The MITRE ATT&CK framework defines 14 adversary tactics—from reconnaissance through impact—that map the progression of a network attack, and it can be used alongside the Cyber Kill Chain to build a comprehensive picture of threat behavior.
MITRE ATT&CK & Cyber Kill Chain
We're going to take a deeper dive into tactics, looking at the different tactics that an adversary will use to get into a network and leverage things within the network.
MITRE ATT&CK outlines 14 different tactics, from reconnaissance to resource development to initial access, execution, and so on and so forth. These tactics are designed to be a flow. That is, a lot of adversaries will start at the beginning here, reconnaissance, and then work their way through these different tactics. Not that they have to necessarily hit each one of these tactics — in fact, they might not even start at reconnaissance. For instance, maybe they're already an insider threat: they're already within the business, within the organization. Well, they have already gained initial access, so they just need to start at the next step. So the MITRE ATT&CK framework allows us to see the flow of what an adversary will do as they are attacking a network, as they are taking advantage of an organization.
I'm here on the MITRE ATT&CK website, and if I go to tactics and say enterprise tactics, I can see all of these listed out. These give us an idea, once again, of what that flow looks like, and a description of each one of those tactics.
Most adversaries are going to start by reconnaissance, which is gathering information about their target. Then they go into resource development. This is where they're going to start collecting the tools and skills and everything they need to carry out their attack. Once they've got that, they're going to try to gain access into the network. This is initial access; this is just getting into the network. Once they're in the network, they might go through the execution phase, where they're going to run some sort of malicious code. And part of this is that they want to gain persistence within the network. That is, they don't want to be booted out of the network as soon as they're in the network, so they're going to try to maintain some sort of foothold in here.
Then they get into privilege escalation. When they get into the network, they might not have the necessary privileges to carry out their attack, so they're going to try to get a higher level of permission. Then they're going to get into defense evasion. They don't want to be detected, so they're going to do some things to avoid being detected. Then they're going to get some credentials in the system. They're going to look for credentials, look for access, so maybe steal some sort of account usernames and passwords.
Then they'll go through a discovery phase. In the discovery phase, they're going to discover things within the network. This is similar to the reconnaissance phase, but now they're inside of the network. Then they're going to perform lateral movement. When they're in the network, they're going to pivot from one area of the network to another, so they're going to move throughout the environment. Then they're going to start collecting more data and gathering more data of their interest. Where are they trying to attack? How are they going to meet their goals?
Then they do what's called command and control. Command and control is the idea that they want to control aspects of the environment, so they're going to communicate within the environment and control different aspects of the environment. Then it comes time for action on objectives. Maybe they're doing some sort of data exfiltration — this is stealing data — or maybe they're trying to make some sort of impact to the environment: manipulating or interrupting the environment, destroying something within the environment, maybe causing some sort of chaos within the environment.
So MITRE ATT&CK is a flow of information, but it's not the only model or framework that we have to work with out there. We also have the cyber kill chain, which has a similar type of flow with similar types of tactics in it. In fact, I've got them all lined up here. You can see that in both models there's a reconnaissance phase. In one model they call it weaponization, in the other resource development. In one there's delivery and exploitation, in the other one there's initial access and execution. So there's a lot of similarities between these two models.
We're going to use both throughout this course. What I'm actually going to do is, if I'm talking more about the steps that an adversary is going to take, I'm going to use the cyber kill chain. It's a little more streamlined in how it operates, and it is used for things like the diamond intrusion analysis model. So we're going to be using that cyber kill chain for much of this course.
But I also want to make sure we approach this from a very comprehensive angle, where we're going to take an in-depth look into how an attacker, how an adversary, attacks a network. So we're going to be using MITRE ATT&CK in many cases to really see the overall picture, all of the things that could happen on your network. So the answer to this is we'll be using both the cyber kill chain and MITRE ATT&CK throughout this course.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →