1200km / attack & detection modules

Interactive ATT&CK
& ATLAS matrix

From an adversary technique to its local workspace. Explore tactics, open TTP pages, and follow the connected simulation, detection and telemetry evidence.

918 ATT&CK entries208 ATLAS entries4 frameworks / domainsEvery technique is linked

Explore the matrix

Enterprise, Mobile and ICS are ATT&CK domains. ATLAS is a separate AI-security framework. IoT/OT and cloud are explicitly labelled 1200km navigation views.

The complete static matrices below work without JavaScript. Interactive filters load when available.

Scroll within each matrix to explore tactics, or choose the wrapped layout. Use each parent’s disclosure control to show its sub-techniques. Counts are unique techniques plus sub-techniques, not the number of tactic cells.

MITRE ATT&CK Enterprise 19.2 · 697 unique techniques and sub-techniques

Reconnaissance46 matching entries

Resource Development50 matching entries

2 sub-techniques

Initial Access22 matching entries

Execution64 matching entries

T1197BITS Jobs
Documented candidateDetection ↗
T1106Native API
Documented candidateDetection ↗
3 sub-techniques

Persistence113 matching entries

T1197BITS Jobs
Documented candidateDetection ↗
3 sub-techniques
T1542Pre-OS Boot
No catalog candidateDetection ↗
5 sub-techniques
2 sub-techniques
2 sub-techniques

Privilege Escalation96 matching entries

Stealth148 matching entries

T1197BITS Jobs
Documented candidateDetection ↗
T1542Pre-OS Boot
No catalog candidateDetection ↗
5 sub-techniques
T1014Rootkit
Documented candidateDetection ↗
2 sub-techniques
2 sub-techniques

Defense Impairment56 matching entries

Credential Access67 matching entries

2 sub-techniques

Discovery49 matching entries

Lateral Movement23 matching entries

Collection41 matching entries

T1074Data Staged
No catalog candidateDetection ↗
2 sub-techniques

Command and Control45 matching entries

2 sub-techniques
T1090Proxy
No catalog candidateDetection ↗
4 sub-techniques
2 sub-techniques

Exfiltration19 matching entries

1 sub-technique

Impact33 matching entries

T1491Defacement
No catalog candidateDetection ↗
2 sub-techniques
T1561Disk Wipe
No catalog candidateDetection ↗
2 sub-techniques
T1489Service Stop
Documented candidateDetection ↗

MITRE ATT&CK Mobile 19.2 · 124 unique techniques and sub-techniques

Initial Access11 matching entries

T1660Phishing
No catalog candidateDetection ↗

Execution5 matching entries

T1575Native API
No catalog candidateDetection ↗

Persistence10 matching entries

Privilege Escalation5 matching entries

1 sub-technique

Defense Evasion33 matching entries

1 sub-technique
T1617Hooking
No catalog candidateDetection ↗
T1575Native API
No catalog candidateDetection ↗
1 sub-technique

Credential Access10 matching entries

1 sub-technique
T1634.001Keychain
No catalog candidateDetection ↗
2 sub-techniques

Discovery13 matching entries

Lateral Movement2 matching entries

Collection24 matching entries

T1616Call Control
No catalog candidateDetection ↗
2 sub-techniques
5 sub-techniques

Command and Control17 matching entries

1 sub-technique
T1616Call Control
No catalog candidateDetection ↗

Exfiltration3 matching entries

Impact11 matching entries

T1616Call Control
No catalog candidateDetection ↗
T1582SMS Control
No catalog candidateDetection ↗

MITRE ATT&CK ICS 19.2 · 97 unique techniques and sub-techniques

Initial Access12 matching entries

T0848Rogue Master
No catalog candidateDetection ↗

Execution10 matching entries

T0874Hooking
No catalog candidateDetection ↗
T0834Native API
No catalog candidateDetection ↗
T0853Scripting
No catalog candidateDetection ↗

Persistence10 matching entries

2 sub-techniques

Privilege Escalation2 matching entries

T0874Hooking
No catalog candidateDetection ↗

Evasion9 matching entries

T0849Masquerading
No catalog candidateDetection ↗
T0851Rootkit
No catalog candidateDetection ↗
2 sub-techniques

Discovery8 matching entries

Lateral Movement11 matching entries

3 sub-techniques

Collection11 matching entries

T0877I/O Image
No catalog candidateDetection ↗

Command and Control3 matching entries

Inhibit Response Function20 matching entries

3 sub-techniques
T1695.002Ethernet
No catalog candidateDetection ↗
T1695.003Wi-Fi
No catalog candidateDetection ↗
2 sub-techniques
T0851Rootkit
No catalog candidateDetection ↗
T0881Service Stop
No catalog candidateDetection ↗

Impair Process Control8 matching entries

2 sub-techniques
2 sub-techniques

Impact12 matching entries

T0829Loss of View
No catalog candidateDetection ↗

MITRE ATLAS 2026.09 · 208 unique techniques and sub-techniques

Reconnaissance18 matching entries

Resource Development29 matching entries

AI Attack Adaptation25 matching entries

Initial Access18 matching entries

AI Model Access4 matching entries

Execution13 matching entries

3 sub-techniques

Persistence20 matching entries

2 sub-techniques

Privilege Escalation4 matching entries

Defense Evasion19 matching entries

Credential Access7 matching entries

Discovery17 matching entries

Lateral Movement9 matching entries

Collection8 matching entries

Command and Control5 matching entries

AML.T0108AI Agent
Not assessed

Exfiltration9 matching entries

Impact20 matching entries

Evidence, scope and source versions

ATT&CK 19.2 · ATLAS 2026.09 (data format 6.0.0) · imported 2026-09-28. Sources are pinned, not a live feed.

Pinned enterprise STIX · Pinned mobile STIX · Pinned ics STIX · Pinned ATLAS YAML · Versions and SHA-256 hashes · Simulation catalog provenance

MITRE Enterprise · MITRE Mobile · MITRE ICS · MITRE ATLAS · ATLAS attribution · Apache 2.0 license

ATT&CK is a registered trademark and ATLAS is a trademark of The MITRE Corporation. This independently built 1200km navigation module does not imply MITRE endorsement.