What is MITRE ATT&CK?
MITRE ATT&CK is a curated, globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It organizes how attackers operate — from initial access to exfiltration — into a common vocabulary used across the security industry.
In threat modeling, mapping threats to ATT&CK techniques grounds the analysis in how attackers actually behave, improves consistency, and helps reduce speculative or hallucinated threats. It also makes findings easier to communicate and to connect with detection and response.
Related terms
Virantis automates threat modeling with agentic AI — STRIDE & PASTA on every change.
Request Early Access