skip to content

ATT&CK, Kill Chain and TTPs

You will learn what the kill chain, the ATT&CK catalogue, the Diamond Model and the Pyramid of Pain each claim about an adversary. Interviewers use them to hear whether you think in campaigns.

on this pageshow

explore

questions

page 1 of 2

Why does ATT&CK number ICS techniques T0### instead of extending the Enterprise T1### range?

level: juniorimportance: must knowfreq 55%

answer

  1. three domains, not one tree
  2. columns differ, not just contents
  3. no cross-matrix parent or child
  4. Mobile is separate yet still T1###

basics

~20 s

Because ICS is a separate matrix, not a branch of Enterprise. It has its own tactic columns and its own technique list, so its identifiers live in their own space and never nest under an Enterprise number.

solid answer

~50 s

ATT&CK publishes several domain matrices — Enterprise, Mobile and ICS — and each is its own coordinate system: its own ordered tactic columns and its own techniques. ICS carries goals that Enterprise has no column for, such as Impair Process Control and Inhibit Response Function, because Enterprise has no notion of a physical process to mis-drive. The `T0###` range makes the non-nesting explicit: no ICS technique is a child of an Enterprise technique, and you cannot roll ICS numbers up into Enterprise or add the two technique counts together. One caveat that catches people out — the prefix is not a general rule. Mobile is also a separate matrix, but its techniques are numbered in the same `T1###` space, so digits do not tell you which matrix a technique lives in. Only ICS has a distinctive range; for anything else you look the technique up.

go deeper

for a junior

Be ready to say plainly that Enterprise, Mobile and ICS are separate matrices with their own tactic columns, and that ICS techniques use a T0### range because they are not children of Enterprise techniques.

for a middle

Explain why the columns differ, not just the numbers: ICS carries goals such as Impair Process Control that Enterprise has no cell for, and name an action that Enterprise genuinely cannot express.

for a senior

Show what the separation forbids in practice — no nesting, no summed counts across matrices, no dedupe on shared technique names — and note that Mobile is separate despite sharing the T1### space.

for a principal

Own the consequence for reporting: any figure quoted against 'ATT&CK' without naming a matrix is not comparable across estates or vendors, and mixed IT/OT estates need two named denominators rather than one blended one.

## ATT&CK is several catalogues, not one tree People say "ATT&CK" as though it were a single list of numbered attacker behaviours. It is not. MITRE publishes several **domain matrices**, and each one is an independent coordinate system made of three things: an ordered set of **tactic columns** (what the adversary is trying to achieve at that moment), a set of **techniques** placed under those columns (how they achieve it), and the identifiers that name them. The domains are Enterprise, Mobile and ICS (industrial control systems). A "domain" here is not a filter or a view. It is a redraw. Two domain matrices can disagree about what the columns even are, because the adversary's available goals differ once the assets differ. ## What the ICS matrix has that Enterprise does not The clearest evidence is the columns. The ICS matrix carries tactics such as **Impair Process Control** and **Inhibit Response Function** — goals with no Enterprise counterpart, because in Enterprise there is no physical process to drive to the wrong value and no safety function to stop from firing. Enterprise's Impact column is about availability and integrity of data and services; it does not stretch to "the pump now runs at a setpoint the operator did not choose". The same asymmetry shows in the techniques. Consider an ICS technique like **Unauthorized Command Message** (`T0855`) — sending a well-formed, protocol-legal command that the device simply obeys, because the control protocol's specification contains no authentication at all. Try to place that in the Enterprise matrix. It is not Execution: no attacker code runs anywhere. It is not Lateral Movement: nothing was logged into. It is not Exploitation: nothing was exploited, the device did exactly what its designers said it would. Enterprise has no cell for it, which is exactly why ICS is a matrix and not a platform tag. ## What the separate number range asserts The `T0###` range is a structural claim, and it forecloses three specific errors: 1. **Nesting.** No ICS technique is a sub-technique of an Enterprise technique, and no Enterprise technique is the "IT version" of an ICS one. There is no parent-child edge across matrices in either direction. 2. **Summation.** "We address 140 techniques" is meaningless if some are `T1###` and some are `T0###`. The denominators are different catalogues, so the numerator is not a quantity. 3. **Comparison.** Two estates measured against different matrices have not been measured against the same thing, even where the technique names look similar. That last point matters because **names recur across matrices**. Several familiar technique names appear in both the Enterprise and ICS catalogues, but each occurrence is a distinct object with its own identifier, its own description and its own asset scope. Deduplicating by name silently merges two different claims. ## The prefix is evidence, not a rule Here is where a confident answer goes wrong. Having learned that ICS is `T0###`, people generalise: every matrix must have its own prefix, therefore the digits identify the domain. They do not. **Mobile is the third domain matrix and its techniques are numbered in the same `T1###` space as Enterprise.** Identifiers are unique across all of ATT&CK, so there is no collision — but there is also no readable signal. Given a bare `T1###` number you cannot tell from the digits whether it is an Enterprise technique or a Mobile one; you have to look it up. So the honest statement is: ICS has a distinctive range, and that range is good evidence that ICS is separate — but separateness is a property of the matrix, not of the numbering scheme, and Mobile proves it by being separate without a distinctive range. ## Why interviewers ask this It is a cheap test of whether you have opened the catalogue or only cited it. The wrong answers are all reasonable-sounding: "T0 is the legacy numbering", "ICS is the OT sub-tree of Enterprise", "each matrix has its own prefix". Each one implies a wrong operating model — that ICS behaviours roll up into an Enterprise picture, that an OT-adjacent estate can be described in one coordinate system, that you can add the numbers. The correction is a single fact you either know or do not: they are different matrices with different tactic columns, and nothing nests. ## Where it bites Any estate that is neither purely office nor purely plant — building automation, physical security devices, lab and facility equipment sitting on the same network as laptops — forces the question of which matrix describes it. The answer is normally "both, per asset group, joined by hand", and knowing that the two number spaces do not nest is the first step to saying so without pretending the join comes for free.

  • If T0### marks ICS, what prefix marks Mobile?
    None. Mobile is a separate domain matrix, but its techniques are numbered in the same T1### space as Enterprise. Identifiers are unique across all of ATT&CK, so nothing collides, but the digits carry no domain signal. ICS is the only domain with a distinctive range, and you identify any other technique's matrix by looking the object up rather than by reading the number.
  • A technique name appears in both the Enterprise and ICS catalogues. Same definition?
    No. Each is a distinct object with its own identifier, description and asset scope, written for a different set of devices. Treating the shared name as one entry merges two different claims and quietly halves your technique count. If you are joining Enterprise and ICS material, join on identifiers and keep both, never on names.
  • Someone reports coping with 140 ATT&CK techniques across a mixed IT and OT estate. What is wrong with the number?
    It sums across two catalogues. Enterprise and ICS have different tactic columns and different technique populations, so a count that mixes T1### and T0### has no denominator behind it and cannot be compared with anyone else's figure. Report two numbers against two named matrices, or report none.

Two maps of the same country drawn on different grids. A grid reference from one is not a coarser or finer version of the other's — it is unreadable there.

saying these in an interview costs you the question

  • Calls ICS a sub-tree or OT branch of Enterprise ATT&CK
  • Reads T0### as an older or deprecated numbering scheme
  • Assumes every ATT&CK matrix has its own numeric prefix
  • Adds Enterprise and ICS technique counts into one total
  • Merges same-named Enterprise and ICS techniques as duplicates

context

open as a page

In MITRE ATT&CK, what does a tactic column name, and why does one technique sit in several?

level: juniorimportance: must knowfreq 74%

basics

~20 s

A tactic names the adversary's goal for an action, not the action. The same technique can serve several goals, so ATT&CK lists it under every tactic it achieves: T1078 Valid Accounts sits in four columns.

open as a page

In MITRE ATT&CK, what does a T#### identifier name, and why does an observed command line have none?

level: juniorimportance: must knowfreq 65%

basics

~20 s

A T#### identifier names a technique, a class of adversary behaviour, and T####.### a sub-technique of it. The exact command line you saw is a procedure: one implementation of that class, and ATT&CK gives procedures no identifier at all.

open as a page

Are MITRE ATT&CK's tactic columns an ordered sequence an intrusion moves through?

level: juniorimportance: must knowfreq 72%

basics

~20 s

No. ATT&CK's tactic columns are goal categories, not stages. An intrusion can re-enter one column repeatedly, never touch several of them, and hit them in any order. The Cyber Kill Chain is the model that asserts order; ATT&CK's columns do not.

open as a page

In MITRE ATT&CK, which field on a technique page tells you how severe that technique is?

level: juniorimportance: must knowfreq 58%

basics

~20 s

None does. An ATT&CK technique page carries an ID, tactics, platforms, procedure examples, mitigations, detection notes and data components, but no severity, likelihood, frequency or impact score. Severity is a property of your estate, not of the technique.

open as a page

In the Pyramid of Pain, what does a rung's height actually measure?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Height measures the adversary's replacement cost: how much money and operator time it costs them to swap that thing once it stops working. It says nothing about how dangerous the thing is or how confident you are.

open as a page

Can ATT&CK technique T1550.001 be closed out by patching, and if not, why not?

level: middleimportance: must knowfreq 60%

basics

~20 s

No. An ATT&CK T-number names a class of adversary behaviour, not a defect in a product. T1550.001 - using an application's access token - involves nothing broken, so only a control over grants and scopes changes exposure.

open as a page

A root-owned systemd timer runs a script hourly on a Linux server — which ATT&CK tactic is it?

level: middleimportance: must knowfreq 56%

basics

~20 s

None can be read from the unit alone. The same timer is byte-identical whether an operator installed it to keep access, installed it to reach root, or an administrator installed it during maintenance. The tactic names the goal, and the goal is not on disk.

open as a page

Does blocking one observed shell command line stop ATT&CK T1059.004 on a CI runner?

level: middleimportance: must knowfreq 58%

basics

~20 s

No. You removed one procedure, a matchable value, not the technique. T1059.004 is the class of using a Unix shell to execute commands, and an operator who already runs code on that runner respells it in minutes.

open as a page

Which Cyber Kill Chain links does a buyer of working VPN credentials never traverse?

level: middleimportance: must knowfreq 52%

basics

~10 s

Reconnaissance, Weaponization, Delivery and Exploitation. The buyer's path begins no earlier than Installation, and where the purchased access is itself standing access, their first act is Actions on Objectives.

open as a page

Should an ATT&CK mapping credit a credential-access step the write-up only implies?

level: middleimportance: must knowfreq 61%

basics

~10 s

Credit it only when the described outcome entails the step, and only as a row marked inferred against the sentence behind it. Silence is a fact about the author, not the intrusion.

open as a page

Why does an ATT&CK technique identifier fail to capture an insider's export done with their own granted cloud role?

level: middleimportance: must knowfreq 58%

basics

~20 s

ATT&CK records what was done and toward which goal, never whether the actor was permitted to do it. A cloud bulk-read technique is equally true of the nightly analytics job, so the identifier carries nothing that makes the export wrong.

open as a page

A reused self-signed certificate links adversary staging hosts to a second company's cloud control-plane endpoint — what does that Diamond Model pivot actually establish?

level: seniorimportance: must knowfreq 46%

basics

~20 s

Only that, within a dated window, a host presenting a particular private key exchanged traffic with a particular endpoint. It establishes an edge to a victim asset, not a compromise, not targeting, and not that the asset belongs to that company.

open as a page

ATT&CK T1527 was a valid technique ID in 2019 and is absent from today's matrix - what happened?

level: juniorimportance: should knowfreq 50%

basics

~20 s

T1527 was revoked in the July 2020 ATT&CK v7 release, when sub-techniques were introduced. The same behaviour is now T1550.001, a sub-technique of Use Alternate Authentication Material. The number changed; the adversary behaviour did not.

open as a page

In the Diamond Model, how do two filled vertices lead you to a third?

level: juniorimportance: should knowfreq 44%

basics

~20 s

By pivoting: a feature you already know is used as a search key to find features you do not. Knowing the capability and the infrastructure that served it, you can reach a victim nobody has looked at yet.

open as a page

Two ATT&CK mappings of the same intrusion write-up differ — is one of them wrong?

level: juniorimportance: should knowfreq 52%

basics

~10 s

Not necessarily. An ATT&CK mapping is a claim about the account you read, not about the intrusion itself. Two people differ mainly because they apply different rules to steps the author never wrote down.

open as a page

ATT&CK entries rest on published real-world use, so what does a behaviour with no technique tell you?

level: juniorimportance: should knowfreq 46%

basics

~20 s

It tells you nobody has publicly written up a real adversary doing it. ATT&CK indexes published observations, so a missing technique is a fact about the literature, not proof that the behaviour is rare, impossible or harmless.

open as a page

In ATT&CK, what is the difference between a deprecated technique and a revoked one?

level: middleimportance: should knowfreq 38%

basics

~20 s

Revoked means replaced: the object names the technique that superseded it, so an old reference migrates mechanically. Deprecated means withdrawn with no successor, so nothing can be migrated and a person must re-judge the behaviour.

open as a page

In ATT&CK Enterprise, what does listing Cloud or Containers as a platform assert, and what does it not?

level: middleimportance: should knowfreq 46%

basics

~20 s

A platform is an applicability tag on techniques inside the single Enterprise matrix: it says the behaviour applies to IaaS, SaaS, identity or container assets. It creates no separate tactic set, no separate technique list and no separate matrix.

open as a page

In an ATT&CK-tagged intrusion, why can Discovery recur three times while Persistence never occurs?

level: middleimportance: should knowfreq 54%

basics

~20 s

Because a tactic names a goal, not a step. An operator re-enters Discovery every time the next decision needs information they do not have, and never reaches Persistence when the objective completes inside one visit and returning is worth nothing to them.

open as a page

In the Diamond Model, why does every event carry a timestamp, direction and result?

level: middleimportance: should knowfreq 33%

basics

~20 s

Because they are what make an edge falsifiable. Meta-features date the event, say which way it ran, and record whether it succeeded, so a pivot is a claim someone can disprove rather than a permanent line on a graph.

open as a page

A step in an intrusion write-up has no matching ATT&CK technique — what do you do?

level: middleimportance: should knowfreq 37%

basics

~20 s

Leave it unmapped and say so. ATT&CK catalogues adversary behaviour, so much of any account — conditions, motive, business context, the author's speculation — carries no identifier. Forcing the nearest one asserts a behaviour the source never describes.

open as a page

Two teams order the same 30 ATT&CK techniques differently. Which one misread the catalogue?

level: middleimportance: should knowfreq 45%

basics

~20 s

Probably neither. ATT&CK stores no ordering, so both lists were built from assumptions the teams brought with them: who they expect to face, and what their estate exposes. Compare the assumptions, not the two lists.

open as a page

In the Pyramid of Pain, why is renaming an implant's mutex cheaper than changing tools?

level: middleimportance: should knowfreq 46%

basics

~20 s

A mutex name is just a literal the tool writes, like a service name or install path. Changing one is an edit and a rebuild. Losing the tool costs the capability itself: weeks of development, or money.

open as a page

A five-year ATT&CK technique series shows one technique dropping 30% - why is "they stopped" wrong?

level: seniorimportance: should knowfreq 44%

basics

~10 s

Because the catalogue moved underneath the series. Identifiers were revoked, split and re-parented across those releases, and the mappings count labels people wrote, not adversary actions. Normalise every year to one release first.

open as a page

In ATT&CK, how do you map one intrusion that crosses an Enterprise host action and an ICS-only plant action?

level: seniorimportance: should knowfreq 34%

basics

~20 s

You produce two mappings in two coordinate systems and join them yourself. ATT&CK has no edge linking a T1### technique to a T0### one, so the ordering, the causal link and the single narrative are yours to write, not the catalogue's.

open as a page

A root systemd timer runs a script writable by a deploy account — which adversary goal do you remove?

level: seniorimportance: should knowfreq 42%

basics

~10 s

Remove the Privilege Escalation goal first: make nothing a lower-privileged account can write execute as root. That goal has no substitute. Persistence has many carriers, so blocking timers alone just relocates it.

open as a page

Three different shell spellings of one action on a CI runner: one ATT&CK technique or three?

level: seniorimportance: should knowfreq 42%

basics

~20 s

One technique and three procedures, provided all three still depend on the same mechanism. Classify by what the action cannot do without, not by how it was written; a new sub-technique needs a mechanism that differs in kind, not a different string.

open as a page

In an ATT&CK-tagged intrusion, Impact occurs before any Exfiltration. What does that order tell you?

level: seniorimportance: should knowfreq 41%

basics

~20 s

It is evidence about the operator's payoff, not a mapping error. Impact first says the visible effect was the objective itself, so nothing after it was worth doing. It does not prove that no data ever left.

open as a page

showing 1–30 of 43