Case F7BDF8 · Malware & intel · L1 Foundations
MITRE ATT&CK tactics
Practise as: Explain it · Interview
Interview questionWhat is MITRE ATT&CK, and how is a tactic different from a technique?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- ATT&CK is a knowledge base of real-world adversary behavior, organized as tactics (why) and techniques (how)
- Enterprise has 15 tactics since v19 (2026) split Defense Evasion into Stealth and Defense Impairment
- Techniques have IDs like T1059; sub-techniques add detail, e.g. T1059.001 is PowerShell
- Used to map detection coverage, emulate adversaries in purple teams, and describe threat groups
- It is not a strict kill chain: tactics can repeat or happen out of order during an intrusion
If the interviewer pushes back
- How would you use ATT&CK to prioritize which detections to build next?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.