Learning Hub › Deep Dives › Threat Intel & MITRE
Deep Dive 02 · Interactive guide
Threat Intelligence & MITRE ATT&CK
"Know your adversary." Cyber threat intelligence (CTI) turns raw security data into decisions: what to patch first, what to detect, what to tell the board. MITRE ATT&CK gives everyone a shared map of how attackers actually behave. This guide covers both, then lets you map a realistic intrusion onto the ATT&CK v19 matrix yourself.
Data is not intelligence
A log line is data. Context makes it information. Intelligence answers "so what, and what do we do?" for a specific reader. Click each stage.
Four levels, four audiences
The same threat produces different intelligence for different readers.
The intelligence lifecycle
Good CTI is a loop, not a feed. It starts with a question from the business and ends with feedback that sharpens the next question. Follow one worked example through all six phases.
The Pyramid of Pain
David Bianco's pyramid (2013) ranks indicators by how much pain you cause the attacker when you detect and block them. Blocking a file hash costs them seconds. Detecting their behaviour forces them to retrain. Click a level.
IOC
Indicator of Compromise
Evidence something bad already happened: a hash, an IP, a domain. Fast to share and match, quick to go stale. Bottom of the pyramid.
IOA
Indicator of Attack
Behaviour that shows an attack in progress: Word spawning PowerShell, a process reading LSASS. Harder to build, much harder to dodge. Top of the pyramid.
The MITRE ATT&CK Enterprise matrix (v19)
Tactics (columns) are the attacker's goals: the "why". Techniques (cells) are how they achieve them. Version 19 (2026) split the old Defense Evasion tactic into Stealth (hiding) and Defense Impairment (breaking your security tools), giving 15 tactics. A few representative techniques are shown per tactic; the full matrix has hundreds. Click any technique.
Pick a technique to see what it is, how to detect it and how to mitigate it.
Exercise: map the intrusion
Here is a realistic ransomware intrusion, step by step, based on patterns common in public incident reports. For each step, pick the ATT&CK tactic: what was the attacker trying to achieve? When you finish, the path lights up in the matrix above.
The Diamond Model and putting intel to work
The Diamond Model (Caltagirone, Pendergast & Betz, 2013) says every intrusion event has four corners. Find one, and you can pivot to the others. Click a corner: the examples come from the intrusion you just mapped.
From feed to detection: the operational pipeline
Intel only matters when it changes what your tools see. Click each stage.
Sources & further reading
- MITRE ATT&CK (v19)
The knowledge base of adversary tactics and techniques. See the release notes for the Defense Evasion split.
- David J. Bianco: The Pyramid of Pain
The original 2013 post.
- FIRST: Traffic Light Protocol 2.0
The official label definitions.
- OASIS: STIX 2.1 and TAXII 2.1
Specs, examples and tooling for exchanging threat intel.
- The Diamond Model of Intrusion Analysis
Caltagirone, Pendergast & Betz, 2013.
- SigmaHQ: generic detection rules
Thousands of community rules, tagged with ATT&CK IDs.
Want the live view? Active Threats tracks current advisories, and the Zero Trust deep dive shows how to shrink the blast radius when an intrusion like the one above starts.