Open cardosec

Case F7BDF8 · Malware & intel · L1 Foundations

MITRE ATT&CK tactics

Practise as: Explain it · Interview

Interview questionWhat is MITRE ATT&CK, and how is a tactic different from a technique?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. ATT&CK is a knowledge base of real-world adversary behavior, organized as tactics (why) and techniques (how)
  2. Enterprise has 15 tactics since v19 (2026) split Defense Evasion into Stealth and Defense Impairment
  3. Techniques have IDs like T1059; sub-techniques add detail, e.g. T1059.001 is PowerShell
  4. Used to map detection coverage, emulate adversaries in purple teams, and describe threat groups
  5. It is not a strict kill chain: tactics can repeat or happen out of order during an intrusion

If the interviewer pushes back

  • How would you use ATT&CK to prioritize which detections to build next?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.