Skip to content
All articles
September 7, 2026 8 min read

Introducing the Interactive MITRE ATT&CK Matrix: Every Tactic and Technique, Clickable and Explained

Chris Rees

Chris Rees

25+ years in IT · Pluralsight author, 4.6/5 across 2,000+ ratings

Introducing the Interactive MITRE ATT&CK Matrix: Every Tactic and Technique, Clickable and Explained

Every serious security exam now assumes you can read an intrusion as a sequence of adversary behaviors, and the vocabulary they use for that is MITRE ATT&CK. The trouble is that attack.mitre.org was built as a reference, not a teacher: a wall of 222 cells, each one a page of dense prose. So we built the version we wished existed when we were studying. The interactive ATT&CK matrix is live today, and it is free.

Why a framework page, on a study guide site

ATT&CK is the shared language of attacker behavior. CySA+ objective 3.1 names it outright and expects you to place a technique in its tactic on sight. Security+ Domain 2 is, in practice, the left half of the matrix: threat vectors, indicators, and mitigations. CISSP uses it as the vocabulary for security operations and threat modeling. SecAI+ leans on MITRE ATLAS, which is ATT&CK rebuilt for AI systems and reads itself once you know the original.

That is four exams and one framework. Learning it well once pays out everywhere, and learning it as a list of 222 names is the wrong way. ATT&CK is a way of reading behavior, and the exam questions test the reading, not the memorization: here is what happened, which stage of the intrusion is it, what control would have stopped it. The page is built around that skill.

What is on the page

The whole matrix, clickable. All 15 tactics as columns, all 222 techniques as cells, all 475 sub-techniques a toggle away. Search by name or ID (type "token" and the four techniques that mention tokens light up, with the matching sub-techniques expanded inline), or filter by platform to see only what applies to Windows, or SaaS, or containers.

A detail panel that teaches. Click any cell and you get MITRE's description, the platforms, the sub-techniques, the mitigations, the detection strategies, and which real groups and malware families use the technique. Then two panels that are ours: what a defender sees, in one paragraph, and on the exam, mapped to the specific objectives in CySA+, Security+ and CISSP where that tactic shows up. Click a column header and you get the same treatment for the tactic itself, starting with the one-line question every tactic answers.

Three attack stories. This is the part we are proudest of. Pick an intrusion, and the page walks it step by step across the matrix, lighting up each technique as it goes:

A simplified ATT&CK matrix of fifteen tactic columns from reconnaissance to impact, with the twelve steps of a human-operated ransomware intrusion marked as numbered cells that trace a path from initial access on the left to impact on the right ONE STORY, LEFT TO RIGHT ACROSS THE MATRIX Recon12 Resource9 Initial11 Execution20 Persist22 Priv Esc13 Stealth30 Impair18 Cred17 Discovery34 Lateral9 Collect17 C218 Exfil9 Impact15 1 2 3 4 5 6 7 8 9 10 11 12 1 to 4phishing attachment, user opens it, PowerShell, run key 5 to 7LSASS dump, domain mapped, admin shares 8 to 10security tools off, data archived, uploaded 11 to 12backups destroyed, then encryption Step 8 sits to the left of steps 5 to 7. The matrix is a vocabulary, not a timeline, and attackers loop back. Every numbered cell before 12 was a chance to see it coming. That is the exam's favorite question.
The human-operated ransomware story, as the page draws it. Twelve steps, eleven of them before anything is encrypted.

The three stories are a human-operated ransomware intrusion (the full left-to-right run, twelve steps), a cloud account takeover that never drops a file (nine steps, and nearly nothing for an endpoint tool to see), and a software supply chain compromise where the attack arrives as a signed update (eight steps). Each step gives you both sides: what the attacker did, and what a defender could have seen. That pairing is the shape of almost every scenario question on CySA+ and Security+, and it is the habit the stories are meant to build.

A tactic drill. Eight questions, generated fresh from the live matrix each time: here is what an adversary did, with the tactic words blanked out and no technique name until you answer, so which stage of the intrusion is it? It sounds simple, and the first run usually is not, because the misses are always the neighbors: discovery versus collection, persistence versus privilege escalation, stealth versus defense impairment. The feedback names the tactic and the one-line question it answers, and offers to open the technique in the matrix.

The vocabulary. Tactic, technique, sub-technique, procedure, mitigation, detection strategy, group, software. Eight words, and exam questions regularly turn on the difference between two of them. Procedure versus technique is the one that separates a pass from a strong pass.

How we suggest using it

The page rewards a particular order, and it is not the obvious one.

  1. Read the fifteen questions first. Click each column header and read the one-line question the tactic answers. "How does the attacker survive a reboot?" is persistence. "How does the attacker learn the layout?" is discovery. Fifteen questions are easier to hold than fifteen names, and they are what you actually apply in a scenario.
  2. Walk one story with auto-play on. Let the ransomware story run. Watch where the path goes and, more usefully, where it does not: no reconnaissance step, because the phishing email was the first thing anyone saw, and a jump back to the left when the attacker switches the security tools off. That is the point the exams make about ATT&CK not being a strict sequence.
  3. Drill until the neighbors stop tripping you. Then take the CySA+ readiness quiz, which tests the framework the way the real exam does, inside a scenario.
A naming change to know about: the current ATT&CK data (Enterprise v19) splits what older versions called Defense Evasion into two tactics, Stealth and Defense Impairment. The exam objectives were written against the older name. If a question says "defense evasion," it means the techniques now spread across those two columns, and the page's tactic panels say so.

What is inside a cell

The anatomy of the technique detail panel: MITRE's data on the left, including description, platforms, sub-techniques, mitigations, detection strategies and groups, and Skillthropic's additions on the right, what a defender sees and where the tactic appears on each exam, with deep link and source link at the bottom WHAT OPENS WHEN YOU CLICK A TECHNIQUE FROM MITRE, ABRIDGED Description, platforms, version Sub-techniques, each one clickable Mitigations: the M-numbers that reduce it Detection strategies: what to monitor Groups and software observed using it Link to the full entry on attack.mitre.org ADDED BY SKILLTHROPIC What a defender sees The log lines, alerts and anomalies that give this tactic away, in one paragraph. On the exam CySA+, Security+ and CISSP objectives where this tactic is tested, by number, so you can go straight to the guide section. A shareable link Every technique, sub-technique and tactic has its own URL. Same panel for a tactic, with the plain-English question it answers and every technique in the column.
MITRE's data on the left, the teaching layer on the right. The two are kept visibly separate so you always know which is which.

Where the data comes from

The matrix is generated from MITRE's official STIX data for Enterprise ATT&CK, currently version 19.2, and rebuilt from the source whenever MITRE publishes an update. The descriptions are abridged to the opening paragraphs; the full entries are one click away on attack.mitre.org, and every panel links there. The tactic explanations, the defender's view, the exam mapping, the attack stories and the drill are ours. ATT&CK is a trademark of The MITRE Corporation, and the content is reproduced with attribution under their terms of use; the page says so at the bottom, and we are not affiliated with MITRE.

Send it to someone

Every state of the page is a link. Open a technique and the address bar updates, so a link to /mitre-attack?t=T1566.001 opens straight to Spearphishing Attachment, and ?tactic=credential-access opens the tactic. If you teach, run a study group, or are just trying to explain to a colleague what "T1003" in an incident report means, that is the fastest way we know to do it.

Key takeaways

  • The whole Enterprise matrix, clickable and free. 15 tactics, 222 techniques, 475 sub-techniques, searchable by name, ID and platform.
  • Every technique comes with what a defender sees and where it is on the exam. MITRE's data on one side, the teaching layer on the other.
  • Three attack stories walk the matrix left to right. Ransomware, cloud account takeover, supply chain, with the attacker's move and the defender's view at every step.
  • Learn the fifteen questions, not the fifteen names. Then drill until the neighboring tactics stop tripping you.
  • Defense Evasion is now two columns. Stealth and Defense Impairment in ATT&CK v19; the exams still say Defense Evasion.

Attack frameworks are objective 3.1 of CySA+ Domain 3, Incident Response and Management, 24% of the exam, and they appear again in Security+ Domain 2 and CISSP Domain 7. Explore the interactive ATT&CK matrix first, then work the frameworks the way the exam asks them with our CySA+ Domain 3 study guide.

#MITREATTACK #ATTACK #ThreatInformedDefense #CySAplus #CS0004 #SecurityPlus #SY0701 #CISSP #InfoSec #CyberSecurity

Share this article

Keep reading

Enjoyed this? Get the AI security news that matters.

Join The AI Security Brief for the top AI security news, plus what's important to the C-suite. Free, straight to your inbox.

No spam. Unsubscribe anytime.

CySA+ Domain 3 · 24% of the exam

Know the attack before you answer it

Incident Response and Management is a quarter of CySA+ CS0-004. Work all 20 topics across three objectives, from the Kill Chain, Diamond Model and ATT&CK through the response process and the techniques of containment, eradication and recovery, with 60 practice questions.

Get the CySA+ Domain 3 guide