skip to content

Inside the Technique Catalogue

ATT&CK has a shape: numbered levels, tactic columns chosen by intent, one matrix per domain, and identifiers that move between releases. Interviewers probe whether you have read it or only cited it.

on this pageshow

explore

questions

17

Why does ATT&CK number ICS techniques T0### instead of extending the Enterprise T1### range?

level: juniorimportance: must knowfreq 55%

answer

  1. three domains, not one tree
  2. columns differ, not just contents
  3. no cross-matrix parent or child
  4. Mobile is separate yet still T1###

basics

~20 s

Because ICS is a separate matrix, not a branch of Enterprise. It has its own tactic columns and its own technique list, so its identifiers live in their own space and never nest under an Enterprise number.

solid answer

~50 s

ATT&CK publishes several domain matrices — Enterprise, Mobile and ICS — and each is its own coordinate system: its own ordered tactic columns and its own techniques. ICS carries goals that Enterprise has no column for, such as Impair Process Control and Inhibit Response Function, because Enterprise has no notion of a physical process to mis-drive. The `T0###` range makes the non-nesting explicit: no ICS technique is a child of an Enterprise technique, and you cannot roll ICS numbers up into Enterprise or add the two technique counts together. One caveat that catches people out — the prefix is not a general rule. Mobile is also a separate matrix, but its techniques are numbered in the same `T1###` space, so digits do not tell you which matrix a technique lives in. Only ICS has a distinctive range; for anything else you look the technique up.

go deeper

for a junior

Be ready to say plainly that Enterprise, Mobile and ICS are separate matrices with their own tactic columns, and that ICS techniques use a T0### range because they are not children of Enterprise techniques.

for a middle

Explain why the columns differ, not just the numbers: ICS carries goals such as Impair Process Control that Enterprise has no cell for, and name an action that Enterprise genuinely cannot express.

for a senior

Show what the separation forbids in practice — no nesting, no summed counts across matrices, no dedupe on shared technique names — and note that Mobile is separate despite sharing the T1### space.

for a principal

Own the consequence for reporting: any figure quoted against 'ATT&CK' without naming a matrix is not comparable across estates or vendors, and mixed IT/OT estates need two named denominators rather than one blended one.

## ATT&CK is several catalogues, not one tree People say "ATT&CK" as though it were a single list of numbered attacker behaviours. It is not. MITRE publishes several **domain matrices**, and each one is an independent coordinate system made of three things: an ordered set of **tactic columns** (what the adversary is trying to achieve at that moment), a set of **techniques** placed under those columns (how they achieve it), and the identifiers that name them. The domains are Enterprise, Mobile and ICS (industrial control systems). A "domain" here is not a filter or a view. It is a redraw. Two domain matrices can disagree about what the columns even are, because the adversary's available goals differ once the assets differ. ## What the ICS matrix has that Enterprise does not The clearest evidence is the columns. The ICS matrix carries tactics such as **Impair Process Control** and **Inhibit Response Function** — goals with no Enterprise counterpart, because in Enterprise there is no physical process to drive to the wrong value and no safety function to stop from firing. Enterprise's Impact column is about availability and integrity of data and services; it does not stretch to "the pump now runs at a setpoint the operator did not choose". The same asymmetry shows in the techniques. Consider an ICS technique like **Unauthorized Command Message** (`T0855`) — sending a well-formed, protocol-legal command that the device simply obeys, because the control protocol's specification contains no authentication at all. Try to place that in the Enterprise matrix. It is not Execution: no attacker code runs anywhere. It is not Lateral Movement: nothing was logged into. It is not Exploitation: nothing was exploited, the device did exactly what its designers said it would. Enterprise has no cell for it, which is exactly why ICS is a matrix and not a platform tag. ## What the separate number range asserts The `T0###` range is a structural claim, and it forecloses three specific errors: 1. **Nesting.** No ICS technique is a sub-technique of an Enterprise technique, and no Enterprise technique is the "IT version" of an ICS one. There is no parent-child edge across matrices in either direction. 2. **Summation.** "We address 140 techniques" is meaningless if some are `T1###` and some are `T0###`. The denominators are different catalogues, so the numerator is not a quantity. 3. **Comparison.** Two estates measured against different matrices have not been measured against the same thing, even where the technique names look similar. That last point matters because **names recur across matrices**. Several familiar technique names appear in both the Enterprise and ICS catalogues, but each occurrence is a distinct object with its own identifier, its own description and its own asset scope. Deduplicating by name silently merges two different claims. ## The prefix is evidence, not a rule Here is where a confident answer goes wrong. Having learned that ICS is `T0###`, people generalise: every matrix must have its own prefix, therefore the digits identify the domain. They do not. **Mobile is the third domain matrix and its techniques are numbered in the same `T1###` space as Enterprise.** Identifiers are unique across all of ATT&CK, so there is no collision — but there is also no readable signal. Given a bare `T1###` number you cannot tell from the digits whether it is an Enterprise technique or a Mobile one; you have to look it up. So the honest statement is: ICS has a distinctive range, and that range is good evidence that ICS is separate — but separateness is a property of the matrix, not of the numbering scheme, and Mobile proves it by being separate without a distinctive range. ## Why interviewers ask this It is a cheap test of whether you have opened the catalogue or only cited it. The wrong answers are all reasonable-sounding: "T0 is the legacy numbering", "ICS is the OT sub-tree of Enterprise", "each matrix has its own prefix". Each one implies a wrong operating model — that ICS behaviours roll up into an Enterprise picture, that an OT-adjacent estate can be described in one coordinate system, that you can add the numbers. The correction is a single fact you either know or do not: they are different matrices with different tactic columns, and nothing nests. ## Where it bites Any estate that is neither purely office nor purely plant — building automation, physical security devices, lab and facility equipment sitting on the same network as laptops — forces the question of which matrix describes it. The answer is normally "both, per asset group, joined by hand", and knowing that the two number spaces do not nest is the first step to saying so without pretending the join comes for free.

  • If T0### marks ICS, what prefix marks Mobile?
    None. Mobile is a separate domain matrix, but its techniques are numbered in the same T1### space as Enterprise. Identifiers are unique across all of ATT&CK, so nothing collides, but the digits carry no domain signal. ICS is the only domain with a distinctive range, and you identify any other technique's matrix by looking the object up rather than by reading the number.
  • A technique name appears in both the Enterprise and ICS catalogues. Same definition?
    No. Each is a distinct object with its own identifier, description and asset scope, written for a different set of devices. Treating the shared name as one entry merges two different claims and quietly halves your technique count. If you are joining Enterprise and ICS material, join on identifiers and keep both, never on names.
  • Someone reports coping with 140 ATT&CK techniques across a mixed IT and OT estate. What is wrong with the number?
    It sums across two catalogues. Enterprise and ICS have different tactic columns and different technique populations, so a count that mixes T1### and T0### has no denominator behind it and cannot be compared with anyone else's figure. Report two numbers against two named matrices, or report none.

Two maps of the same country drawn on different grids. A grid reference from one is not a coarser or finer version of the other's — it is unreadable there.

saying these in an interview costs you the question

  • Calls ICS a sub-tree or OT branch of Enterprise ATT&CK
  • Reads T0### as an older or deprecated numbering scheme
  • Assumes every ATT&CK matrix has its own numeric prefix
  • Adds Enterprise and ICS technique counts into one total
  • Merges same-named Enterprise and ICS techniques as duplicates

context

open as a page

In MITRE ATT&CK, what does a tactic column name, and why does one technique sit in several?

level: juniorimportance: must knowfreq 74%

basics

~20 s

A tactic names the adversary's goal for an action, not the action. The same technique can serve several goals, so ATT&CK lists it under every tactic it achieves: T1078 Valid Accounts sits in four columns.

open as a page

In MITRE ATT&CK, what does a T#### identifier name, and why does an observed command line have none?

level: juniorimportance: must knowfreq 65%

basics

~20 s

A T#### identifier names a technique, a class of adversary behaviour, and T####.### a sub-technique of it. The exact command line you saw is a procedure: one implementation of that class, and ATT&CK gives procedures no identifier at all.

open as a page

Can ATT&CK technique T1550.001 be closed out by patching, and if not, why not?

level: middleimportance: must knowfreq 60%

basics

~20 s

No. An ATT&CK T-number names a class of adversary behaviour, not a defect in a product. T1550.001 - using an application's access token - involves nothing broken, so only a control over grants and scopes changes exposure.

open as a page

A root-owned systemd timer runs a script hourly on a Linux server — which ATT&CK tactic is it?

level: middleimportance: must knowfreq 56%

basics

~20 s

None can be read from the unit alone. The same timer is byte-identical whether an operator installed it to keep access, installed it to reach root, or an administrator installed it during maintenance. The tactic names the goal, and the goal is not on disk.

open as a page

Does blocking one observed shell command line stop ATT&CK T1059.004 on a CI runner?

level: middleimportance: must knowfreq 58%

basics

~20 s

No. You removed one procedure, a matchable value, not the technique. T1059.004 is the class of using a Unix shell to execute commands, and an operator who already runs code on that runner respells it in minutes.

open as a page

ATT&CK T1527 was a valid technique ID in 2019 and is absent from today's matrix - what happened?

level: juniorimportance: should knowfreq 50%

basics

~20 s

T1527 was revoked in the July 2020 ATT&CK v7 release, when sub-techniques were introduced. The same behaviour is now T1550.001, a sub-technique of Use Alternate Authentication Material. The number changed; the adversary behaviour did not.

open as a page

In ATT&CK, what is the difference between a deprecated technique and a revoked one?

level: middleimportance: should knowfreq 38%

basics

~20 s

Revoked means replaced: the object names the technique that superseded it, so an old reference migrates mechanically. Deprecated means withdrawn with no successor, so nothing can be migrated and a person must re-judge the behaviour.

open as a page

In ATT&CK Enterprise, what does listing Cloud or Containers as a platform assert, and what does it not?

level: middleimportance: should knowfreq 46%

basics

~20 s

A platform is an applicability tag on techniques inside the single Enterprise matrix: it says the behaviour applies to IaaS, SaaS, identity or container assets. It creates no separate tactic set, no separate technique list and no separate matrix.

open as a page

A five-year ATT&CK technique series shows one technique dropping 30% - why is "they stopped" wrong?

level: seniorimportance: should knowfreq 44%

basics

~10 s

Because the catalogue moved underneath the series. Identifiers were revoked, split and re-parented across those releases, and the mappings count labels people wrote, not adversary actions. Normalise every year to one release first.

open as a page

In ATT&CK, how do you map one intrusion that crosses an Enterprise host action and an ICS-only plant action?

level: seniorimportance: should knowfreq 34%

basics

~20 s

You produce two mappings in two coordinate systems and join them yourself. ATT&CK has no edge linking a T1### technique to a T0### one, so the ordering, the causal link and the single narrative are yours to write, not the catalogue's.

open as a page

A root systemd timer runs a script writable by a deploy account — which adversary goal do you remove?

level: seniorimportance: should knowfreq 42%

basics

~10 s

Remove the Privilege Escalation goal first: make nothing a lower-privileged account can write execute as root. That goal has no substitute. Persistence has many carriers, so blocking timers alone just relocates it.

open as a page

Three different shell spellings of one action on a CI runner: one ATT&CK technique or three?

level: seniorimportance: should knowfreq 42%

basics

~20 s

One technique and three procedures, provided all three still depend on the same mechanism. Classify by what the action cannot do without, not by how it was written; a new sub-technique needs a mechanism that differs in kind, not a different string.

open as a page

Why is Defense Evasion an ATT&CK tactic column rather than a label for any quiet action?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

Defense Evasion names a goal an operator spends effort on: steps taken specifically to avoid or degrade controls. Being inconspicuous by accident is not Defense Evasion. Used as an adjective, the column tags everything and stops naming a choice.

open as a page

ATT&CK ships two releases a year - do you re-map five years of technique mappings or pin a version?

level: principalimportance: nice to knowfreq 26%

basics

~10 s

Do both, selectively. Migrate mechanically resolvable identifiers on a schedule and keep the originals, never back-fill granularity nobody recorded, and stamp every mapping with its release. Pinning forever fails because everyone else moves.

open as a page

Which ATT&CK matrix scopes an estate whose flat segment mixes office hosts with building-automation controllers?

level: principalimportance: nice to knowfreq 24%

basics

~20 s

Both, scoped per asset group rather than per estate: Enterprise for the office hosts, ICS for the controllers. The decision matters because naming a matrix names which adversary goals are in scope, and therefore whose budget owns the gap between them.

open as a page

Your remediation list blocks command lines one by one — how do you state ATT&CK technique risk to the owner?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

State the claim in the adversary's currency: say which procedures are closed, what respelling costs the operator, and that the technique class remains open. Never let a procedure-shaped item close a technique-shaped one, even under schedule pressure.

open as a page