ATT&CK technique heat map
Which MITRE ATT&CK techniques are most observed across the global threat actor catalog. Rolled up by tactic, ranked by the number of distinct actors known to use the technique. Sub-techniques fold into their parent.
Loading heat map…
How to read the heat map
Each cell counts distinct threat actors associated with a MITRE ATT&CK technique, not the number of reports that mention it. This keeps heavily reported groups from dominating the ranking. Choose an industry to narrow the actor set, then open a technique to review the actors behind the count.
Use the common-technique view to plan broad detection coverage. Use the initial-access view to prioritize controls around exposed services, stolen credentials, phishing, and other techniques adversaries use to enter an environment.