Two teams order the same 30 ATT&CK techniques differently. Which one misread the catalogue?
answer
- neither of them, probably
- nothing in the page to disagree about
- two inputs come from outside
- assumed adversary plus specific estate
basics
~20 sProbably neither. ATT&CK stores no ordering, so both lists were built from assumptions the teams brought with them: who they expect to face, and what their estate exposes. Compare the assumptions, not the two lists.
solid answer
~50 sNeither, unless one made a factual error, because there is no ordering in ATT&CK to misread. Any ranked technique list is the product of two imported inputs: an assumed adversary and a specific estate. Assume a ransomware affiliate working on a revenue split, and the list sorts toward whatever shortens the time to a payable position — breadth, reach into file shares, removing whatever would slow the final step; noise is acceptable because the operation ends anyway. Assume a state-funded crew with years of patience and no revenue target, and the same thirty techniques sort toward quiet durable access and collection, toward credential material and delegated rights and behaviour that looks like administration. Same catalogue, different top five. So the question worth asking is not who read the page correctly, but which adversary each team assumed and whether that assumption is defensible for this organisation.
go deeper
Know that ATT&CK ships no ordering at all, so two different rankings built from it are not a contradiction. Be able to say what a ranking would need that the catalogue does not hold.
Explain the two imported inputs, an assumed adversary and a specific estate, and show with a concrete contrast that changing the assumed adversary re-sorts the list while every page stays identical.
Demonstrate how you resolve the argument in practice: make each team state its premise before its list, and move the disagreement onto estate facts, which can be checked, rather than onto the framework, which cannot arbitrate.
Be ready to defend which adversary assumption your organisation ranks against, and to say who owns changing it, because that single premise silently determines every prioritised list your teams produce.
## There is no ordering to misread The question is a trap, and the trap is worth naming out loud: it invites you to adjudicate between two readings of a document that contains nothing to read on this point. ATT&CK stores no severity, no likelihood and no ranking. Two ordered lists derived from it therefore cannot disagree *about the catalogue*. They disagree about the two things each team supplied from outside it. ## The two imported inputs **An assumed adversary.** Ranking behaviour requires knowing whose behaviour you are ranking, because ordering is a statement about what someone would choose to do, and choice follows economics. **A specific estate.** The same behaviour reaches different things in different places, so even two teams who agree perfectly on the adversary will still order differently if they are describing different infrastructure. Get a disagreement, and one of those two is where it lives. Neither is in the document. ## The demonstration: one list, two economies Take the same thirty techniques and price them twice. An affiliate working for a share of a payment has a clock and a margin. Every hour spent is unpaid, and the operation is disposable — it ends in an event that announces itself, so stealth has value only up to that moment and none after it. What rises in that ordering is anything that buys **breadth quickly**: mass reach across hosts, access to the shares and backups that determine whether anyone pays, removal of whatever would slow the final step. What sinks is anything patient. Careful long-lived access is worth nothing to someone who is leaving on Friday. A crew with state funding, a collection requirement and no revenue target prices time at nearly zero and prices *discovery* very high. What rises there is **durability and quiet**: credential material that keeps working, delegated rights that look like administration, access paths that survive a password reset and a rebuild, behaviour indistinguishable from the estate's own noise. What sinks is anything loud and anything that forces a decision from the owner of the estate. | What the adversary is optimising | What rises in the ordering | | --- | --- | | Time to a payable position, on a revenue split | Breadth, reach to shared storage, removing what would slow the end | | Durable collection, with time and no revenue target | Quiet credential access, delegated rights, paths that survive a reset | Same thirty pages. Both orderings are internally correct. Neither was produced by the catalogue. The point of the contrast is not a taxonomy of adversaries. It is that swapping one assumption re-sorts the entire list while every technique page stays byte-for-byte identical. That is the proof that the ordering was never in there. ## What to do with the disagreement Ask each team to state its premise as a sentence before its list: *assuming an adversary who is optimising for X, against this estate as it is configured today, here is the order.* Almost every argument of this kind dissolves the moment both premises are on the table, because the teams turn out to have been answering two different questions competently. If the premises match and the lists still differ, the disagreement has moved to facts about the estate, and that is a much better argument to be having: it is checkable. ## The failure mode to avoid The weak move is to appeal to the framework as an arbiter — to go looking for the authoritative order and to treat the team whose list is further from some remembered "top techniques" article as wrong. Those articles are themselves someone else's imported ordering, usually derived from published reporting, which measures disclosure rather than what will happen to you. Borrowing an ordering is legitimate; borrowing it and forgetting it was borrowed is how an organisation ends up defending someone else's estate.
- The two teams agree on the assumed adversary but still disagree on the order. What is left to explain?The estate. Ordering is a function of what actually exists, what is exposed, and what a given behaviour reaches from where it lands. If both teams share a premise about the adversary, the argument is now about configuration facts, which is a checkable argument rather than a matter of taste.
- Could MITRE fix this by adding a severity field to every technique?Not usefully. The value would have to be a function of the reader's estate and expected adversary, so any single stored number would be wrong for nearly every consumer, and being wrong authoritatively is worse than being absent. The ordering genuinely belongs to the consumer.
saying these in an interview costs you the question
- Declares one team obviously misread the ATT&CK page
- Believes ATT&CK ranks techniques by prevalence
- Treats a published top-techniques list as objective
- Cannot state the adversary assumption behind their own ordering