skip to content

In MITRE ATT&CK, what does a T#### identifier name, and why does an observed command line have none?

level: juniorimportance: must knowfreq 65%

answer

  1. Numbering stops one level early
  2. Class versus one instance of it
  3. TA####, T####, T####.###
  4. Procedures live as attributed prose examples
  5. Values are unbounded, classes are not

basics

~20 s

A T#### identifier names a technique, a class of adversary behaviour, and T####.### a sub-technique of it. The exact command line you saw is a procedure: one implementation of that class, and ATT&CK gives procedures no identifier at all.

solid answer

~50 s

ATT&CK numbers three levels of behaviour and stops. A tactic carries a TA#### and names the adversary's goal; a technique carries a T#### and names a class of action, such as `T1059` Command and Scripting Interpreter; a sub-technique carries a decimal suffix, such as `T1059.004` Unix Shell, and narrows that class. Beneath it sits the procedure, which ATT&CK defines as the specific implementation an adversary used. Procedures appear on a technique page only as prose Procedure Examples, each attributed to a group (`G####`) or a piece of software (`S####`) with a citation, so the number in that row belongs to the actor or the software, never to the procedure. The reason is a difference in kind: a procedure is a matchable value, essentially unbounded in how it can be spelled, while a technique is a class defined by what the action cannot do without.

code

text · 7 lines
text
TA0002        Execution                            <- tactic, numbered
 T1059        Command and Scripting Interpreter    <- technique, numbered
  T1059.004   Unix Shell                           <- sub-technique, numbered
   procedure  shell started directly by the job step        <- no identifier
   procedure  same shell reached through a wrapper script   <- no identifier
   procedure  same shell fed commands from an env variable  <- no identifier
   ...

go deeper

for a junior

Be ready to recite the three numbered levels — tactic, technique, sub-technique — and to say plainly that the procedure below them has no number. Know that T1059.004 is Unix Shell under T1059 Command and Scripting Interpreter.

for a middle

Explain why the numbering stops: a procedure is one matchable value out of an unbounded set, while a technique is a class named by what the action depends on. Be able to point to Procedure Examples and say whose identifier appears there.

for a senior

Show you can classify from the class rather than the string: given several implementations, say which technique they all sit under and why nothing in the catalogue changes between them. Expect to be pushed on what would change it.

for a principal

Own the consequence for how work is written down. Anything phrased in procedure-shaped items promises far less than a technique-shaped claim, and being clear about which one a plan actually delivers is a leadership call, not a documentation detail.

## What ATT&CK actually numbers Enterprise ATT&CK is a catalogue of typed objects, and several of them carry identifiers: tactics (`TA####`), techniques (`T####`), sub-techniques (`T####.###`), groups (`G####`), software (`S####`), campaigns (`C####`), mitigations (`M####`) and data sources (`DS####`). The part that describes *what an adversary does* is only three levels deep: | Level | Identifier | What it names | |---|---|---| | Tactic | `TA0002` Execution | the adversary's goal for the action | | Technique | `T1059` Command and Scripting Interpreter | a class of action that achieves it | | Sub-technique | `T1059.004` Unix Shell | a narrower class of the same action | And then the numbering stops. ## Where the procedure sits The procedure is the level beneath the sub-technique: ATT&CK's own definition is the specific implementation the adversary used for a technique or sub-technique. On a technique page, procedures are not a numbered list. They are the Procedure Examples section, written as prose sentences of the form *this group used a shell script to run these commands*, each linked to a `G####` group or an `S####` software entry and footnoted to a public report. The identifier you can cite from that row identifies the actor or the tooling. There is no identifier for the implementation itself, and there is no place in the schema to put one. ## Why the numbering stops one level early Because the two things differ in kind, not merely in specificity. A **procedure is a matchable value**. It is a string, an argument order, a parent/child process pair, a file path, a hash. Values are concrete, comparable, and — this is the point — effectively unbounded. One operator with the ability to start a process can spell the same action a hundred ways in an afternoon: wrap it in a script, reorder the flags, feed the commands in from an environment variable, change which parent starts it. Every one of those is a different value and none of them is a different behaviour. A **technique is a class of behaviour**, defined by what the action requires. `T1059.004` covers *an adversary using a Unix shell to execute commands* — the class holds whatever the spelling, because the class is named by the dependency (a shell interpreter, reachable in that context, fed operator-supplied input), not by the text. An identifier is a promise that the thing named is stable and enumerable. Techniques are: the catalogue can list them, argue about them, split them, and a reader can check whether an action falls in the class. Procedures are neither stable nor enumerable. Numbering them would advertise a closed set that does not exist, and would invite the reader to think that when the listed spellings are gone the behaviour is gone. ## A concrete case An operator holding standing privilege on a self-hosted CI runner runs the same action three times in one afternoon: once as a shell started directly by the job step, once through a small wrapper script committed alongside the job, once with the commands supplied from an environment variable the runner already exports. Three procedures. One technique, `T1059.004`, and one tactic, `TA0002` Execution. Nothing in ATT&CK changes between the three, and nothing should: the class the operator depends on is identical each time. ## Two things a T-number is not It is not a name for a *specific* attack that happened — that is a campaign or an incident, described in prose and attributed. And it is not a flaw identifier: `T1059.004` says a shell can be used to execute commands, which is what a shell is for. Flaws live in the CVE namespace and their weakness classes in CWE; ATT&CK identifiers name behaviour, and the two namespaces answer different questions. ## How to say it in an interview *Tactic, technique and sub-technique are numbered; the procedure below them is not, because a procedure is a value and a technique is a class. ATT&CK records procedures as attributed prose examples, and the identifier on that row belongs to the group or the software, not to the implementation.*

  • If procedures carry no identifier, how does ATT&CK record them at all?
    As the Procedure Examples section on a technique page: prose sentences describing what was done, each attributed to a group (`G####`) or software (`S####`) and footnoted to a public report. The identifier in that row names the actor or the tooling, not the implementation, so you can cite who did it but never cite the spelling itself.
  • Do tactics carry identifiers too, or only techniques?
    Tactics carry `TA####` — Execution is `TA0002`. Groups, software, campaigns, mitigations and data sources are numbered as well. What matters is that the behavioural spine is exactly three levels deep: tactic, technique, sub-technique. Everything more specific than a sub-technique is described in prose.
  • Does a sub-technique identifier tell you an adversary can be stopped by patching?
    No. A T-number names a behaviour, not a flaw, and most techniques describe legitimate mechanisms being used by someone unauthorised. `T1059.004` describes using a Unix shell, which is not a defect anyone can patch. Flaw identifiers are CVE records and their weakness classes are CWE entries.

A field guide numbers species, not individuals. The exact bird you photographed does not get its own Latin name; it is an instance of one.

saying these in an interview costs you the question

  • Calls every observed command line its own technique
  • Assumes each procedure gets a decimal identifier under the sub-technique
  • Thinks ATT&CK enumerates every way a technique can be run
  • Reads a T-number as a vulnerability identifier to patch
  • Cites a procedure example by number that does not exist

context