MITRE ATT&CK @attack.mitre.org · 29/09/2026If you register before 10/1 to attend in-person, you can submit a Lightning Talk for consideration. Keep an eye on your email for details after you register. 010
MITRE ATT&CK @attack.mitre.org · 29/09/2026Excited to share our full ATT&CKcon 7.0 agenda. We cannot wait to welcome the ATT&CK community both in person and virtually on October 27. Virtual tickets are now available. Check out our full set of talks and register today! na.eventscloud.com/website/93925/ 161
MITRE ATT&CK @attack.mitre.org · 29/06/2026It's the final countdown for the ATT&CKcon CFP Friendly reminder that our CFP closes 7/2 at 8PM ET. If your entry is still 3 bullet points in Notes, or a fully formed concept you've been "letting marinate," this is your sign. Be a hero, hitting submit is underrated www.openconf.org/ATTACKcon202... 010
MITRE ATT&CK @attack.mitre.org · 24/06/2026On Cat World Domination Day, it feels only right to acknowledge the obvious (cats run everything). Even if you don't answer to a 🐈 overlord, a reminder that the ATT&CKcon 7.0 CFP closes 7/2 at 8pm ET. Take back a bit of control and submit before next Thursday: www.openconf.org/ATTACKcon202.... 030
MITRE ATT&CK @attack.mitre.org · 17/06/202615 days left. Every year, without fail, we get a handful of emails after the ATT&CKcon CFP deadline that say some variation of, "I was just about to submit..." Don't be that person. CFP closes 7/2 at 8:00 PM EDT. No extensions, no secret back door, no "just one more." openconf.org/ATTACKcon2026/static.klipy.comJudge Judy's Surprised ReactionALT: Judge Judy's Surprised Reaction 130
MITRE ATT&CK @attack.mitre.org · 26/05/2026And last but not least, interested in getting in front of the ATT&CK community through conference sponsorship? Check out na.eventscloud.com/website/9392..., we'd love to hear from you!na.eventscloud.comATT&CKcon 7.0 010
MITRE ATT&CK @attack.mitre.org · 26/05/2026Looking to sit back and join us from the audience? Hang tight, in-person and virtual ticket sales will open over the coming months. Watch this space or na.eventscloud.com/website/93925/ for more details.na.eventscloud.comATT&CKcon 7.0The only cybersecurity conference led by the MITRE ATT&CK team | October 27-28, 2026 110
MITRE ATT&CK @attack.mitre.org · 26/05/2026The ATT&CKcon 7.0 CFP is open! Want to join us on stage in McLean, VA, 10/28-29? We'd love to hear your best talk ideas with some relation to ATT&CK so we can bring to the wider ATT&CK community. To submit to go www.openconf.org/ATTACKcon2026/ before 8pm ET on July 2nd. 121
MITRE ATT&CK @attack.mitre.org · 28/04/2026ATT&CK v19 is live! 🍾 We've split Defense Evasion into Stealth and Defense Impairment, introduced Sub-Techniques to ICS ATT&CK, Detection Strategies to Mobile, and added some AI and Social Engineering to Enterprise. Check out all the details in our blog post at medium.com/mitre-attack....medium.comATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage…ATT&CK v19 is here, and this release has been a long time coming. The Defense Evasion split is finally in place, detection strategies are… 081
MITRE ATT&CK @attack.mitre.org · 01/04/2026🚨 We’re thrilled to announce a new addition to ATT&CK… 🥁🥁🥁 ✨ EMOJIS ✨ 🤩🤠🥳😻🤘 😵💫 Techniques can be hard to describe 📝➡️🧠 Some folks are visual learners 👀📊 So… why not add a little 🔥🎨 fun? Example: attack.mitre.org/emoji-techni... 💡Drop your best technique ➡️ emoji translations in replies 🗣️👇attack.mitre.orgEmoji Technique | MITRE ATT&CK® 151
MITRE ATT&CK @attack.mitre.org · 30/03/2026ATT&CK v19 is coming 4/28! Along with our usual updates, the big change this release is the replacement of the Defense Evasion tactic in Enterprise ATT&CK with new Stealth and Impair Defenses tactics. Cat Self talked about what's changing back at ATT&CKcon 6.0 (www.youtube.com/watch?v=0rQQ...). 160
MITRE ATT&CK @attack.mitre.org · 09/03/2026Pencil in Oct 27-28, 2026 for ATT&CKcon 7.0! We'll be live for both in-person in McLean, VA and live online. Drop us a line at attackcon@mitre.org if you're interested in sponsoring, watch for our CFP to open in May, and grab a ticket when they go on sale this summer. See you in October! 022
MITRE ATT&CK @attack.mitre.org · 11/12/2025An exciting role of the ATT&CK team is getting to engage with the community. As today's kids are increasingly plugged into technologies, cybersecurity education for them is increasingly important too--and our leadership has been doing just that. www.mitre.org/news-insight...mitre.orgIntroducing Cybersecurity to the Most Connected Generation | MITREMITRE’s cyber experts present the ATT&CK® framework to young people as an entrée into cybersecurity. 061
MITRE ATT&CK @attack.mitre.org · 07/11/2025It was recorded, and slides are now being shared.... Slides and videos from ATT&CKcon 6.0 are now posted in an easy to find way. Check out attack.mitre.org/resources/at... to check out our great talks (and Couch Talks) from October, or even check out past ATT&CKcons from that same page.attack.mitre.orgMITRE ATT&CKcon - ATT&CKcon 6.0 | MITRE ATT&CK® 075
MITRE ATT&CK @attack.mitre.org · 28/10/2025ATT&CK v18 is now out! Today marks the release of Detection Strategies, where we've moved from single-sentence notes to structured, behavior-focused strategies across the board. A new blog post describes the changes medium.com/mitre-attack... with details at attack.mitre.org/resources/up....medium.comATT&CK v18: Detection Strategies, More Adversary Insights,ATT&CK v18 is released with new Detection Strategies, Analytics, and revamped Data Components! 095
MITRE ATT&CK @attack.mitre.org · 23/10/2025🚨Big changes coming to ATT&CK on Tue (10/28) as we improve detections! It you use x_mitre_detection or x_mitre_data_sources, you need to update. @lexonthehunt.bsky.social covers the changes at: 🖥️ mitre.app.box.com/s/3lynwg8ebc... 📽️ mitre.brandlive.com/MITRE-ATTACK... 📖 medium.com/p/7e6738fec31fmedia.tenor.coma man in a hooded jacket says " i am once again asking for your attention "ALT: a man in a hooded jacket says " i am once again asking for your attention " 132
MITRE ATT&CK @attack.mitre.org · 03/09/2025Virtual registration for ATT&CKcon 6.0 is open! We hope you'll chose to join us in person at ATT&CK's home in McLean, VA October 14-15... But if you can't, catch the action for free online by registering at na.eventscloud.com/attackcon6/. Catch all of our talks & some exclusive online only content. 030
MITRE ATT&CK @attack.mitre.org · 26/08/2025The ATT&CKcon 6.0 talk lineup is now live! Check out our fabulous group of speakers, or pick up a ticket to join us October 14-15 in McLean, VA at na.eventscloud.com/attackcon6. Only able to join us virtually? Hang tight, virtual registration opens September 3rd. 031
MITRE ATT&CK @attack.mitre.org · 19/08/2025Want to learn even more detail about v18? We'll be covering it in depth at ATT&CKcon 6.0 October 14-15. In-person tickets are onsite now at na.eventscloud.com/attackcon6, with virtual registration coming in early September.na.eventscloud.comATT&CKcon 6.0MITRE ATT&CKcon | October 14 - 15, 2025 010
MITRE ATT&CK @attack.mitre.org · 19/08/2025Are you ready to celebrate National Chocolate Day this October 28th? We will be by releasing ATT&CK v18, our next version of MITRE ATT&CK! We'll be releasing our usual updates to Techniques and Groups, but check out some big defensive changes on the way in this release (medium.com/mitre-attack...). 130
MITRE ATT&CK @attack.mitre.org · 05/08/2025The ATT&CK team is out at #hackersummercamp and happy to chat, meet up, or just share some stickers. Drop a DM or stop by an appearance if you’re interested in saying hi! 021
MITRE ATT&CK @attack.mitre.org · 30/07/2025In-person ATT&CKcon 6.0 ticket sales are open! Come join us October 14-15 at ATT&CK HQ in McLean, VA. na.eventscloud.com/attackcon6/ We're almost set to announce this year's exciting speaker lineup and will open virtual registration Sep 3rd, so stay tuned!na.eventscloud.comATT&CKcon 6.0MITRE ATT&CKcon | October 14 - 15, 2025 033
MITRE ATT&CK @attack.mitre.org · 09/07/2025Tonight's the night! The ATT&CKcon 6.0 CFP will automatically stop accepting submissions at 8pm ET tonight. Historically we get about half of our submissions today, so all you procrastinators are in good company. Give it your best shot at openconf.org/ATTACKCON2025.media.tenor.coma man in a black shirt and tie is holding a pen and a notebook and says you 're on my listALT: a man in a black shirt and tie is holding a pen and a notebook and says you 're on my list 021
MITRE ATT&CK @attack.mitre.org · 07/07/2025Wondering about tickets for ATT&CKcon 6.0? Details are coming soon. 000
MITRE ATT&CK @attack.mitre.org · 07/07/2025We are excited to announce our ATT&CKcon 6.0 keynote, Lillian Teng! Lillian's worn numerous hats in cyber at NCIS, FBI, Yahoo, and Capital One and has served with the KC7 Foundation, GirlSecurity, and LEAP. Want to also join us on stage? CFP closes Wed night! www.openconf.org/ATTACKCON2025. 160
MITRE ATT&CK @attack.mitre.org · 03/06/2025Looking to attend in-person or virtually? Hang tight, ticket sales will be announced in the coming months. 000
MITRE ATT&CK @attack.mitre.org · 03/06/2025Interested in sponsoring ATT&CKcon? We have a couple slots left, and you can find out more at na.eventscloud.com/attackcon6.na.eventscloud.comATT&CKcon 6.0MITRE ATT&CKcon | October 14 - 15, 2025 100
MITRE ATT&CK @attack.mitre.org · 03/06/2025We're looking for what's practical, what's aspirational, and what you should never ever do with ATT&CK. We're looking to hear from the community on any and all applications of ATT&CK. From managers to operators, if you're using ATT&CK we want to hear from you. 110
MITRE ATT&CK @attack.mitre.org · 03/06/2025The MITRE ATT&CKcon 6.0 CFP is now open! Are you interested in joining us on the ATT&CKcon stage in McLean, VA October 14-15, 2025? Pitch us on your best ATT&CK related talk! Our CFP will close on July 9th at 8pm ET sharp, so get those proposals started. www.openconf.org/ATTACKCON202... 142
MITRE ATT&CK @attack.mitre.org · 08/05/2025And make sure to check out the ESXi material on ATT&CK including T1675 cloud.google.com/blog/topics/... And see the entire ATT&CK v17 release for more information medium.com/mitre-attack... 010
MITRE ATT&CK @attack.mitre.org · 08/05/2025Read up on Google’s reporting: cloud.google.com/blog/topics/...cloud.google.comVMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors | Mandiant | Google Cloud Blog 110
MITRE ATT&CK @attack.mitre.org · 08/05/2025Google’s reporting details UNC3886, Chinese cyber espionage group, using a zero-day vulnerability that enabled the execution of privileged commands across guest virtual machines without authentication of guest credentials from a compromised ESXi host and no default logging on guest VMs. 100
MITRE ATT&CK @attack.mitre.org · 08/05/2025T1675 describes activity in which an adversary abuses ESXi admin services to execute commands on guest machines. 100
MITRE ATT&CK @attack.mitre.org · 08/05/2025One of the big updates for ATT&CK v17 was the new platform ESXi which reflects the rise in attacks on virtualization infrastructure. The technique we’re spotlighting today is new to ATT&CK: T1675 ESXi Administration Command attack.mitre.org/techniques/T...attack.mitre.orgESXi Administration Command, Technique T1675 - Enterprise | MITRE ATT&CK® 100
MITRE ATT&CK @attack.mitre.org · 08/05/2025We’re currently reading Google’s reporting on VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors cloud.google.com/blog/topics/...cloud.google.comVMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors | Mandiant | Google Cloud Blog 100
MITRE ATT&CK @attack.mitre.org · 08/05/2025An old idea that still holds true: Fight the enemy where they aren’t. Threat actors take this advice to heart by avoiding Endpoint Detection and Response solutions and targeting systems that do not generally support EDR such as VMware ESXi hosts. 191
MITRE ATT&CK @attack.mitre.org · 30/04/2025Read Volexity’s reporting here www.volexity.com/blog/2025/04... and be sure to browse the relevant procedures, mitigations, and detections at the ATT&CK technique page: attack.mitre.org/techniques/T...volexity.comPhishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth WorkflowsSince early March 2025, Volexity has observed multiple suspected Russian threat actors conducting highly targeted social engineering operations aimed at gaining access to the Microsoft 365 (M365) acco... 010
MITRE ATT&CK @attack.mitre.org · 30/04/2025Signal is a powerful end-to-end encrypted chat app. At the end of the day, that doesn’t help at all when you’re being spearphished. In fact, the lack of visibility and detection inherent in an encrypted chat app could even potentially hurt. That’s a wrinkle requiring vigilance on all parts. 110
MITRE ATT&CK @attack.mitre.org · 30/04/2025The world turns, the seasons change, but Russian threat actors targeting Microsoft 365 accounts stays the same. Earlier this year, the same actors were spotted conducting similar attacks also leveraging chat apps like Signal www.volexity.com/blog/2025/02...volexity.comMultiple Russian Threat Actors Targeting Microsoft Device Code AuthenticationStarting in mid-January 2025, Volexity identified several social-engineering and spear-phishing campaigns by Russian threat actors aimed at compromising Microsoft 365 (M365) accounts. These attack cam... 111
MITRE ATT&CK @attack.mitre.org · 30/04/2025This behavior maps to T1566.003 Phishing: Spearphishing via Service, a technique in which adversaries send messages through various non-enterprise controlled services in large part because they are more likely to have a less-strict security policy than an enterprise. attack.mitre.org/techniques/T...attack.mitre.orgPhishing: Spearphishing via Service, Sub-technique T1566.003 - Enterprise | MITRE ATT&CK® 110
MITRE ATT&CK @attack.mitre.org · 30/04/2025The adversary contacts a victim via Signal or WhatsApp, invites them to a meeting, and sends them an OAuth phishing URL to join. Once the OAuth code is given up, the threat actor can access the victim’s M365 account. 110
MITRE ATT&CK @attack.mitre.org · 30/04/2025Russian actors have been spotted conducting highly targeted social engineering operations aimed at gaining access to their target’s Microsoft 365 accounts. 110
MITRE ATT&CK @attack.mitre.org · 30/04/2025We’re currently reading Volexity’s recent report: “Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows” www.volexity.com/blog/2025/04...volexity.comPhishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth WorkflowsSince early March 2025, Volexity has observed multiple suspected Russian threat actors conducting highly targeted social engineering operations aimed at gaining access to the Microsoft 365 (M365) acco... 121
MITRE ATT&CK @attack.mitre.org · 30/04/2025🎣 Get in loser, we’re going phishing. This week, we’re going to spotlight how Russian threat actors are phishing targets associated with Ukraine and human rights to abuse Microsoft OAuth. 1103
MITRE ATT&CK @attack.mitre.org · 24/04/2025Read about T1668 Exclusive Control at ATT&CK attack.mitre.org/techniques/T... and check out all of V17’s new changes here: attack.mitre.org/resources/up...attack.mitre.orgExclusive Control, Technique T1668 - Enterprise | MITRE ATT&CK® 010
MITRE ATT&CK @attack.mitre.org · 24/04/2025An adversary who finds a vulnerable target but wants to be the only threat actor on that machine might take similar actions like disabling vulnerable services or removing malware already on the device www.f-secure.com/v-descs/nets... 100
MITRE ATT&CK @attack.mitre.org · 24/04/2025For this technique, we’re reading a Google report in which researchers spotted some unusual behavior by the initial access brokers UNC5174: The hackers exploited a vulnerability, gained access, and then self-patched the machine. cloud.google.com/blog/topics/...cloud.google.comBringing Access Back — Initial Access Brokers Exploit F5 BIG-IP (CVE-2023-46747) and ScreenConnect | Google Cloud BlogWe observed a threat actor exploiting F5, ConnectWise, and other vulnerabilities. 100
MITRE ATT&CK @attack.mitre.org · 24/04/2025Exclusive Control is a persistence technique in which an adversary prevents other threat actors from accessing or maintaining a foothold on the same system as them. 110
MITRE ATT&CK @attack.mitre.org · 24/04/2025Make sure you read the team’s full write up on the new version of ATT&CK including a whole new ESXi platform and updates across the board medium.com/mitre-attack...medium.comATT&CK v17: New Platform (ESXi), Collection Optimization, & More CountermeasuresBy: Amy Robertson and Adam Pennington 100
MITRE ATT&CK @attack.mitre.org · 24/04/2025What happens when an adversary successfully compromises a target and then “closes the door” behind them? They gain Exclusive Control, a new technique for ATT&CK v17. Let’s take a closer look: attack.mitre.org/techniques/T...attack.mitre.orgExclusive Control, Technique T1668 - Enterprise | MITRE ATT&CK® 151