skip to content

ATT&CK entries rest on published real-world use, so what does a behaviour with no technique tell you?

level: juniorimportance: should knowfreq 46%

answer

  1. the catalogue is empirical, not imaginative
  2. entries need a published case behind them
  3. absence describes the literature
  4. lag and publication bias, not impossibility

basics

~20 s

It tells you nobody has publicly written up a real adversary doing it. ATT&CK indexes published observations, so a missing technique is a fact about the literature, not proof that the behaviour is rare, impossible or harmless.

solid answer

~40 s

ATT&CK is empirical by design: a technique enters the catalogue when there is public reporting that real adversaries used the behaviour, not when someone can imagine it. So an empty search answers one narrow question — has this been published? — and nothing else. Three consequences follow. There is a lag: a behaviour is used in the wild long before anyone writes it up. There is publication bias: behaviours seen at victims who never publish, or in sectors that never disclose, stay invisible. And some behaviours can never qualify at all, because they involve no technical step for a technique to describe. Treating "not in ATT&CK" as "not a threat" inverts the direction of the claim. You can still describe the behaviour in plain language; what you lack is a shared label for it.

go deeper

for a junior

Be ready to say in one sentence that ATT&CK collects behaviours somebody has publicly reported adversaries using, so a gap is a gap in the reporting.

for a middle

Explain the mechanics of how an entry comes to exist — observation, investigation, public write-up, contribution — and why that pipeline guarantees a lag between first use and first identifier.

for a senior

Show you can tell a lag apart from a structural gap, and that you never let "no technique" travel into a conversation as though it were a statement about your own environment.

for a principal

Own the consequence for how your organisation talks about adversary behaviour: if every claim is phrased in identifiers, the things the catalogue structurally cannot name become invisible to everyone reading those claims.

## What the catalogue actually is MITRE ATT&CK is a catalogue of **adversary behaviour**, organised in three layers. A **tactic** names the adversary's objective — Initial Access, Persistence, Collection, Exfiltration — and carries an identifier like `TA0009`. A **technique** names a way of reaching that objective and carries an identifier like `T1059`. A **sub-technique** narrows it further (`T1059.001`). The value of the whole thing is that two engineers who have never met can say `T1059.001` and mean the same behaviour. That shared vocabulary only works because the catalogue is disciplined about what gets in. ## The inclusion rule An entry exists because someone **publicly reported that a real adversary used the behaviour**. Not because it is conceivable. Not because a researcher demonstrated it in a lab. Not because it would be devastating if it happened. The catalogue is a record of what has been seen and written down. This is a deliberate design choice, and it is what makes ATT&CK useful rather than an endless brainstorm: the set of things an adversary *could* do is unbounded, while the set of things adversaries *have been observed doing* is finite, citable and comparable across organisations. ## Three things that follow, and they are all about the catalogue **1. Lag.** A behaviour is used, then investigated, then written up, then contributed, then published as an entry. Every step takes time. The estate meets a novel behaviour long before an identifier exists for it. **2. Publication bias.** Entries come from intrusions that were investigated *and* whose write-ups became public. Victims who never disclose, sectors that settle quietly, and intrusions nobody ever untangled contribute nothing. Two behaviours equally common in the wild can have very different catalogue footprints purely because one happened to well-instrumented, publication-friendly victims. **3. Structural exclusions.** Some behaviour can never earn a technique no matter how often it happens, because the catalogue's axis is *technical behaviour*. A fraud that reaches its objective through a persuasive conversation and a legitimate payment instruction involves no technical step to name. An employee reading a dataset their own granted role permits performs an action the catalogue can describe — but the thing that makes it wrong is that they had no legitimate reason, and the schema has no field for that. The first kind of absence closes when somebody publishes. The second and third never close, because they are axes the model does not have. Being able to tell those apart is the whole skill here. ## Get the direction of the claim right An empty result answers *"has this been published?"*. It does not answer *"can this happen to us?"*, *"how likely is it?"* or *"how bad would it be?"*. Reading a missing technique as reassurance is the same error as reading a quiet estate as a safe one: absence of a label is not evidence of absence of behaviour. The converse also deserves care. Presence tells you the behaviour was observed *somewhere*, against *someone*, at least *once*. It says nothing about whether it is plausible in your environment. ## Other catalogues make the other choice CAPEC catalogues **attack patterns** at varying levels of abstraction and is not restricted to behaviour someone has already observed in an intrusion, so it can hold patterns that ATT&CK will never carry. Knowing that the two catalogues are built on different inclusion rules is what stops you from concluding that a behaviour missing from one is unknown to the field. ## What to do when there is no technique Describe the behaviour in plain language instead: who is acting and from what position, what mechanism they use, what asset they reach, and what they must have in order to do it. That description is what a technique identifier was always shorthand for. Losing the shorthand costs you comparability with other organisations; it does not cost you the ability to reason about the behaviour or to argue for the control class that removes it. What you must not do is convert the absence into an assurance. "There is no technique for this" is a true sentence about a catalogue. "Therefore we are fine" is a sentence about your organisation, and the first one is not evidence for the second.

  • How does a genuinely novel behaviour ever get a technique identifier?
    Someone investigates an intrusion, writes it up publicly or contributes it with a citable case, and MITRE adds an entry. The identifier follows the publication, which is why estates meet new behaviour first and get the shared label second.
  • Does every absence eventually close?
    No. There are two kinds. A lag closes as soon as somebody publishes a case. A structural absence never closes: if the behaviour involves no technical step, or if the only thing wrong with it is that the actor had no legitimate reason, the catalogue has no axis on which to record it.
  • Someone claims a behaviour is low priority because it has no technique. What is wrong with that?
    It swaps a fact about publication for a judgement about risk. The catalogue stores no likelihood and no impact, so nothing in it supports a priority claim — that judgement has to come from knowing your own environment.

A field guide lists the birds somebody has photographed. A species missing from the guide is missing from the photographs, not from the forest.

saying these in an interview costs you the question

  • Says a missing technique means no adversary does it
  • Treats ATT&CK as an exhaustive list of possible attacks
  • Reads absence of an entry as assurance about the estate
  • Assumes new behaviours appear in the catalogue immediately
  • Confuses ATT&CK's observed-use rule with CAPEC's broader patterns

context