MITRE ATT&CK Enterprise Tactics
A Quick Reference for the 14 Core Adversary Playbooks
Initial Access
TA0001
Gaining an initial foothold within a network.
Execution
TA0002
Running adversary-controlled code on a system.
Persistence
TA0003
Maintaining access across restarts and interruptions.
Privilege Escalation
TA0004
Gaining higher-level permissions on a system.
Defense Evasion
TA0005
Avoiding detection by security software and analysts.
Credential Access
TA0006
Stealing credentials like account names and passwords.
Discovery
TA0007
Gaining knowledge about the internal network and systems.
Lateral Movement
TA0008
Pivoting through the environment to control remote systems.
Collection
TA0009
Gathering sensitive information prior to exfiltration.
Exfiltration
TA0010
Stealing data from the compromised network.
Command and Control
TA0011
Communicating with compromised systems.
Impact
TA0040
Manipulating, interrupting, or destroying systems and data.
Resource Development
TA0042
Establishing resources to support operations.
Reconnaissance
TA0043
Gathering information to plan future operations.