Skip to main content
Skip to technique list

MITRE ATT&CK® Techniques

MITRE ATT&CK Detection Training

Master detection for 85+ MITRE ATT&CK® techniques across all major tactics. Each technique includes real detection strategies, example alerts from SIEM, XDR, and Firewall tools, and links to hands-on training in SOCSimulator Operations.

0+Techniques
0Tactics
0+Detection Tips
0+Example Alerts

What is MITRE ATT&CK®?

MITRE ATT&CK® Framework
MITRE ATT&CK® (Adversarial Tactics, Techniques, and Common Knowledge) is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. SOC analysts use the framework to classify threats, build detection rules, assess security coverage, and communicate about attack behavior in a common language.

Each technique describes a specific method adversaries use to achieve their goals: from gaining initial access to exfiltrating data and causing impact. SOCSimulator maps its training operations and shift mode scenarios directly to MITRE ATT&CK® techniques, so every alert you investigate teaches you something real. Start free.

ATT&CK is used by defenders, threat intelligence teams, and red teamers worldwide to improve their understanding of adversary behavior and strengthen organizational security posture.

80%+
Global adoption by SOC teams
SANS Institute (2024)
600+
Techniques documented
MITRE Corporation (2024)
10,000+
Organizations referencing ATT&CK
MITRE ATT&CK® (2024)

Initial Access

7 techniques

Execution

7 techniques

Persistence

8 techniques

Privilege Escalation

4 techniques

Defense Evasion

8 techniques

Credential Access

10 techniques
T1110easy

Brute Force

Brute Force covers any guess-driven path to credentials: classic password guessing, password spraying a few common passw...

SIEMFirewall
T1003hard

OS Credential Dumping

Credential dumping harvests hashes or plaintext secrets from where the OS stores them: LSASS memory, the SAM hive, cache...

XDRSIEM
T1558hard

Steal or Forge Kerberos Tickets

This technique subverts Kerberos by stealing tickets from memory or forging them from domain secrets, enabling Pass-the-...

SIEMXDR
T1555medium

Credentials from Password Stores

This technique loots the places that deliberately concentrate secrets, browser-saved passwords, the Windows Credential M...

XDRSIEM
T1552easy

Unsecured Credentials

Unsecured Credentials is the adversary harvesting secrets that were left in the clear, in configuration files, source co...

XDRSIEM
T1556hard

Modify Authentication Process

Modify Authentication Process tampers with the components that verify identity, LSASS and authentication packages on Win...

SIEMXDR
T1621medium

Multi-Factor Authentication Request Generation

Multi-Factor Authentication Request Generation (T1621) is what an attacker does with an already-stolen password: instead...

SIEM
T1557hard

Adversary-in-the-Middle

Adversary-in-the-Middle (T1557) is when an attacker sits between two systems to intercept, relay, or steal session data,...

SIEMXDR
T1539medium

Steal Web Session Cookie

Steal Web Session Cookie (T1539) is credential access without credentials: an infostealer, a malicious browser extension...

SIEMXDR
T1528medium

Steal Application Access Token

Steal Application Access Token (T1528) is OAuth abuse: an attacker registers a rogue app in Entra ID, then phishes a use...

SIEM

Discovery

8 techniques

Lateral Movement

3 techniques

Collection

9 techniques

Command and Control

7 techniques

Exfiltration

4 techniques

Impact

6 techniques

Reconnaissance

2 techniques

Resource Development

2 techniques

FAQ

Frequently Asked Questions

Common questions about MITRE ATT&CK® detection training and SOCSimulator.

What is the MITRE ATT&CK® framework and why do SOC analysts need it?
MITRE ATT&CK® is a globally accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. SOC analysts use it to classify threats, build detection rules, measure security coverage gaps, and communicate about attack behavior in a standardized language that teams and vendors understand.
How does SOCSimulator teach MITRE ATT&CK® techniques?
SOCSimulator maps every training scenario and alert to specific MITRE ATT&CK® techniques. When you investigate alerts in Operations or Shift Mode, you practice detecting real techniques like T1566 Phishing or T1059 Command-Line Interface using realistic SIEM, XDR, and Firewall interfaces. Each technique page includes detection strategies, example alerts, and links to hands-on practice.
Do I need prior experience to start learning ATT&CK detection?
No. SOCSimulator is designed for analysts at all levels. Techniques are tagged by difficulty (easy, medium, hard) so beginners can start with foundational detection scenarios like phishing triage and progress to advanced techniques like lateral movement and defense evasion. The platform is free.
How many MITRE ATT&CK® techniques does SOCSimulator cover?
SOCSimulator currently covers 50+ MITRE ATT&CK® techniques across all 12 major tactics, from Initial Access through Impact. Each technique includes multiple detection strategies, realistic example alerts across SIEM, XDR, and Firewall tools, and hands-on training scenarios in Operations.
Can I use SOCSimulator to prepare for SOC analyst certifications?
Yes. SOCSimulator provides hands-on experience that complements certifications like CompTIA CySA+, GIAC GSOC, and BTL1. Practicing MITRE ATT&CK®-mapped detection scenarios builds the practical skills that certification exams test, including alert triage, threat investigation, and incident response decision-making.

Practice Detecting These Techniques

SOCSimulator puts you in the analyst seat with real alerts, real pressure, and zero consequences. Investigate MITRE ATT&CK®-mapped scenarios in our guided Operations or face a full shift in Shift Mode. Start free.

Free tier
Real IOCs & techniques