Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Framework structureIntermediate

The MITRE ATT&CK® Data Model

How ATT&CK represents tactics, techniques, sub-techniques, relationships, detections, mitigations, groups, software, campaigns, and supporting references as connected objects.

Framework mapping

MITRE ATT&CK® Enterprise mapping

Catalog v19.2

Framework-methodology article aligned to Enterprise ATT&CK v19.2; no technique equivalence is asserted.

Why this matters

How ATT&CK represents tactics, techniques, sub-techniques, relationships, detections, mitigations, groups, software, campaigns, and supporting references as connected objects.

ATT&CK is most useful when it creates a common language for a real decision. The framework can connect threat intelligence, architecture, security operations, incident response, assessment, and leadership reporting, but the meaning of a mapping depends on the evidence and method behind it.

Bare Metal Cyber treats ATT&CK metadata as a maintained reference layer. Original explanations, labs, course links, and defensive guidance remain separate so a framework refresh cannot silently replace the educational content or its local context.

Core elements

The following elements establish the vocabulary needed to use this part of ATT&CK consistently. Each element should be read as a specific data or analytic concept rather than a colored cell on a matrix.

  • Core behavior objects: tactics, techniques, and sub-techniques
  • Defensive objects: mitigations, detection strategies, analytics, and data components
  • Threat-intelligence objects: groups, software, campaigns, and procedure examples
  • Relationships that connect objects without collapsing them into one category
  • External references, stable identifiers, versions, platforms, and lifecycle fields

A defensible workflow

A repeatable workflow makes ATT&CK mappings easier to review, compare, and update. The sequence below starts with the operational question and preserves enough context for another analyst to reproduce the result.

  • Identify the question the data must answer.
  • Select the smallest relevant object set rather than importing everything into one table.
  • Preserve object identifiers and relationship direction.
  • Record the ATT&CK release used for the analysis.
  • Keep local editorial content separate from imported framework metadata.

Evidence, confidence, and scope

Every mapping should identify the observation, source, time range, affected platform, and confidence. A technique ID without evidence may be a hypothesis, a vendor claim, or a convenient label; it is not automatically a verified incident fact or a tested control.

Scope also matters. A detection validated on one Windows server does not prove coverage across a cloud tenant, identity provider, Linux fleet, or network-device estate. State what was assessed, what was excluded, and which ATT&CK release controlled the analysis.

Common failure modes

Most ATT&CK mistakes do not come from misunderstanding an identifier. They come from losing the relationship between behavior, evidence, technology, and the decision that the mapping was intended to support.

  • Treating a technique ID as proof that a specific actor performed the behavior
  • Discarding relationships and retaining only object names
  • Overwriting local notes when framework data updates
  • Ignoring deprecated or revoked object status
  • Mixing Enterprise, Mobile, and ICS objects without recording domain

Safe practitioner exercise

Use a public incident report, a sanitized internal case, or a fictional scenario. Identify three observable actions, map only the behaviors supported by the evidence, and record confidence plus an alternative interpretation.

Next, describe one preventive control, one detection opportunity, one investigation question, and one recovery consideration for each behavior. Compare your work with a peer and resolve differences by returning to the evidence rather than by choosing the broadest possible mapping.

  • Record the Enterprise ATT&CK catalog version used.
  • Preserve the source passage or event that supports each mapping.
  • Mark not observed, not applicable, not tested, and unknown as different states.
  • Document any deprecated, revoked, or renamed object encountered.
  • Retain the analysis as a versioned artifact rather than only a screenshot.

How Bare Metal Cyber uses this material

This Wiki stores stable ATT&CK identifiers, catalog version, object names, platform and tactic metadata, mapping role, review date, and links to the official object. Existing BMC concept pages are mapped only when they provide direct, defensive, investigative, or contextual coverage.

Technique coverage in an Academy course is derived from exact Wiki-to-lesson relationships. A course is not marked as teaching a technique merely because a transcript contains a weak keyword match. Gaps are retained as curriculum opportunities for future lessons, books, podcast episodes, and Magazine features.

Attribution and independence

© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.

The descriptions and instructional guidance on this page are original Bare Metal Cyber content. Official identifiers, names, relationships, and version information remain attributed to MITRE and should be verified against the linked ATT&CK resources when used for operational decisions.

Certification relevance

This subject appears in or supports the following certification bodies of knowledge:

CompTIA CySA+GIAC GCTIISC2 CISSP

Authoritative sources