Tactic
Definition
The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK defines 14 tactics for enterprise environments. A tactic answers the question 'why is the attacker doing this?'
- Field
- Cyber threat intelligence, MITRE ATT&CK
- Definition
- Adversary's high-level objective at a stage of attack
- ATT&CK count
- 14 enterprise tactics
- Question answered
- Why is the attacker doing this?
Common questions
How does a tactic relate to a technique in the ATT&CK model?+
A tactic is the goal, such as Persistence, while a technique is one specific way of achieving that goal, such as creating a scheduled task. Several different techniques can all serve the same tactic, which is why ATT&CK groups techniques under their parent tactics.
Why do defenders map incidents to tactics rather than just listing the tools used?+
Tools change constantly, but an attacker's objectives at each stage stay consistent across campaigns. Mapping to tactics lets analysts compare incidents and build detections around adversary intent rather than chasing a moving list of malware names.
Related terms
- Technique
- A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...
- ATT&CK Navigator
- A free, browser-based visualisation tool from MITRE that renders the ATT&CK matrix as an interactive heat map. Teams use it to annotate...
- Credential Dumping
- Extraction of authentication credentials from operating system memory, the Windows SAM database, Active Directory, or credential stores. Tools such as Mimikatz target...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- Living-Off-the-Land (LotL)
- An attack approach where the adversary uses tools and binaries already present on the target system, such as PowerShell, WMI, certutil, or...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Sub-Technique
- A finer-grained variation of a technique, identified with a decimal suffix such as T1059.001 for PowerShell under the Command and Scripting Interpreter...
- Threat Group Profile
- An ATT&CK entry for a named threat actor, listing the techniques attributed to that group based on public reporting. Analysts use group...
- TTP (Tactics, Techniques, and Procedures)
- The three levels of specificity used to describe attacker behaviour. Tactics are the goal (e.g., persistence). Techniques are the method (e.g., scheduled...
Explained in these topics
- Common Attack Techniques and Tactics, Techniques and Procedures
- MITRE ATT&CK in Threat Hunting and Incident ResponseThe adversary's tactical goal at a given stage of an attack, represented as columns in the ATT&CK matrix. Examples include Persistence, Lateral Movement, and E...