Introducing the Interactive MITRE ATT&CK Matrix: Every Tactic and Technique, Clickable and Explained

Chris Rees
25+ years in IT · Pluralsight author, 4.6/5 across 2,000+ ratings

Every serious security exam now assumes you can read an intrusion as a sequence of adversary behaviors, and the vocabulary they use for that is MITRE ATT&CK. The trouble is that attack.mitre.org was built as a reference, not a teacher: a wall of 222 cells, each one a page of dense prose. So we built the version we wished existed when we were studying. The interactive ATT&CK matrix is live today, and it is free.
Why a framework page, on a study guide site
ATT&CK is the shared language of attacker behavior. CySA+ objective 3.1 names it outright and expects you to place a technique in its tactic on sight. Security+ Domain 2 is, in practice, the left half of the matrix: threat vectors, indicators, and mitigations. CISSP uses it as the vocabulary for security operations and threat modeling. SecAI+ leans on MITRE ATLAS, which is ATT&CK rebuilt for AI systems and reads itself once you know the original.
That is four exams and one framework. Learning it well once pays out everywhere, and learning it as a list of 222 names is the wrong way. ATT&CK is a way of reading behavior, and the exam questions test the reading, not the memorization: here is what happened, which stage of the intrusion is it, what control would have stopped it. The page is built around that skill.
What is on the page
The whole matrix, clickable. All 15 tactics as columns, all 222 techniques as cells, all 475 sub-techniques a toggle away. Search by name or ID (type "token" and the four techniques that mention tokens light up, with the matching sub-techniques expanded inline), or filter by platform to see only what applies to Windows, or SaaS, or containers.
A detail panel that teaches. Click any cell and you get MITRE's description, the platforms, the sub-techniques, the mitigations, the detection strategies, and which real groups and malware families use the technique. Then two panels that are ours: what a defender sees, in one paragraph, and on the exam, mapped to the specific objectives in CySA+, Security+ and CISSP where that tactic shows up. Click a column header and you get the same treatment for the tactic itself, starting with the one-line question every tactic answers.
Three attack stories. This is the part we are proudest of. Pick an intrusion, and the page walks it step by step across the matrix, lighting up each technique as it goes:
The three stories are a human-operated ransomware intrusion (the full left-to-right run, twelve steps), a cloud account takeover that never drops a file (nine steps, and nearly nothing for an endpoint tool to see), and a software supply chain compromise where the attack arrives as a signed update (eight steps). Each step gives you both sides: what the attacker did, and what a defender could have seen. That pairing is the shape of almost every scenario question on CySA+ and Security+, and it is the habit the stories are meant to build.
A tactic drill. Eight questions, generated fresh from the live matrix each time: here is what an adversary did, with the tactic words blanked out and no technique name until you answer, so which stage of the intrusion is it? It sounds simple, and the first run usually is not, because the misses are always the neighbors: discovery versus collection, persistence versus privilege escalation, stealth versus defense impairment. The feedback names the tactic and the one-line question it answers, and offers to open the technique in the matrix.
The vocabulary. Tactic, technique, sub-technique, procedure, mitigation, detection strategy, group, software. Eight words, and exam questions regularly turn on the difference between two of them. Procedure versus technique is the one that separates a pass from a strong pass.
How we suggest using it
The page rewards a particular order, and it is not the obvious one.
- Read the fifteen questions first. Click each column header and read the one-line question the tactic answers. "How does the attacker survive a reboot?" is persistence. "How does the attacker learn the layout?" is discovery. Fifteen questions are easier to hold than fifteen names, and they are what you actually apply in a scenario.
- Walk one story with auto-play on. Let the ransomware story run. Watch where the path goes and, more usefully, where it does not: no reconnaissance step, because the phishing email was the first thing anyone saw, and a jump back to the left when the attacker switches the security tools off. That is the point the exams make about ATT&CK not being a strict sequence.
- Drill until the neighbors stop tripping you. Then take the CySA+ readiness quiz, which tests the framework the way the real exam does, inside a scenario.
What is inside a cell
Where the data comes from
The matrix is generated from MITRE's official STIX data for Enterprise ATT&CK, currently version 19.2, and rebuilt from the source whenever MITRE publishes an update. The descriptions are abridged to the opening paragraphs; the full entries are one click away on attack.mitre.org, and every panel links there. The tactic explanations, the defender's view, the exam mapping, the attack stories and the drill are ours. ATT&CK is a trademark of The MITRE Corporation, and the content is reproduced with attribution under their terms of use; the page says so at the bottom, and we are not affiliated with MITRE.
Send it to someone
Every state of the page is a link. Open a technique and the address bar updates, so a link to /mitre-attack?t=T1566.001 opens straight to Spearphishing Attachment, and ?tactic=credential-access opens the tactic. If you teach, run a study group, or are just trying to explain to a colleague what "T1003" in an incident report means, that is the fastest way we know to do it.
Key takeaways
- The whole Enterprise matrix, clickable and free. 15 tactics, 222 techniques, 475 sub-techniques, searchable by name, ID and platform.
- Every technique comes with what a defender sees and where it is on the exam. MITRE's data on one side, the teaching layer on the other.
- Three attack stories walk the matrix left to right. Ransomware, cloud account takeover, supply chain, with the attacker's move and the defender's view at every step.
- Learn the fifteen questions, not the fifteen names. Then drill until the neighboring tactics stop tripping you.
- Defense Evasion is now two columns. Stealth and Defense Impairment in ATT&CK v19; the exams still say Defense Evasion.
Attack frameworks are objective 3.1 of CySA+ Domain 3, Incident Response and Management, 24% of the exam, and they appear again in Security+ Domain 2 and CISSP Domain 7. Explore the interactive ATT&CK matrix first, then work the frameworks the way the exam asks them with our CySA+ Domain 3 study guide.
#MITREATTACK #ATTACK #ThreatInformedDefense #CySAplus #CS0004 #SecurityPlus #SY0701 #CISSP #InfoSec #CyberSecurity
Keep reading
Security+ SY0-701 vs SY0-801: Every Change in the Draft Objectives, and Which Exam to Take
CompTIA's draft SY0-801 objectives are out, the exam is expected to open this autumn, and SY0-701 retires on June 11, 2027. Built from the two objectives documents themselves: the weight shifts, the new AI objective, what moved between domains, what was dropped, and a decision rule for which exam to book.
Read Exam prepHow Long Does It Take to Study for CompTIA SecAI+?
A realistic timeline for preparing for the CompTIA SecAI+ exam, based on your starting point, study pace, and how you study.
Read Exam prepIs CompTIA SecAI+ Worth It? Who Should Get the AI Security Certification
Wondering whether CompTIA SecAI+ is worth your time and money? An honest look at who benefits, what it proves, and the right time to take it.
ReadEnjoyed this? Get the AI security news that matters.
Join The AI Security Brief for the top AI security news, plus what's important to the C-suite. Free, straight to your inbox.
No spam. Unsubscribe anytime.
Know the attack before you answer it
Incident Response and Management is a quarter of CySA+ CS0-004. Work all 20 topics across three objectives, from the Kill Chain, Diamond Model and ATT&CK through the response process and the techniques of containment, eradication and recovery, with 60 practice questions.
Get the CySA+ Domain 3 guide