All cheat sheets

MITRE ATT&CK Tactics and Technique IDs

The 14 Enterprise tactics with their TA IDs, and the technique IDs you will actually meet in reports and exam questions.

Last updated

Download PDF

Free, no signup · 1 page · 14 tactics, 56 techniques · 230 KB

If you only learn three technique IDs

ATT&CK documents over 200 techniques and treats them all equally. These three carry a disproportionate share of real incidents and exam questions.

T1566
PhishingStarts a large share of intrusions. If a question describes a malicious email, this is it.
T1059
Command and Scripting InterpreterWhat runs once they are in, usually PowerShell (.001).
T1486
Data Encrypted for ImpactThe ransomware endgame. Note it is Impact, not Exfiltration.

1. Reconnaissance

TA0043

Gathering information to plan future operations.

  • T1595Active Scanning
  • T1589Gather Victim Identity Info
  • T1598Phishing for Information
  • T1590Gather Victim Network Info

2. Resource Development

TA0042

Establishing resources to support operations.

  • T1583Acquire Infrastructure
  • T1588Obtain Capabilities
  • T1585Establish Accounts
  • T1608Stage Capabilities

3. Initial Access

TA0001

Gaining an initial foothold within a network.

  • T1566Phishing
  • T1190Exploit Public-Facing App
  • T1078Valid Accounts
  • T1133External Remote Services

4. Execution

TA0002

Running adversary-controlled code on a system.

  • T1059Command & Scripting Interpreter
  • T1204User Execution
  • T1053Scheduled Task / Job
  • T1569System Services

5. Persistence

TA0003

Maintaining access across restarts and interruptions.

  • T1547Boot / Logon Autostart
  • T1136Create Account
  • T1505Server Software Component
  • T1098Account Manipulation

6. Privilege Escalation

TA0004

Gaining higher-level permissions on a system.

  • T1068Exploitation for Priv Esc
  • T1548Abuse Elevation Control
  • T1055Process Injection
  • T1134Access Token Manipulation

7. Defense Evasion

TA0005

Avoiding detection by security software and analysts.

  • T1070Indicator Removal
  • T1027Obfuscated Files or Info
  • T1562Impair Defenses
  • T1218System Binary Proxy Exec

8. Credential Access

TA0006

Stealing credentials like account names and passwords.

  • T1110Brute Force
  • T1003OS Credential Dumping
  • T1555Creds from Password Stores
  • T1056Input Capture

9. Discovery

TA0007

Gaining knowledge about the internal network and systems.

  • T1082System Information Discovery
  • T1018Remote System Discovery
  • T1087Account Discovery
  • T1057Process Discovery

10. Lateral Movement

TA0008

Pivoting through the environment to control remote systems.

  • T1021Remote Services
  • T1550Use Alternate Auth Material
  • T1570Lateral Tool Transfer
  • T1091Replication via Removable Media

11. Collection

TA0009

Gathering sensitive information prior to exfiltration.

  • T1005Data from Local System
  • T1114Email Collection
  • T1056Input Capture
  • T1560Archive Collected Data

12. Command & Control

TA0011

Communicating with compromised systems.

  • T1071Application Layer Protocol
  • T1105Ingress Tool Transfer
  • T1573Encrypted Channel
  • T1090Proxy

13. Exfiltration

TA0010

Stealing data from the compromised network.

  • T1041Exfil Over C2 Channel
  • T1048Exfil Over Alt Protocol
  • T1567Exfil Over Web Service
  • T1052Exfil Over Physical Medium

14. Impact

TA0040

Manipulating, interrupting, or destroying systems and data.

  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery
  • T1489Service Stop
  • T1498Network Denial of Service

Frequently asked questions

What is the difference between a tactic and a technique in MITRE ATT&CK?

A tactic is the adversary’s goal, the why: Initial Access, Persistence, Exfiltration. A technique is how they achieve it: Phishing, Valid Accounts, Exfiltration Over C2 Channel. Tactics are the columns of the matrix and there are only 14 of them; techniques are the hundreds of entries filling those columns. Tactic IDs start with TA, technique IDs start with T.

How many tactics are in the ATT&CK Enterprise matrix?

Fourteen, running from Reconnaissance through to Impact. Note that the numbering does not match the order: Initial Access is TA0001 but appears third, because Reconnaissance (TA0043) and Resource Development (TA0042) were added later, in 2020, when ATT&CK extended to cover pre-compromise activity. Ordering by ID is a common mistake.

What do the T numbers and sub-technique numbers mean?

A technique has an ID such as T1059 (Command and Scripting Interpreter). A sub-technique appends a decimal, so T1059.001 is the PowerShell variant of it. Sub-techniques were introduced in 2020 to break broad techniques into specific behaviours. When a question or report cites T1566.001, it is naming Spearphishing Attachment specifically rather than phishing in general.

Is the ATT&CK matrix sequential like the Cyber Kill Chain?

No, and this is the distinction most often tested. The Cyber Kill Chain is a linear seven-phase narrative of an intrusion. ATT&CK is a matrix of observed behaviours with no assumed order: an adversary may loop through Discovery and Lateral Movement repeatedly, skip tactics entirely, or run several in parallel. The tactics are categories, not steps.

Which ATT&CK techniques should I learn first?

T1566 Phishing, because it begins a large share of real intrusions. T1059 Command and Scripting Interpreter, because it is what executes once an attacker has a foothold, most often PowerShell. And T1486 Data Encrypted for Impact, the ransomware endgame, which sits under Impact rather than Exfiltration. Those three cover a disproportionate amount of what you will read in incident reports.

Are there other ATT&CK matrices besides Enterprise?

Yes. Enterprise covers Windows, macOS, Linux, cloud, containers and network devices, and is the one most people mean by ATT&CK. Mobile covers Android and iOS, and ICS covers industrial control systems, which have their own tactics reflecting physical process impact. The tactic list on this page is the Enterprise matrix.

About this cheat sheet

Source
Tactic and technique IDs follow the MITRE ATT&CK Enterprise matrix. ATT&CK is revised periodically: IDs are stable, technique names are not, so check the current version before quoting a name in a report.
Scope
All 14 Enterprise tactics with four representative techniques each, chosen for how often they appear rather than alphabetically. Mobile and ICS have their own matrices and are not covered here.
Want the explanation?
This page is the lookup table. The MITRE ATT&CK framework explained covers what tactics, techniques and procedures actually mean, and Kill Chain vs ATT&CK vs D3FEND compares the three models.
Corrections
Spotted something wrong? Tell us and we will fix it. Compiled and maintained by CyberQuizzer.