MITRE ATT&CK

Glossary

MITRE ATT&CK

Definition: MITRE ATT&CK is a publicly maintained knowledge base of real-world adversary tactics and techniques, organised as a matrix that lets defenders map what an attacker actually did to a specific, named technique ID rather than a vague description.

The value of ATT&CK is precision. “Attacker used stolen credentials” is a paragraph. “T1078 Valid Accounts” is a control you can build a detection rule against. Three technique IDs recur across TAB’s own breach coverage: T1078 (Valid Accounts, the mechanism behind a 24-billion-record infostealer corpus feeding credential-based attacks), T1190 (Exploit Public-Facing Application, used twice in a single incident where an autonomous AI agent chained two separate internet-facing vulnerabilities), and T1552.004 (Unsecured Credentials: Private Keys, the Accenture secrets-sprawl breach). ATT&CK also anchors the Know Your Adversary series profiling active ransomware and extortion crews by their signature techniques, rather than by which headlines they made most recently.

Read the full case study on Substack: One Stolen Credential Opened Accenture’s Master Keyring (T1552.004) →

← Back to Glossary