Glossary
MITRE ATT&CK
Definition: MITRE ATT&CK is a publicly maintained knowledge base of real-world adversary tactics and techniques, organised as a matrix that lets defenders map what an attacker actually did to a specific, named technique ID rather than a vague description.
The value of ATT&CK is precision. “Attacker used stolen credentials” is a paragraph. “T1078 Valid Accounts” is a control you can build a detection rule against. Three technique IDs recur across TAB’s own breach coverage: T1078 (Valid Accounts, the mechanism behind a 24-billion-record infostealer corpus feeding credential-based attacks), T1190 (Exploit Public-Facing Application, used twice in a single incident where an autonomous AI agent chained two separate internet-facing vulnerabilities), and T1552.004 (Unsecured Credentials: Private Keys, the Accenture secrets-sprawl breach). ATT&CK also anchors the Know Your Adversary series profiling active ransomware and extortion crews by their signature techniques, rather than by which headlines they made most recently.