Framework mapping
MITRE ATT&CK® Enterprise mapping
Primary BMC learning hub aligned to Enterprise ATT&CK v19.2; no endorsement is implied.
MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.
What MITRE ATT&CK is
MITRE ATT&CK® is a curated knowledge base and model for describing cyber adversary behavior. It gives defenders, threat-intelligence teams, architects, assessors, red teams, and leaders a shared vocabulary for discussing what an adversary is trying to accomplish and how observed behavior supports that objective.
The Enterprise knowledge base is organized around tactics, techniques, sub-techniques, platforms, defensive content, and threat-intelligence relationships. It should be used as a structured source of questions and evidence—not as a product checklist, a guaranteed chronology, or a substitute for understanding the affected environment.
This Bare Metal Cyber learning center transforms framework metadata into original educational material. The goal is to help learners move from an ATT&CK identifier to architecture, telemetry, detection, investigation, mitigation, recovery, and exact Academy lessons.
The Enterprise scope represented here
This release is reviewed against Enterprise ATT&CK catalog version 19.2. It introduces learning hubs for all 15 Enterprise tactics and 50 high-value technique or sub-technique profiles selected for broad defensive value.
The tactic identifiers represented are TA0043, TA0042, TA0001, TA0002, TA0003, TA0004, TA0005, TA0112, TA0006, TA0007, TA0008, TA0009, TA0011, TA0010, TA0040. Platform paths cover Windows, Linux, macOS, cloud and IaaS, identity providers and SaaS, containers, network devices, and ESXi. Pre-compromise behavior is included within the Reconnaissance and Resource Development paths.
- TA0043 — Reconnaissance: Adversaries collect information about people, organizations, technology, and exposed services before or during an operation so they can choose targets and shape later actions.
- TA0042 — Resource Development: Adversaries establish infrastructure, accounts, capabilities, and operational resources that support access, command and control, evasion, or influence.
- TA0001 — Initial Access: Adversaries obtain the first foothold through people, internet-facing services, remote access, trusted relationships, removable media, or other entry paths.
- TA0002 — Execution: Adversaries run commands, scripts, code, interpreters, APIs, or user-driven content to carry out malicious actions in an environment.
- TA0003 — Persistence: Adversaries preserve access through accounts, services, scheduled mechanisms, startup locations, application components, cloud resources, or configuration changes.
- TA0004 — Privilege Escalation: Adversaries gain permissions beyond their current access by exploiting weaknesses, abusing tokens, changing controls, or misusing elevation mechanisms.
- TA0005 — Stealth: Adversaries conceal their presence, blend with expected activity, alter indicators, disguise artifacts, or make analysis more difficult.
- TA0112 — Defense Impairment: Adversaries weaken, disable, reconfigure, or bypass security controls so later activity is less likely to be blocked or observed.
- TA0006 — Credential Access: Adversaries obtain passwords, hashes, tokens, tickets, keys, cookies, or other secrets that can be used to authenticate or impersonate an identity.
- TA0007 — Discovery: Adversaries query systems, networks, identities, applications, policies, and cloud resources to understand the environment and select follow-on actions.
- TA0008 — Lateral Movement: Adversaries move from one account, system, workload, or trust zone to another using remote services, credentials, exploits, or transferred tools.
- TA0009 — Collection: Adversaries gather, stage, capture, or aggregate information of interest before using or removing it.
- TA0011 — Command and Control: Adversaries communicate with compromised resources to issue instructions, receive results, transfer tools, or maintain operational control.
- TA0010 — Exfiltration: Adversaries transfer collected information outside an authorized boundary through command channels, web services, cloud storage, physical media, or alternate paths.
- TA0040 — Impact: Adversaries disrupt availability, destroy or manipulate information, impair recovery, consume resources, or otherwise affect mission and business operations.
How to use the learning center
Begin with the Foundations path if ATT&CK is new to you. Then choose a tactic path to study adversary objectives, a platform path to focus on your technology, or the detection and mitigation paths to connect behaviors to defensive work.
Each technique profile separates the framework mapping from the BMC explanation. The profile states the identifier, tactic, platform scope, catalog version, and official link, then explains operational behavior, evidence, controls, investigation, and a safe exercise.
Existing Wiki articles are reused rather than duplicated whenever they already teach the underlying concept. Their ATT&CK panel labels the mapping role—such as direct behavior coverage, defensive context, detection context, or mitigation context—so readers do not confuse related material with an exact equivalence.
What coverage means here
A BMC course receives an ATT&CK mapping only through an exact relationship between a mapped Wiki article and an Academy lesson. Coverage counts therefore describe educational connections, not proof that a course teaches every procedure, platform, detection, or mitigation associated with the technique.
The curriculum-gap report intentionally retains techniques with no exact linked lesson. Those gaps identify the next lessons, labs, books, podcast episodes, and Magazine features needed to round out the educational program.
- Direct behavior coverage: the article teaches the technique or sub-technique itself.
- Defensive or mitigation context: the article teaches a control that constrains the behavior.
- Detection or evidence context: the article explains telemetry, analytics, or investigation relevant to the behavior.
- Architecture or risk context: the article explains the environment, trust relationship, or consequence that gives the behavior meaning.
- Curriculum gap: no sufficiently exact Academy relationship has been established.
Maintaining current ATT&CK data
The source package includes an importer and comparison tool for the official STIX 2.1 Enterprise collection. It can download a selected release, normalize supported object types, compare them with a previous snapshot, and report added, changed, deprecated, and revoked objects.
Automated updates never replace BMC prose. They update or propose changes to framework metadata, while meaningful changes enter an editorial review queue. This separation preserves local explanations and relationships while still allowing repeatable synchronization with the evolving knowledge base.
Safe use and attribution
© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.
Use the official ATT&CK site and cited underlying sources for operational attribution, current object status, and procedure evidence. Bare Metal Cyber articles summarize and teach; they do not replace current threat intelligence, legal review, or organization-specific testing.
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: