MITRE anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

MITRE Corporation

  • MITRE Corporation โ€” US not-for-profit. Operates FFRDCs for US government.
  • MITRE Center for Threat-Informed Defense โ€” community-funded center driving ATT&CK and related work.

Frameworks and resources

  • ATT&CK โ€” attack.mitre.org
  • D3FEND โ€” d3fend.mitre.org
  • ATLAS โ€” atlas.mitre.org
  • CWE (Common Weakness Enumeration) โ€” cwe.mitre.org
  • CVE (Common Vulnerabilities and Exposures) โ€” cve.org (MITRE-hosted)
  • STIX / TAXII โ€” threat intelligence sharing standards (MITRE-developed)
  • ATT&CK Navigator โ€” visualization tool for ATT&CK matrices

Community and adopters

  • Major SIEM/EDR/XDR vendors map products to ATT&CK: CrowdStrike, SentinelOne, Microsoft Defender, Splunk, Sentinel, Elastic, Palo Alto Cortex, others.
  • Threat intel vendors tag indicators: Mandiant, Recorded Future, Crowdstrike, others.
  • National cybersecurity agencies use ATT&CK: CISA (US), NCSC (UK), ANSSI (FR), BSI (DE), others.
  • Red team firms report against ATT&CK.

ATLAS contributors

  • MITRE primary author.
  • Microsoft, Bosch, IBM, NVIDIA, Anthropic, OpenAI among contributing organizations.
  • NIST CSF 2.0 โ€” high-level functions cross-reference ATT&CK.
  • NIST 800-53 controls can be mapped to D3FEND.
  • OWASP LLM Top 10 โ€” application-level AI security; complementary to ATLAS.
  • CWE โ€” software weakness taxonomy (also MITRE).
  • CAPEC โ€” Common Attack Pattern Enumeration and Classification (MITRE).

Reference resources

  • attack.mitre.org/resources โ€” official ATT&CK resources.
  • MITRE Engenuity โ€” non-profit for community engagement.
  • ATT&CK Evaluations โ€” vendor product evaluations against ATT&CK.

See also