Skip to content

Tactic

Definition

The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK defines 14 tactics for enterprise environments. A tactic answers the question 'why is the attacker doing this?'

Field
Cyber threat intelligence, MITRE ATT&CK
Definition
Adversary's high-level objective at a stage of attack
ATT&CK count
14 enterprise tactics
Question answered
Why is the attacker doing this?

Common questions

How does a tactic relate to a technique in the ATT&CK model?+

A tactic is the goal, such as Persistence, while a technique is one specific way of achieving that goal, such as creating a scheduled task. Several different techniques can all serve the same tactic, which is why ATT&CK groups techniques under their parent tactics.

Why do defenders map incidents to tactics rather than just listing the tools used?+

Tools change constantly, but an attacker's objectives at each stage stay consistent across campaigns. Mapping to tactics lets analysts compare incidents and build detections around adversary intent rather than chasing a moving list of malware names.

Related terms

Technique
A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...
ATT&CK Navigator
A free, browser-based visualisation tool from MITRE that renders the ATT&CK matrix as an interactive heat map. Teams use it to annotate...
Credential Dumping
Extraction of authentication credentials from operating system memory, the Windows SAM database, Active Directory, or credential stores. Tools such as Mimikatz target...
Lateral Movement
Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
Living-Off-the-Land (LotL)
An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
Sub-Technique
A finer-grained variation of a technique, identified with a decimal suffix such as T1059.001 for PowerShell under the Command and Scripting Interpreter...
Threat Group Profile
An ATT&CK entry for a named threat actor, listing the techniques attributed to that group based on public reporting. Analysts use group...
TTP (Tactics, Techniques, and Procedures)
The three levels of specificity used to describe attacker behaviour. Tactics are the goal (e.g., persistence). Techniques are the method (e.g., scheduled...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.