skip to content

The Catalogue's Missing Fields

No technique in ATT&CK carries a severity, a likelihood or a frequency, so the matrix cannot tell you what to do first. Interviewers ask because teams quietly use it as a risk register anyway.

on this pageshow

explore

questions

4

In MITRE ATT&CK, which field on a technique page tells you how severe that technique is?

level: juniorimportance: must knowfreq 58%

answer

  1. look for the score column
  2. descriptive catalogue, not a register
  3. IDs, tactics, platforms, procedures, mitigations
  4. no severity, likelihood, frequency, impact

basics

~20 s

None does. An ATT&CK technique page carries an ID, tactics, platforms, procedure examples, mitigations, detection notes and data components, but no severity, likelihood, frequency or impact score. Severity is a property of your estate, not of the technique.

solid answer

~50 s

None of them, because no such field exists. An ATT&CK technique page is descriptive: technique identifier and tactic, the platforms it applies to, procedure examples drawn from published intrusions, mitigations named as control classes, detection guidance, and the data components that would record the behaviour. There is no severity, no likelihood, no frequency count and no impact magnitude anywhere in the schema. A few Impact-tactic techniques carry an `Impact Type` label such as Availability or Integrity, but that names the *kind* of effect, not how bad it is. So when someone hands you a ranked technique list and says ATT&CK produced it, the ranking came from somewhere else: an assumption about who is attacking, and a fact about the estate being attacked. The catalogue can tell you a technique exists and has been used. It cannot tell you it matters to you.

code

text · 11 lines
text
T1558.003   Kerberoasting            (sub-technique of T1558)
  Tactic:               Credential Access
  Platforms:            Windows
  Permissions Required: User
  Description:          <prose: what the behaviour is>
  Procedure examples:   <named intrusion sets and software, unweighted>
  Mitigations:          <named control classes, each with an M#### id>
  Detection / data components: <what would record it>
  Version, created, last modified

  --- no severity, likelihood, frequency or impact-magnitude field exists ---

go deeper

for a junior

Be ready to say plainly that no severity, likelihood or frequency field exists, and to name what the page does carry: identifier, tactic, platforms, procedure examples, mitigations, detection guidance and data components.

for a middle

Explain why the schema omits it. The same behaviour has different consequences in different estates, so a single stored number would be wrong for nearly every reader, and inclusion rests on published evidence rather than importance.

for a senior

Show where teams silently invent the missing field, usually by sorting on procedure-example count or tactic name, and describe how you make the imported assumption explicit instead of laundering it through the framework.

for a principal

Own the reporting consequence. Any technique ranking your organisation publishes is a judgement about one estate under one adversary assumption; it must be attributed as such and revisited when the estate changes, never presented as the framework's verdict.

## What is actually on the page An ATT&CK Enterprise technique page has a fixed shape, and it is worth reciting because the recitation is the answer. At the top: the technique identifier (for example `T1558.003`), whether it is a sub-technique and of which parent, the tactic or tactics the behaviour can serve, the platforms it applies to, and on many techniques a `Permissions Required` value. Then a prose description of the behaviour itself. Then **procedure examples** — named intrusion sets and software that have been *publicly reported* using it. Then **mitigations**, each a named control class carrying an `M####` identifier. Then detection guidance and the data components that would record the behaviour. Then version and modification metadata. Read that list again and notice the absence. There is no severity. No likelihood. No probability. No frequency count. No impact magnitude. No score of any kind, and no ordering between techniques. ATT&CK is a catalogue of adversary behaviour, not a risk register. ## Why the omission is deliberate, not an oversight The same technique has wildly different consequences in different places. `T1078` Valid Accounts against a lab domain with four users and against an identity provider federating three hundred applications is the same behaviour and two entirely different outcomes. Any severity number stored on the page would therefore be wrong for almost every reader. The only place the number can honestly live is in the estate that is consuming the catalogue. The inclusion criterion reinforces this. A technique earns a page by having been observed and published in real-world use. That is an **evidence test**, not an importance test. Nothing about being catalogued asserts that a behaviour is common, dangerous, or relevant to you. ## The four things people mistake for a score **Procedure-example count.** A page with forty named examples is not forty times more likely than a page with two. The count measures publication and attribution: heavily reported crews inflate it, and behaviour used quietly, or used against estates that never published anything, is under-evidenced. Sorting by this count imports a reporting bias and calls it frequency. **Tactic membership.** "It sits under Impact, so it is critical." Tactic names the adversary's goal at that moment, not the size of the consequence. Estates are lost entirely through Credential Access, with nothing under Impact ever executed. **Impact Type.** Some Impact-tactic techniques carry an `Impact Type` label such as Availability or Integrity. That is a category of effect. It has no magnitude attached and cannot be compared across techniques as if it were a rating. **Mitigation count.** A short mitigations list usually means the behaviour abuses legitimate system functionality, so preventive controls at the technique level do not apply. It is not a difficulty score, and a long list is not a reassurance. ## What this means when you are handed a ranked list Every ordered technique list in existence was produced by combining the catalogue with two things the catalogue does not contain: an assumed adversary, and a specific estate. That is fine, and it is the normal way the framework is used. What is not fine is presenting the result as the framework's output. "ATT&CK says these are our top ten" is a sentence about a field that does not exist; "we ranked these ten for our estate assuming this kind of adversary" is the same work, honestly attributed, and it can be argued with. ## What the catalogue does buy you Shared identifiers over behaviour. `T1558.003` means the same thing to your architect, to a vendor's write-up and to the report you are reading over someone's shoulder, in a way that "the Kerberos ticket thing" never will. That precision is the product. Confusing *we can name it exactly* with *we know how bad it is* is the specific error this question is designed to surface, and it is a very easy one to make, because a page that is this structured looks like it ought to have a score on it.

  • Does the number of procedure examples on a technique page work as a frequency field?
    No. It counts published, attributed reports, so it tracks how well studied and how loudly reported a behaviour is, not how often it happens. Techniques used by quiet operators, or against estates that never publish, stay thin forever. Sorting a list by that count is sorting by other people's disclosure habits.
  • A technique sits under the Impact tactic. Does that make it more severe than a Discovery technique?
    No. Tactic names what the adversary was trying to achieve at that step, not the size of the loss. Plenty of total compromises never execute anything under Impact, and a Discovery technique that reveals one delegated right can be the step that decides the whole intrusion.
  • If the catalogue has no severity, where does a ranked technique list come from?
    From two things you supply: an assumption about the adversary you expect, and facts about your own estate — what exists, what is exposed, and what a given behaviour would actually reach. The catalogue supplies the names and the descriptions; the ordering is entirely yours, and should be labelled as yours.

A field guide to birds tells you which species exist and how to recognise each one. It does not tell you which one is about to ruin your crop. That depends entirely on what you happen to be growing.

saying these in an interview costs you the question

  • Claims a technique's tactic implies its severity
  • Reads the procedure-example count as a frequency field
  • Believes ATT&CK ships a default technique ranking
  • Treats Impact Type as a magnitude rather than a category
  • Says the catalogue told them what their top risks are

context

open as a page

Two teams order the same 30 ATT&CK techniques differently. Which one misread the catalogue?

level: middleimportance: should knowfreq 45%

basics

~20 s

Probably neither. ATT&CK stores no ordering, so both lists were built from assumptions the teams brought with them: who they expect to face, and what their estate exposes. Compare the assumptions, not the two lists.

open as a page

ATT&CK lists mitigations for a technique and your estate implements all of them. Is it handled?

level: seniorimportance: should knowfreq 42%

basics

~20 s

No. The mitigations section is an unordered list of general control classes, not a specification and not a completeness claim. Some techniques carry an explicit note that preventive controls cannot mitigate them, because they abuse legitimate functionality.

open as a page

Your Active Directory has one host with unconstrained delegation. How does that reorder ATT&CK techniques?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

It promotes a thinly evidenced technique over a heavily evidenced one. A host trusted for unconstrained delegation caches the Kerberos ticket of whatever authenticates to it, so coercing a privileged account there reaches the directory in one step.

open as a page