Avijit Roy
Interactive student guide · about 15 minutes

Learn to navigate MITRE ATT&CK.

Follow one example, learn how to read an ATT&CK page, then find a different technique yourself. You will leave with a repeatable way to connect evidence to an official entry.

Start the guide
Keep two questions in mindWhat was the adversary trying to do? What observable action did they take?
01 / Guided walkthrough

From a clue to the right ATT&CK entry

Select each step. The official link changes as you move from the broad goal to a specific behavior.

Case note · hypothetical

An employee receives a targeted email containing a malicious link intended to gain access to the organization. The email alone does not show whether anyone clicked it or whether access succeeded.

Tactic · whyTechnique · howSubtechnique · more specific howProcedure · observed use

Use the behavior, not the headline

“Phishing” can mean different things. If the goal is gathering information before an intrusion, compare T1598, Phishing for Information. In this case the goal is initial access, so follow T1566. Read the description and tactic before choosing an ID.

Next, learn how to read the entry you found.Read an ATT&CK page →
02 / Page anatomy

Know where to look on a technique page

This map follows the current Enterprise page for T1566.002, Spearphishing Link. Choose a section to see the question it answers.

TA…Tactic ID: the goal.
T…Technique ID: the behavior.
T….002Subtechnique ID: a specific variant.
DET… / AN…Detection strategy / analytic. These are separate defensive entries.

Procedure ≠ subtechnique

A subtechnique is a named category of behavior. A procedure example describes a reported implementation by a group or software. Its row may link to a group (G…) or software (S…).

Now use these cues on a new case.Find a technique →
04 / Find an ID

Jump to an official entry

Saw an ID in a report or a procedure row? Paste it here. The tool reads the prefix to tell you what kind of entry it is and builds a link to MITRE. MITRE's page is the source of truth for whether an entry exists or has changed.

Enter an ID above. The letters tell you the entry type; the number gives you an exact way to find it.

Read the prefix first
PrefixEntry typeAnswers
TATacticWhat goal?
T / T….nnnTechnique / subtechniqueWhat action?
MMitigationHow could it be prevented or limited?
GGroupWhich tracked threat group reportedly used it?
SSoftwareWhich malware or tool reportedly used it?
CCampaignWhich set of intrusions over a period of time?

No ID yet?

Start at the Enterprise Matrix if you know the goal, or use the official ATT&CK search if you know a behavior. Read the candidate's description, platforms, and tactic before assigning it to evidence.

Finish by checking what you learned.Start the practice questions →
05 / Practice

Can you find the right part of the page?

Seven short questions: some ask where to look on a page, others give you a new clue to map. After each answer, open the linked MITRE entry and check it yourself.

A reliable reading order

Choose the domain → name the goal → identify the behavior → check the most specific subtechnique → read procedure examples and detection strategy → record the ID and official URL. A technique may belong to more than one tactic, so verify the context.

Where to go next

  • Groups ↗: open one group and read which techniques it is reported to use, and the evidence cited for each.
  • ATT&CK Navigator ↗: color techniques on the matrix to compare a group's behavior against your detection coverage.
  • MITRE's resources ↗: official getting-started material and training.

Based on MITRE ATT&CK Enterprise pages, checked September 2026 (ATT&CK v19.2). Entries and section names can change.

MITRE ATT&CK · FAQ · Version history