Skip to main content
SECURITY-OPERATIONS-SOC5 MIN READ

Map Alerts to ATT&CK Tactics

Use MITRE ATT&CK tactics and techniques to describe what an alert may mean.

The reframe: Tool names tell you what fired; ATT&CK helps you explain what the adversary may be trying to do. Tactic The tactic is the objective. A suspicious process may be execution, defense evasion, discovery, or credential access depending on context. Technique The technique is the method. Scheduled task creation, PowerShell, valid accounts, remote services, and data staged each point to a different investigation path. Scope question Once you map the behavior, ask the next question tied to that tactic: persistence asks where else it was installed, credential access asks what secrets were touched, and command and control asks which…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us