skip to content

Tactic Assignment by Intent

The same technique sits under several tactics, because a tactic names the adversary's goal for an action rather than the action. Interviewers use it to catch people reading it as a filing system.

on this pageshow

explore

questions

4

In MITRE ATT&CK, what does a tactic column name, and why does one technique sit in several?

level: juniorimportance: must knowfreq 74%

answer

  1. columns ask why, cells ask how
  2. the same act can buy different things
  3. Valid Accounts appears in four columns
  4. goal is not written on the artefact

basics

~20 s

A tactic names the adversary's goal for an action, not the action. The same technique can serve several goals, so ATT&CK lists it under every tactic it achieves: T1078 Valid Accounts sits in four columns.

solid answer

~50 s

ATT&CK is a grid: columns are tactics, cells are techniques. A technique answers *how* — Valid Accounts, Scheduled Task/Job, Masquerading. A tactic answers *why the operator did that, at that moment* — Initial Access, Persistence, Privilege Escalation, Defense Evasion and the rest. Because one act can buy different things, a technique is listed under every tactic it can serve. `T1078` Valid Accounts is the standard example: the same sign-in is Initial Access if it is how they got in, Persistence because the account is still valid tomorrow, Privilege Escalation if the account carries rights the operator lacked, and Defense Evasion because the work is indistinguishable from the owner's own. That is one technique with four tactic memberships, not four techniques. The corollary matters more than the definition: you cannot read the tactic off the artefact, because the artefact records the action and the tactic names the goal.

go deeper

for a junior

Be ready to state the difference in one line: tactic equals goal, technique equals method, and one technique can serve several goals. Naming Valid Accounts as the multi-tactic example is enough at this level.

for a middle

Expect to explain why multi-tactic membership is structural rather than sloppy, and to work the classifying question out loud: what did this action buy that the operator did not already hold?

for a senior

Show that you refuse to assign a tactic from an artefact alone, and that you say what further facts about the intrusion would settle it. Interviewers watch for candidates who classify confidently on no evidence.

for a principal

Own the downstream cost of the confusion. When goals are read off artefacts, remediation gets aimed at the artefact, the goal survives with another carrier, and the organisation believes it has removed something it has not.

## Two levels, two different questions ATT&CK is a grid. The columns are **tactics**; the cells beneath a column are **techniques**. They answer different questions, and they are not two names for the same layer. - A **technique** answers *how*: `T1078` Valid Accounts, `T1053` Scheduled Task/Job, `T1036` Masquerading. - A **tactic** answers *why the adversary did that, at that moment*: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact — with Reconnaissance and Resource Development covering what happens before the intrusion touches the estate at all. A tactic is a **short-range goal**. It is not a severity, not a description of the act, and not a phase every intrusion must pass through. ## Why one technique sits in several columns Because one act reaches different goals depending on what it bought the operator. `T1078` Valid Accounts is the canonical case: authenticating with credentials that belong to a real account is listed under four tactics. | Tactic | What that sign-in bought | |---|---| | Initial Access | it is how the operator got in at all | | Persistence | the account is still valid tomorrow, so nothing has to be dropped on a host | | Privilege Escalation | the account carries rights the operator's previous one did not | | Defense Evasion | the work is indistinguishable from the account owner's own | That is **one** technique object carrying four tactic memberships. It is not four techniques sharing an identifier, it is not a technique that 'moved column' between releases, and it is not a numbering accident. `T1053` Scheduled Task/Job behaves the same way, carrying Execution, Persistence and Privilege Escalation. ## The consequence: the artefact never carries the tactic This is the part candidates skip. If the tactic names the goal, then nothing you can hold in your hand — a unit file, a registry value, a binary, a sign-in record — decides it. Two engineers can produce the identical artefact for opposite reasons, and the classification differs while the bytes do not. The tactic comes from the **surrounding intrusion**: what the operator held before the act, what they held after, and what they would have had to do instead if this act had failed. A useful test: *what did this action buy that the operator did not already have?* If the answer is 'a way back in after a reboot', the tactic is Persistence. If it is 'a context with rights I did not hold', it is Privilege Escalation. If it is 'nothing — they already had all of that', then either you have the wrong tactic or you are looking at an ordinary administrator's work. ## Ordering is a convenience, not a sequence The columns run left to right in the rough order a textbook intrusion unfolds, and this misleads people into treating the matrix as a pipeline. It is not. Real intrusions skip columns entirely (an operator who arrives on a valid account with the rights they need never touches Privilege Escalation), revisit them (Discovery happens again after every hop), and interleave them. The kill chain, a different and older model, is the one that asserts sequence; ATT&CK deliberately does not. ## What ATT&CK is describing Every technique is a **behaviour** — a class of things people have been observed doing. It is not a flaw, not a product weakness, and not a thing you can patch. That is why a technique identifier and a vulnerability identifier are not interchangeable and never map one-to-one: one names what an adversary does, the other names a specific defect in specific code. ## The wrong answer this question aims at The confident-sounding wrong answer is *'the technique determines the tactic, so a technique lives in one column'*. It is wrong in both halves. Techniques are multi-tactic by design because goals are what tactics name, and the goal is a fact about the operator's plan, not about the act. Anyone who tries to classify by looking only at what was done will assign a tactic that reads plausibly and is unfalsifiable — and will then propose a remedy aimed at the artefact rather than at the goal, which is where the real cost of the mistake lands.

  • If a technique appears under four tactics, is that four techniques or one?
    One. There is a single technique object with a single identifier and a set of tactic memberships. `T1078` Valid Accounts is one technique that ATT&CK asserts can serve Initial Access, Persistence, Privilege Escalation or Defense Evasion. Rendering the matrix repeats the cell once per column, which is a display artefact of a grid, not four separate entries.
  • If the tactic is not in the artefact, where does it come from?
    From the intrusion around it — what the operator held before the act and what they held after. The classifying question is what this action bought that they did not already have: a way back after reboot means Persistence, a higher-privileged context means Privilege Escalation. If it bought nothing, you may be looking at ordinary administration rather than an adversary at all.
  • Does the left-to-right order of the columns mean an intrusion visits them in order?
    No. The order is a readability convention. Intrusions skip columns entirely, revisit them repeatedly and interleave them: an operator arriving on an account that already holds the rights they need never enters Privilege Escalation at all. The kill chain is the model that asserts a sequence; ATT&CK deliberately does not.

A ladder is one object. Whether it is a burglary tool, a maintenance tool, or nothing at all depends entirely on who is standing on it and what they wanted from the roof.

saying these in an interview costs you the question

  • Says every technique belongs to exactly one tactic column
  • Reads the tactic straight off the artefact that was found
  • Treats tactic and technique as two words for the same layer
  • Claims the column order is a sequence every intrusion follows
  • Describes a technique as a vulnerability that can be patched

context

open as a page

A root-owned systemd timer runs a script hourly on a Linux server — which ATT&CK tactic is it?

level: middleimportance: must knowfreq 56%

basics

~20 s

None can be read from the unit alone. The same timer is byte-identical whether an operator installed it to keep access, installed it to reach root, or an administrator installed it during maintenance. The tactic names the goal, and the goal is not on disk.

open as a page

A root systemd timer runs a script writable by a deploy account — which adversary goal do you remove?

level: seniorimportance: should knowfreq 42%

basics

~10 s

Remove the Privilege Escalation goal first: make nothing a lower-privileged account can write execute as root. That goal has no substitute. Persistence has many carriers, so blocking timers alone just relocates it.

open as a page

Why is Defense Evasion an ATT&CK tactic column rather than a label for any quiet action?

level: middleimportance: nice to knowfreq 33%

basics

~20 s

Defense Evasion names a goal an operator spends effort on: steps taken specifically to avoid or degrade controls. Being inconspicuous by accident is not Defense Evasion. Used as an adjective, the column tags everything and stops naming a choice.

open as a page