MITRE ATT&CK
Knowledge base of real-world adversary tactics, techniques, and procedures organized into a matrix used to model threats and assess defenses.
Definition
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible framework that catalogs observed adversary behavior across the full attack lifecycle. It is organized as a matrix of tactics (the attacker's goal, e.g., Initial Access, Execution, Persistence, Lateral Movement, Exfiltration) and the specific techniques and sub-techniques attackers use to achieve each. ATT&CK is maintained by MITRE under government and community funding and is updated quarterly. Separate matrices exist for Enterprise, Mobile, ICS (Industrial Control Systems), and the mappings are widely used by SOCs, threat intel teams, red teams, and increasingly by medical device security teams.What this means in practice
For medical device manufacturers, ATT&CK is the lingua franca that connects threat modeling to detection engineering and incident response. When you write a threat model (STRIDE-based or otherwise) the next step is mapping each identified threat to specific ATT&CK techniques so your security controls, monitoring rules, and pen-test scope can be measured against real adversary behavior. ICS ATT&CK is particularly relevant for connected hospital devices that share characteristics with operational technology environments.- •Mapping threats to ATT&CK tactics only (the column headers) instead of specific techniques and sub-techniques, the granularity is the point.
- •Treating ATT&CK as a checklist of controls rather than a reference of attacker behavior, defensive frameworks like D3FEND or NIST CSF cover controls.
- •Ignoring ICS ATT&CK for hospital-deployed devices; many techniques in that matrix apply to networked imaging, lab analyzers, and infusion fleets.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsAAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
MITRE's knowledge graph of defensive cybersecurity countermeasures, explicitly mapped to the ATT&CK techniques they mitigate.
A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryA six-category framework for enumerating threats: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Primary references
3 sources- 1
MITRE ATT&CKVerifiedMITREattack.mitre.org
- 2
ATT&CK for ICSVerifiedMITREattack.mitre.org
- 3
Getting Started with ATT&CKVerifiedMITREmitre.org
Inline markers like [1] jump to the matching reference above.