What category of knowledge base this is
MITRE ATT&CK is a knowledge base of adversarial techniques based on real-world observations. The Get Started page says it focuses on how adversaries interact with systems during an operation. Tactics are why an adversary performs an action. Techniques are how adversaries achieve those tactical goals. It is a language for behaviors and evidence. It is not a scoring system that proves defensive coverage.
Who it commonly frames: detection engineers and SOC learners who tag a case once evidence exists, threat intelligence readers who need a shared behavior name, and AppSec readers who meet technique names on vendor slides. Foundations readers may have seen ATT&CK only as a name on the six-map comparison. This is an industry knowledge base. It is not a U.S. statute, and it is not a certification scheme.
What security people most often confuse: they fold a green matrix cell, a compliance badge, a finished CSF profile, a product that "has ATT&CK," and an Atlas lesson into one seal. This page keeps those objects apart. The Reference card at /reference/frameworks/mitre-attack-v19-2/ remains the framework summary. This explainer complements that card. It does not replace it, and it does not list tactics or techniques.
Edition pin
The edition string to teach is ATT&CK v19.2. The August 2026 updates page marks ATT&CK v19 as the current version of ATT&CK, with a start date of 2026-08-06 (6 August 2026), and points the data at v19.2 on MITRE/CTI (release tag ATT&CK-v19.2). That page calls v19.2 the first Agile release, and says this release updates Groups and Software for Enterprise. The versions page lists ATT&CK v19.2 as the current version. The Atlas Reference edition string is ATT&CK v19.2. If a newer version appears, update this pin and treat the older claim as UNKNOWN.
Literacy note, slogan only: major v19, on the April 2026 updates page, has a start date of 2026-04-28. That release split the former Defense Evasion tactic into Stealth and Defense Impairment. Do not reuse older tactic counts as if they were current. This page does not list tactics, techniques, or sub-techniques, and it does not reprint a matrix.
Name a behavior only when evidence supports it
Pick one real or synthetic case. Map only techniques supported by evidence. Leave the rest unmarked. Ask what telemetry would show this technique, rather than what share of a matrix looks green.
Riverstone can tag the Jordan Hale case with relevant techniques once evidence exists, without coloring a matrix cell and declaring victory. The triage note on /learn/topics/identity-alert-triage/ and the investigation timeline on /learn/topics/investigate-respond-verify/ stay that evidence habit. This page does not rewrite those lessons into an ATT&CK course. The Agentic SOC lesson (/learn/topics/agentic-soc/) already records a coverage limit when a connector is missing. That sentence is about missing evidence. It is not an ATT&CK coverage score.
MITRE's Get Started page says not to treat a checklist as done, not to try to achieve complete coverage, and not to color a box green because one way of performing a technique was seen. Adversaries have more than one way to perform most techniques. Not every tactic or technique applies to every organization. Do not invent a coverage percentage for a board.
A matrix cell is a label
A matrix cell is a label for a behavior class. Painting it green does not mean a TrackPort export would be caught. One detection does not paint a technique green forever. The same Get Started page says the matrix documents observed real-world behaviors, and that adversaries may use behaviors the matrix does not document yet.
ATT&CK Navigator can visualize defensive coverage, planning, and detected techniques. A heatmap is not the lesson on this page, and paint is not evidence. This page does not ship a second matrix, and it does not assign colors. It is not a Navigator heatmap tutorial.
What this card is not
Not a tactic or technique encyclopedia. Not a Navigator heatmap tutorial as the lesson core. Not a replacement for the Reference framework card at /reference/frameworks/mitre-attack-v19-2/. Not red-team exploit homework. Not proof that attackers will skip you. Not a SOC playbook dump. Not an Atlas attestation of coverage.
Not a CSF 2.0 profile. CSF 2.0 is outcomes and function language. ATT&CK is adversary-behavior description. Related maps may exist. Do not collapse them. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. The six-map comparison is /reference/frameworks/compare/. The ATT&CK row there says the purpose is to describe adversary behaviors, that the map is not certifiable, and that a typical misuse is treating a coverage percentage as a compliance score. A row is not this page, and a row is not a heatmap.
Rewrite the one-line claim
Replace "we are ATT&CK, covered, CSF, and product-badge secure" with a reading sentence. We use ATT&CK v19.2 as a behavior-naming and evidence-hunting knowledge base. That is different from CSF 2.0 outcomes, from a compliance attestation, and from product marketing that says a tool has ATT&CK.
When a slide shows a green heatmap, privately ask which behaviors have evidence and which telemetry would show them, before treating paint as coverage. Do not paste proprietary detection logic, or customer data, into Atlas.
A matrix cell is not coverage, not compliance, not a CSF profile, not a product badge, and not an Atlas seal
Teaching table only. It does not assign coverage, a certificate, a CSF profile, a product finding, or a detection seal. It does not invent a coverage percentage.
| Phrase people say | Literacy correction |
|---|---|
| This matrix cell is green, so we have coverage | A cell is a behavior label. Green paint is not proof the relevant telemetry and analytic would catch the next case. Reference card: /reference/frameworks/mitre-attack-v19-2/. |
| We are ATT&CK compliant / certified | ATT&CK is not a compliance framework and not a certification scheme. The comparison row lists certifiable as No. Six-map comparison: /reference/frameworks/compare/. |
| ATT&CK done means CSF profile done | CSF 2.0 is outcomes and function language. ATT&CK is adversary-behavior description. Related maps may exist. Do not collapse them. Atlas card: /reference/frameworks/nist-csf-2-0/. Lesson: /learn/topics/outcomes-then-controls/. |
| The product has ATT&CK, so we are safe | A vendor badge that says the product has ATT&CK is not evidence your detections work on your telemetry. Reference card: /reference/frameworks/mitre-attack-v19-2/. |
| Atlas ATT&CK lesson = detection seal / coverage percentage done | Atlas does not issue detection seals or coverage scores. Completing a lesson is not covered. |
| We should invent a coverage percentage for the board | Do not invent a coverage percentage. Map evidence-backed techniques, and leave gaps visible. SOC evidence habit: /learn/topics/identity-alert-triage/ and /learn/topics/investigate-respond-verify/. |
Claims to retire
A green matrix cell means detection coverage, so the organization is safe.
A cell is a behavior label. Green paint is not proof the relevant telemetry and analytic would catch the next case. One detection does not close a technique forever.
ATT&CK is a compliance framework, and finishing it is a certificate.
ATT&CK is an adversary behavior knowledge base. The six-map comparison lists it as not certifiable. It is not a compliance framework.
ATT&CK done, a CSF profile done, and a product badge are the same seal.
They are different objects. ATT&CK names adversary behaviors. CSF 2.0 is outcomes language. A vendor badge is marketing. A mapping does not finish the others.
This page replaces the Reference ATT&CK framework card.
The card at /reference/frameworks/mitre-attack-v19-2/ stays the framework summary. This page is literacy beside that card.
Atlas, or a vendor homepage shield, attests ATT&CK coverage.
Atlas does not issue detection seals or coverage scores. Completing this lesson is not covered. A homepage shield is not evidence your detections work on your telemetry.
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- MITRE ATT&CK Reference card (framework summary, not replaced by this page)
- Compare the six maps (a row is not a heatmap)
- Triage a synthetic identity alert (S1, evidence habit)
- Investigate, respond, and verify recovery (S3)
- Understand and build toward an Agentic SOC (S4)
- Outcomes first, then controls (F8a)
- NIST CSF 2.0 framework card (outcomes, not a behavior matrix)
- SOC analyst practice path
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.