Views: 3
Getting More Out of MITRE ATT&CK in Threat Modelling
MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is an openly available knowledge base describing how cyber adversaries behave. The MITRE Corporation maintains it. Organisations use it to understand how attacks progress and to build defences that match real attacker behaviour.
The framework is a matrix. Tactics are the high-level objectives an attacker pursues, and techniques are the concrete methods used to achieve them. Every technique has descriptions, examples, and mitigations, which together show how threat actors operate and what tooling they rely on.
A Worked Example: Exploit Public-Facing Application
The best way to understand ATT&CK is to open a technique page. Take Exploit Public-Facing Application (T1190). Every technique page follows the same five-part layout.
1. Technique name and details
The header block records the technique ID (T1190), notes that it has no sub-techniques, and places it under the Initial Access tactic. It lists the relevant platforms (Containers, IaaS, Linux, Network, Windows, macOS), the contributors, the version (2.4), and the creation and last-modified dates (April 2018 and April 2023).
The description explains that attackers target a weakness in an Internet-facing host or system to get their first foothold in a network. That weakness might be a software bug, a temporary glitch, or a misconfiguration. Typical targets include:
- Websites and web servers
- Databases such as SQL
- Standard services such as SMB or SSH
- Network device management protocols such as SNMP and Smart Install
- Any other system with an open, Internet-accessible socket
Depending on the flaw, the exploitation can also tie into Exploitation for Defense Evasion. In cloud or containerised environments, compromising the application can lead to the underlying instance or container. From there an attacker may reach cloud or container APIs, escape to the host, or abuse weak identity and access management policies. Edge network devices and appliances that lack strong host-based defences are also in scope. For web applications and databases, the page points to the OWASP Top 10 and CWE Top 25 as the lists of most common weaknesses.
2. Procedure examples
This section shows how real groups have used the technique:
| Group | How they used it |
|---|---|
| APT28 (G0007) | Exploited Microsoft Exchange flaws (CVE-2020-0688 and CVE-2020-17144) and ran SQL injection against external websites |
| APT29 (G0016) | Exploited Citrix (CVE-2019-19781), Pulse Secure VPN (CVE-2019-11510), FortiGate VPN (CVE-2018-13379), and Zimbra (CVE-2019-9670) |
| APT39 (G0087) | Used SQL injection to gain initial compromise |
3. Mitigations
Six mitigations are listed:
| ID | Mitigation | What it means |
|---|---|---|
| M1048 | Application Isolation and Sandboxing | Limits what an exploited application can reach on the rest of the system |
| M1050 | Exploit Protection | Web application firewalls can keep exploit traffic from reaching the application |
| M1030 | Network Segmentation | Place externally facing services in a DMZ or on separate hosting infrastructure |
| M1026 | Privileged Account Management | Run service accounts with least privilege so a compromised process gets little access |
| M1051 | Update Software | Keep externally exposed applications patched through regular patch management |
| M1016 | Vulnerability Scanning | Scan external systems regularly and patch quickly when critical flaws are found, whether via scanning or public disclosure |
4. Detections
The page is candid that detecting software exploitation can be hard. Exploits may fail, or they may leave the targeted process unstable or crashed, so the signals are not always clean. Two data sources help:
- Application logs (DS0015): Web application firewalls may flag malformed or improper inputs that attempt exploitation.
- Network traffic content (DS0029): Deep packet inspection can look for exploit artefacts such as SQL injection strings or known payloads.
5. References
The final section collects outside material for further reading. For this technique it includes vulnerability database entries, advisories on state-sponsored actors targeting network infrastructure, and reports on incidents such as the exploitation of Microsoft Exchange zero-days.
Reading a technique page like this gives you insight into the specific methods an adversary uses. Applying the listed mitigations and detection ideas can then strengthen your overall security posture.

Plugging ATT&CK into Your Threat Modelling Process
ATT&CK slots into threat modelling by linking the threats and vulnerabilities you have identified to the framework’s tactics and techniques. The change to your methodology is one added step directly after “Identify Threats”:
- Identify Threats. Work out which threats could affect your assets, including cyber attacks, physical attacks, social engineering, and insider threats.
- Map to MITRE ATT&CK. Connect each identified threat to the matching tactics and techniques. For every technique you map, read its page (description, procedure examples, mitigations, and detection strategies) to understand more deeply what the threat means for your system.
Doing this gives you a more complete view of potential threats and makes it easier to apply the right countermeasures, which lowers your organisation’s overall risk.
Other Ways to Use ATT&CK
Threat modelling is one use among several. Depending on your needs, consider these three:
Identifying likely attack paths. Starting from your own infrastructure, the framework can map the routes an attacker might use to compromise you. If your organisation uses Office 365, for example, every technique attributed to that platform is relevant to your threat modelling.
Developing threat scenarios. ATT&CK attributes its tactics and techniques to known threat groups. You can use this to assess your organisation against the groups that are known to target your industry.
Prioritising vulnerability remediation. Each technique’s documentation helps you gauge how serious the impact could be if you suffered a similar attack. Your security team can use that to decide which vulnerabilities are most critical to fix first.
These examples are not exhaustive. How you use the framework is your decision.
Next Step
To refine the process further, the next step is to use and practice ATT&CK Navigator to map the identified threats.

![Using MITRE ATT&CK Navigator to Strengthen Threat Modelling [PART: I]](https://i0.wp.com/netwerklabs.com/wp-content/uploads/2026/10/Cybersecurity-War-Room_-ATTCK-Navigator.png?fit=2048%2C768&ssl=1)