The ATT&CK™ Framework
The ATT&CK™ Framework is a descriptive model used to label and study the activities that a threat actor is capable of carrying out in order to get foothold and operate inside an enterprise environment, a cloud environment, smartphones or even inside industrial control systems.
The magic behind the ATT&CK™ framework is that it provides a common taxonomy for the cyber security community to describe the adversary behavior. It works as a common language that both offensive and defensive researchers can use to better understand each other and to better communicate with people not specialized in the field.
And on top of that you not only can use it as you see fit, but you can also build on top of it, creating your own set of tactics, techniques an procedures (TTPs). Later on, you can shared them with the ATT&CK team following their guideline: https://attack.mitre.org/resources/contribute/
Now, let’s take a closer look to the...