MITRE ATT&CK

@attack.mitre.org

MITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Reposting ≠ endorsement.

ATT&CK v19 is live! 🍾 We've split Defense Evasion into Stealth and Defense Impairment, introduced Sub-Techniques to ICS ATT&CK, Detection Strategies to Mobile, and added some AI and Social Engineering to Enterprise. Check out all the details in our blog post at medium.com/mitre-attack....

ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage…

ATT&CK v19 is here, and this release has been a long time coming. The Defense Evasion split is finally in place, detection strategies are…

medium.com

Pencil in Oct 27-28, 2026 for ATT&CKcon 7.0! We'll be live for both in-person in McLean, VA and live online. Drop us a line at attackcon@mitre.org if you're interested in sponsoring, watch for our CFP to open in May, and grab a ticket when they go on sale this summer. See you in October!

Bild

Are you ready to celebrate National Chocolate Day this October 28th? We will be by releasing ATT&CK v18, our next version of MITRE ATT&CK! We'll be releasing our usual updates to Techniques and Groups, but check out some big defensive changes on the way in this release (medium.com/mitre-attack...).

A chocolate ampersand

The ATT&CK team is out at #hackersummercamp and happy to chat, meet up, or just share some stickers. Drop a DM or stop by an appearance if you’re interested in saying hi!

Adam Pennington@whatshisface.bsky.social · last yr.

Headed for Vegas for @bsideslv.org, @defcon.bsky.social, and @blackhatevents.bsky.social! I have hundreds of @attack.mitre.org stickers and will be popping up Friday 11am on DEF CON Creator Stage 2 (defcon.org/html/defcon-...), and for a short talk in the AttackIQ BH booth (#5030) Wed 11am.

Tonight's the night! The ATT&CKcon 6.0 CFP will automatically stop accepting submissions at 8pm ET tonight. Historically we get about half of our submissions today, so all you procrastinators are in good company. Give it your best shot at openconf.org/ATTACKCON2025.

a man in a black shirt and tie is holding a pen and a notebook and says you 're on my list

ALT: a man in a black shirt and tie is holding a pen and a notebook and says you 're on my list

media.tenor.com

An old idea that still holds true: Fight the enemy where they aren’t. Threat actors take this advice to heart by avoiding Endpoint Detection and Response solutions and targeting systems that do not generally support EDR such as VMware ESXi hosts.

🎣 Get in loser, we’re going phishing. This week, we’re going to spotlight how Russian threat actors are phishing targets associated with Ukraine and human rights to abuse Microsoft OAuth.

🔦 Let’s look closely at an adversary technique grabbing headlines: Medusa ransomware actors are using vulnerable or signed drivers to kill endpoint detection and response tools.

🚪🗝️ Let’s sneak in through the backdoor to peek at more adversary techniques. Today, we focus on T1059.001: Command-Line Interface: PowerShell, which is being used by a notable APT group to deploy their -- you guessed it -- signature backdoor.

Celebrate April 22nd with ATT&CK v17! The next version of ATT&CK is almost here, with new content related to the ESXi hypervisor, broad improvements to defenses, and updates to techniques, groups, and software across the framework.

Earth with ampersand