It's the final countdown for the ATT&CKcon CFP Friendly reminder that our CFP closes 7/2 at 8PM ET. If your entry is still 3 bullet points in Notes, or a fully formed concept you've been "letting marinate," this is your sign. Be a hero, hitting submit is underrated www.openconf.org/ATTACKcon202...
MITRE ATT&CK
@attack.mitre.org
MITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Reposting ≠ endorsement.
On Cat World Domination Day, it feels only right to acknowledge the obvious (cats run everything). Even if you don't answer to a 🐈 overlord, a reminder that the ATT&CKcon 7.0 CFP closes 7/2 at 8pm ET. Take back a bit of control and submit before next Thursday: www.openconf.org/ATTACKcon202....
15 days left. Every year, without fail, we get a handful of emails after the ATT&CKcon CFP deadline that say some variation of, "I was just about to submit..." Don't be that person. CFP closes 7/2 at 8:00 PM EDT. No extensions, no secret back door, no "just one more." openconf.org/ATTACKcon2026/
Judge Judy's Surprised Reaction
ALT: Judge Judy's Surprised Reaction
static.klipy.com
The ATT&CKcon 7.0 CFP is open! Want to join us on stage in McLean, VA, 10/28-29? We'd love to hear your best talk ideas with some relation to ATT&CK so we can bring to the wider ATT&CK community. To submit to go www.openconf.org/ATTACKcon2026/ before 8pm ET on July 2nd.
ATT&CK v19 is live! 🍾 We've split Defense Evasion into Stealth and Defense Impairment, introduced Sub-Techniques to ICS ATT&CK, Detection Strategies to Mobile, and added some AI and Social Engineering to Enterprise. Check out all the details in our blog post at medium.com/mitre-attack....
ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage…
ATT&CK v19 is here, and this release has been a long time coming. The Defense Evasion split is finally in place, detection strategies are…
medium.com
🚨 We’re thrilled to announce a new addition to ATT&CK… 🥁🥁🥁 ✨ EMOJIS ✨ 🤩🤠🥳😻🤘 😵💫 Techniques can be hard to describe 📝➡️🧠 Some folks are visual learners 👀📊 So… why not add a little 🔥🎨 fun? Example: attack.mitre.org/emoji-techni... 💡Drop your best technique ➡️ emoji translations in replies 🗣️👇
Emoji Technique | MITRE ATT&CK®
attack.mitre.org
ATT&CK v19 is coming 4/28! Along with our usual updates, the big change this release is the replacement of the Defense Evasion tactic in Enterprise ATT&CK with new Stealth and Impair Defenses tactics. Cat Self talked about what's changing back at ATT&CKcon 6.0 (www.youtube.com/watch?v=0rQQ...).
Pencil in Oct 27-28, 2026 for ATT&CKcon 7.0! We'll be live for both in-person in McLean, VA and live online. Drop us a line at attackcon@mitre.org if you're interested in sponsoring, watch for our CFP to open in May, and grab a ticket when they go on sale this summer. See you in October!
An exciting role of the ATT&CK team is getting to engage with the community. As today's kids are increasingly plugged into technologies, cybersecurity education for them is increasingly important too--and our leadership has been doing just that. www.mitre.org/news-insight...
Introducing Cybersecurity to the Most Connected Generation | MITRE
MITRE’s cyber experts present the ATT&CK® framework to young people as an entrée into cybersecurity.
mitre.org
It was recorded, and slides are now being shared.... Slides and videos from ATT&CKcon 6.0 are now posted in an easy to find way. Check out attack.mitre.org/resources/at... to check out our great talks (and Couch Talks) from October, or even check out past ATT&CKcons from that same page.
MITRE ATT&CKcon - ATT&CKcon 6.0 | MITRE ATT&CK®
attack.mitre.org
ATT&CK v18 is now out! Today marks the release of Detection Strategies, where we've moved from single-sentence notes to structured, behavior-focused strategies across the board. A new blog post describes the changes medium.com/mitre-attack... with details at attack.mitre.org/resources/up....
ATT&CK v18: Detection Strategies, More Adversary Insights,
ATT&CK v18 is released with new Detection Strategies, Analytics, and revamped Data Components!
medium.com
🚨Big changes coming to ATT&CK on Tue (10/28) as we improve detections! It you use x_mitre_detection or x_mitre_data_sources, you need to update. @lexonthehunt.bsky.social covers the changes at: 🖥️ mitre.app.box.com/s/3lynwg8ebc... 📽️ mitre.brandlive.com/MITRE-ATTACK... 📖 medium.com/p/7e6738fec31f
a man in a hooded jacket says " i am once again asking for your attention "
ALT: a man in a hooded jacket says " i am once again asking for your attention "
media.tenor.com
Virtual registration for ATT&CKcon 6.0 is open! We hope you'll chose to join us in person at ATT&CK's home in McLean, VA October 14-15... But if you can't, catch the action for free online by registering at na.eventscloud.com/attackcon6/. Catch all of our talks & some exclusive online only content.
The ATT&CKcon 6.0 talk lineup is now live! Check out our fabulous group of speakers, or pick up a ticket to join us October 14-15 in McLean, VA at na.eventscloud.com/attackcon6. Only able to join us virtually? Hang tight, virtual registration opens September 3rd.
Are you ready to celebrate National Chocolate Day this October 28th? We will be by releasing ATT&CK v18, our next version of MITRE ATT&CK! We'll be releasing our usual updates to Techniques and Groups, but check out some big defensive changes on the way in this release (medium.com/mitre-attack...).
The ATT&CK team is out at #hackersummercamp and happy to chat, meet up, or just share some stickers. Drop a DM or stop by an appearance if you’re interested in saying hi!
Headed for Vegas for @bsideslv.org, @defcon.bsky.social, and @blackhatevents.bsky.social! I have hundreds of @attack.mitre.org stickers and will be popping up Friday 11am on DEF CON Creator Stage 2 (defcon.org/html/defcon-...), and for a short talk in the AttackIQ BH booth (#5030) Wed 11am.
In-person ATT&CKcon 6.0 ticket sales are open! Come join us October 14-15 at ATT&CK HQ in McLean, VA. na.eventscloud.com/attackcon6/ We're almost set to announce this year's exciting speaker lineup and will open virtual registration Sep 3rd, so stay tuned!
ATT&CKcon 6.0
MITRE ATT&CKcon | October 14 - 15, 2025
na.eventscloud.com
Tonight's the night! The ATT&CKcon 6.0 CFP will automatically stop accepting submissions at 8pm ET tonight. Historically we get about half of our submissions today, so all you procrastinators are in good company. Give it your best shot at openconf.org/ATTACKCON2025.
a man in a black shirt and tie is holding a pen and a notebook and says you 're on my list
ALT: a man in a black shirt and tie is holding a pen and a notebook and says you 're on my list
media.tenor.com
We are excited to announce our ATT&CKcon 6.0 keynote, Lillian Teng! Lillian's worn numerous hats in cyber at NCIS, FBI, Yahoo, and Capital One and has served with the KC7 Foundation, GirlSecurity, and LEAP. Want to also join us on stage? CFP closes Wed night! www.openconf.org/ATTACKCON2025.
The MITRE ATT&CKcon 6.0 CFP is now open! Are you interested in joining us on the ATT&CKcon stage in McLean, VA October 14-15, 2025? Pitch us on your best ATT&CK related talk! Our CFP will close on July 9th at 8pm ET sharp, so get those proposals started. www.openconf.org/ATTACKCON202...
An old idea that still holds true: Fight the enemy where they aren’t. Threat actors take this advice to heart by avoiding Endpoint Detection and Response solutions and targeting systems that do not generally support EDR such as VMware ESXi hosts.
🎣 Get in loser, we’re going phishing. This week, we’re going to spotlight how Russian threat actors are phishing targets associated with Ukraine and human rights to abuse Microsoft OAuth.
What happens when an adversary successfully compromises a target and then “closes the door” behind them? They gain Exclusive Control, a new technique for ATT&CK v17. Let’s take a closer look: attack.mitre.org/techniques/T...
Exclusive Control, Technique T1668 - Enterprise | MITRE ATT&CK®
attack.mitre.org
ATT&CK v17 is now live! This release includes the first version of the ESXi platform, a pile of defensive upgrades, and fresh content across Enterprise, Mobile, and ICS. Check out our blog post describing the changes by Amy Robertson & @whatshisface.bsky.social at medium.com/mitre-attack....
ATT&CK v17: New Platform (ESXi), Collection Optimization, & More Countermeasures
By: Amy Robertson and Adam Pennington
medium.com
🤖 It’s time to look at how adversaries are using ChatGPT to pursue information related to cyber intrusion tools and operations
🔦 Let’s look closely at an adversary technique grabbing headlines: Medusa ransomware actors are using vulnerable or signed drivers to kill endpoint detection and response tools.
🚪🗝️ Let’s sneak in through the backdoor to peek at more adversary techniques. Today, we focus on T1059.001: Command-Line Interface: PowerShell, which is being used by a notable APT group to deploy their -- you guessed it -- signature backdoor.
Today we're launching a new system where the public can help us develop the next ATT&CK release through Macrotechnique Refinement. To start refining FUZZYSNUGGLYDUCK, click here: attack.mitre.org/macro-techni.... Fabulous prizes await success.
🚨It’s time to spotlight more headline-making adversary techniques. Today, a classic behavior seen in multiple global espionage operations: LSASS Credential Dumping attack.mitre.org/versions/v16...
OS Credential Dumping: LSASS Memory, Sub-technique T1003.001 - Enterprise | MITRE ATT&CK®
attack.mitre.org
Celebrate April 22nd with ATT&CK v17! The next version of ATT&CK is almost here, with new content related to the ESXi hypervisor, broad improvements to defenses, and updates to techniques, groups, and software across the framework.