CK @attack.mitre.org · 08/02/2024
Today’s winner is Log Enumeration (T1654 attack.mitre.org/techniques/T...). Recent CISA reporting detailed how the threat actor Volt Typhoon captured successful logon events to analyze user authentication patterns within the network
141
MITRE ATT&CK @attack.mitre.org · 25/12/2023
Wishing all of you an incident-free holiday season from the ATT&CK team. 🫶🎁.
What happens when you tell an AI “more ampersand” enough times.
020
MITRE ATT&CK @attack.mitre.org · 19/12/2023
Hi! We're new here, but see a bunch of familiar faces.
Hello World in C
0114