Skip to content

MITRE Map

The catalog as an ATT&CK matrix: one column per tactic, one cell per technique, with the events that produce evidence for it. Click a technique ID for its context page, an event for its detail page, or filter the matrix by provider.

This coverage is also available as ATT&CK Navigator layers, scoring each technique by catalog event count: combined · AWS · Azure · GCP

Provider
TA0001 Initial Access 7
TA0002 Execution 20
TA0003 Persistence 79
T1053 Scheduled Task/Job
T1525 Implant Internal Image
TA0004 Privilege Escalation 67
T1546 Event Triggered Execution
TA0005 Stealth 16
TA0112 Defense Impairment 75
T1484.002 Trust Modification
T1578 Modify Cloud Compute Infrastructure
TA0006 Credential Access 26
TA0007 Discovery 3
TA0008 Lateral Movement 19
TA0009 Collection 25
TA0010 Exfiltration 24
TA0040 Impact 37