MITRE ATT&CK

MITRE ATT&CK is a free, continuously updated knowledge base that documents the real tactics and techniques adversaries use once they gain a foothold in an environment. The name stands for Adversarial Tactics, Techniques, and Common Knowledge.

The framework is organized around tactics, the attacker’s goals such as persistence or exfiltration, and the specific techniques that achieve each goal. Security teams lean on it to map their detection coverage, guide threat hunts, and describe adversary behavior in a shared vocabulary that everyone from analysts to executives can follow. A frequent misuse is treating ATT&CK as a checklist to cover top to bottom. Chasing every technique spreads a team thin, so the stronger move is to prioritize the handful of techniques that match the threats and systems you actually run.

How is MITRE ATT&CK tested on the CISSP?

ATT&CK is most relevant to Domain 7, Security Operations, which carries 13 percent of the exam and includes detection, monitoring, and incident response. You will not be quizzed on individual technique IDs, but you should know what the framework is for and how it strengthens threat detection and response.