StartToolsPatternsNotesAboutContact
THREAT INTEL · ATT&CK

MITRE ATT&CK Search

Search 35+ ATT&CK techniques by name, ID (T1566), or tactic. Shows description, mitigations, and tactic context.

Bundled from MITRE ATT&CK Enterprise. No network requests.

What this tool searches

Searches the MITRE ATT&CK framework — a structured knowledge base of adversary tactics, techniques, and procedures (TTPs) used in real-world attacks. Returns matching techniques with IDs, tactic categories, descriptions, and platform coverage.

ATT&CK is organized into tactics (the goal: Initial Access, Persistence, Privilege Escalation) and techniques (the method: Phishing, Valid Accounts, Token Impersonation). Sub-techniques provide additional specificity.

How ATT&CK is used in security work

ATT&CK provides a common language for describing attacker behavior across red team reports, threat intelligence, detection engineering, and security assessments. When a pentest finding says "T1078 Valid Accounts," it maps to a known technique with documented detections and mitigations.

Use this tool to research specific techniques when writing or reviewing security reports, to understand what detection rules might cover a given attacker behavior, or to look up the ATT&CK context behind a CVE or threat intelligence report.