From a clue to the right ATT&CK entry
Select each step. The official link changes as you move from the broad goal to a specific behavior.
An employee receives a targeted email containing a malicious link intended to gain access to the organization. The email alone does not show whether anyone clicked it or whether access succeeded.
Use the behavior, not the headline
“Phishing” can mean different things. If the goal is gathering information before an intrusion, compare T1598, Phishing for Information. In this case the goal is initial access, so follow T1566. Read the description and tactic before choosing an ID.
Know where to look on a technique page
This map follows the current Enterprise page for T1566.002, Spearphishing Link. Choose a section to see the question it answers.
Procedure ≠ subtechnique
A subtechnique is a named category of behavior. A procedure example describes a reported implementation by a group or software. Its row may link to a group (G…) or software (S…).
Jump to an official entry
Saw an ID in a report or a procedure row? Paste it here. The tool reads the prefix to tell you what kind of entry it is and builds a link to MITRE. MITRE's page is the source of truth for whether an entry exists or has changed.
Enter an ID above. The letters tell you the entry type; the number gives you an exact way to find it.
| Prefix | Entry type | Answers |
|---|---|---|
TA | Tactic | What goal? |
T / T….nnn | Technique / subtechnique | What action? |
M | Mitigation | How could it be prevented or limited? |
G | Group | Which tracked threat group reportedly used it? |
S | Software | Which malware or tool reportedly used it? |
C | Campaign | Which set of intrusions over a period of time? |
No ID yet?
Start at the Enterprise Matrix if you know the goal, or use the official ATT&CK search if you know a behavior. Read the candidate's description, platforms, and tactic before assigning it to evidence.
Can you find the right part of the page?
Seven short questions: some ask where to look on a page, others give you a new clue to map. After each answer, open the linked MITRE entry and check it yourself.
A reliable reading order
Choose the domain → name the goal → identify the behavior → check the most specific subtechnique → read procedure examples and detection strategy → record the ID and official URL. A technique may belong to more than one tactic, so verify the context.
Based on MITRE ATT&CK Enterprise pages, checked September 2026 (ATT&CK v19.2). Entries and section names can change.
MITRE ATT&CK · FAQ · Version history