MITRE ATT&CK
termsecurity
The public knowledge base that catalogues what attackers actually do, organised as tactics (the goal: initial access, persistence, exfiltration) and techniques (the method), each with observed procedures and the groups seen using them.
ATT&CK replaced a decade of vague vendor vocabulary with shared identifiers, so a detection engineer, a red team and a report can all point at the same T-number and mean the same thing. Its two failure modes are worth naming: coverage theatre, where an organisation counts techniques it has a rule for and calls that a security programme, and the assumption that the matrix is exhaustive - it catalogues what has been observed and written down, which is not the same as everything possible.
Also known as: attack framework, att&ck matrix, tactics techniques procedures matrix