List ATT&CK domainsList the three ATT&CK knowledge bases MITRE publishes — Enterprise, Mobile and ICS — with what each one covers. Every other action takes one of these as its domain.
Get domain detailsRead which ATT&CK release a domain is on, when it was published, and how much it holds: techniques, tactics, groups, software, campaigns, mitigations and detection strategies. Run it to check for a new release before anything else.
List tacticsList a domain's tactics — the adversary goals that make up the columns of the matrix — in the matrix's own order, with how many techniques sit under each.
Get a tacticRead one tactic and every technique filed under it: the whole column of the matrix in one step.
List techniquesBrowse a domain's techniques by tactic, platform, technique level and free text, ordered and paged. Every macOS technique under Credential Access is one step.
Get a techniqueRead one technique in full, with its parent and sub-techniques, and the mitigations, detection strategies, groups, software and campaigns linked to it — each with MITRE's procedure example.
Search ATT&CKSearch a whole domain for a word, name, alias or ATT&CK ID across every kind of entry at once, best matches first, with each result saying which fields it matched on.
List groupsList the adversary groups ATT&CK tracks, each with every name it is known by — the vendor aliases a report is far more likely to use than G0016.
Get a groupRead one adversary group and, with related objects included, the techniques they use, the malware and tools they deploy, and the campaigns attributed to them.
List softwareList the malware and tools ATT&CK tracks, filtered to one or the other, narrowed by platform, and searched by name or alias.
Get softwareRead one piece of malware or tooling, with the techniques it implements and the groups and campaigns observed deploying it.
List mitigationsList the mitigations ATT&CK recommends: the defensive measures its techniques are mapped to.
Get a mitigationRead one mitigation and every technique it defends against, turning a control you already run into the adversary behaviour it covers.
List campaignsList the intrusion campaigns ATT&CK tracks, with when each was first and last reported active.
Get a campaignRead one campaign: what happened, when it ran, the group it is attributed to, and the techniques and software it used.
List data componentsList the telemetry ATT&CK expects detections to be built on, each with the concrete logs it can be read from, down to the channel. Filter to one log source to see what your existing collection can detect.
List related objectsWalk the relationships around any ATT&CK entry in both directions, grouped by how they are linked — which groups use a technique, what mitigates it, what a piece of malware does.
List recent changesList what a domain gained or revised after a date and time: the new techniques, newly tracked groups and revised entries of the latest release.
Get raw STIX objectRead one entry exactly as MITRE publishes it — the whole STIX 2.1 object — with the date the collection took it in and every version it holds.
Export techniques as CSVWrite a filtered technique list out as CSV, one row per technique with its ATT&CK ID, name, tactics, platforms, parent and description.