---
title: "MITRE ATT&CK Enterprise"
description: "Explore 866 MITRE ATT&CK categories and example usages separating ransomware persistence, exfiltration and operational impact across major cyber incidents."
url: "https://nosible.com/ontologies/mitre-attack"
---

[Home](https://nosible.com/) [Ontologies](https://nosible.com/ontologies) MITRE ATT&CK

Ontology field guide

By NOSIBLE Research

Updated 2026-07-18

# MITRE ATT&CK Enterprise

MITRE ATT&CK separates reported cyber operations by objective, technique and implementation detail across an attack sequence.

Cyber incidents are not interchangeable. Credential theft, persistence, lateral movement, command and control, exfiltration and operational impact describe different parts of an intrusion. ATT&CK provides a common hierarchy. Tactics state why an adversary acts. Techniques state how. Sub-techniques add implementation detail. [[ 1 ]](https://attack.mitre.org/resources/) [[ 2 ]](https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf)

World applies Enterprise ATT&CK to event reporting. Researchers can test whether technique mix improves incident triage, vendor-risk estimates or market-response models beyond a generic cyber-event flag. This guide provides the hierarchy, World coverage, three example usages and downloadable observations. [[ 4 ]](https://www.sec.gov/rules-regulations/2023/07/s7-09-22) [[ 5 ]](https://doi.org/10.1016/j.jfineco.2019.05.019) [[ 6 ]](https://doi.org/10.3386/w28906)

Categories 866 categories Structure 3 levels World events labelled 9.7% Stable codes Since v1 Release data CC0

On this page [01 Foundations](https://nosible.com/ontologies/mitre-attack#foundations) [02 Categories](https://nosible.com/ontologies/mitre-attack#vocabulary) [03 Example usages](https://nosible.com/ontologies/mitre-attack#trends) [04 Downloads and references](https://nosible.com/ontologies/mitre-attack#downloads)

Foundations

## ATT&CK classifies observed behaviour without measuring severity or attacker capability

Enterprise ATT&CK organises observed adversary behaviour into tactics, techniques and sub-techniques. A tactic is an operational goal. A technique is a method used to reach that goal. A sub-technique is a more specific method. ATT&CK is maintained from documented real-world observations across known operations. [[ 1 ]](https://attack.mitre.org/resources/) [[ 2 ]](https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf)

World classifies the behaviour described in an event record. It does not verify an attack, reconstruct the complete attack chain or infer attacker skill. A deeper path can mean that reporting contains more implementation detail. It does not prove that the attacker was more capable or the attack more damaging. [[ 1 ]](https://attack.mitre.org/resources/)

Categories

## ATT&CK maps 866 attack categories across tactics, techniques and sub-techniques

World uses Enterprise ATT&CK v16.1 with 14 tactic roots, 866 path-specific categories, 731 leaves and a maximum depth of two. Techniques can appear under several tactics because one method can serve several goals. The explorer preserves each path, definition and World count for direct comparison across phases. [[ 2 ]](https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf)

Search code, label, definition or path

14 shown · 866 total

Labelled events

**1,488,001**

World coverage

**9.7%**

All World events

**15,311,040**

1,488,001 of 15,311,040 World events carry labels from MITRE ATT&CK Enterprise. Select a category to see its count and both relevant shares.

Hierarchy

tactic / technique / subtechnique

+

Execution Code or command execution on a target system · 14 children

+

Collection Data gathered before theft or use · 17 children

+

Persistence Methods used to retain access · 20 children

+

Privilege Escalation Methods used to gain higher permissions · 14 children

+

Credential Access Passwords, tokens and authentication material · 17 children

+

Discovery Mapping systems and network structure · 32 children

+

Resource Development Infrastructure, accounts and capabilities prepared before access · 8 children

+

Reconnaissance Target selection and pre-operation information gathering · 10 children

+

Defense Evasion Methods used to avoid detection · 44 children

+

Initial Access Methods used to enter a target environment · 10 children

+

Impact Disruption, destruction or financial theft · 14 children

+

Lateral Movement Movement between systems · 9 children

+

Command and Control Communication with compromised systems · 18 children

+

Exfiltration Data removed from the target · 9 children

Execution

### Execution

Copy link

#### Definition

Adversaries execute code or commands on target systems.

Potential research use

Code or command execution on a target system

Code Execution Events with label 46,109 Share of labelled 3.1% Share of World 0.3%

**Events with label** is the selected count. **Label share** divides it by 1,488,001 assigned events; **World share** divides it by all 15,311,040 events.

#### Representative World V1.2 events

One strong classified example per available year, with up to ten years shown.

10 examples

1. 2015-07-07HSBC Fires Six Staff Over Mock ISIS Execution Video in BirminghamCoverage 88
2. 2016-05-20Oklahoma Grand Jury Condemns Careless Execution Drug Mix-UpCoverage 32
3. 2017-02-28Critical ESET Antivirus Flaw Enables Mac Remote Code ExecutionCoverage 16
4. 2019-06-22Iran Executes Former Defense Contractor for Alleged CIA SpyingCoverage 39
5. 2020-07-12Federal Execution Prep Worker Tests Positive for CoronavirusCoverage 19
6. 2021-02-02Alabama Faces COVID-19 Execution Risks for SmithCoverage 53
7. 2022-11-16Death Penalty Execution Workers Face Secret Toll and Political ShiftsCoverage 317
8. 2024-10-28Iran Executes German-Iranian Dissident Jamshid Sharmahd on Terrorism ChargesCoverage 159
9. 2025-05-08South Carolina Botched Firing Squad Execution Causes Extreme PainCoverage 89
10. 2026-06-25British Influencer Faces Execution in Dubai for Alleged Murder of PartnerCoverage 96

Browse categories to compare definitions, World V1.2 statistics and representative classified events.

Example usage 1 of 3

### Example Usage: Three cyber incidents clearly expose different operational and financial risk channels

SolarWinds, MOVEit and Change Healthcare are major cyber incidents, but their ATT&CK profiles differ. Entry preparation accounts for 60% of SolarWinds tactic assignments. Exfiltration reaches 20% for MOVEit. Impact accounts for 63% of Change Healthcare assignments after the ransomware disruption affected payment and claims infrastructure. [[ 3 ]](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a) [[ 7 ]](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a) [[ 8 ]](https://www.unitedhealthgroup.com/ns/changehealthcare.html)

These three incidents create different exposure maps. SolarWinds shows software and credential risk. MOVEit shows stolen-data liability. Change Healthcare shows operational cash flow and service disruption. ATT&CK separates these mechanisms before tests of suppliers, customers, insurers, spreads, revisions and incident duration across firms and time. [[ 1 ]](https://attack.mitre.org/resources/) [[ 5 ]](https://doi.org/10.1016/j.jfineco.2019.05.019) [[ 6 ]](https://doi.org/10.3386/w28906)

SolarWinds

**60% entry preparation**

MOVEit

**20% exfiltration**

Change Healthcare

**63% impact**

**Three cyber incidents expose different operational risk channels**

share of ATT&CK tactic assignments

**SolarWinds**

third-party access · n= 114

60 %

38 %

**MOVEit**

data theft · n= 55

13 %

27 %

20 %

27 %

13 %

**Change Healthcare**

operational disruption · n= 73

10 %

63 %

27 %

Entry preparation

Command and control

Exfiltration

Impact

Other tactics

Each fixed English cohort requires an explicit incident name. The chart pools all ATT&CK tactic assignments inside the stated study windows. Entry preparation combines Reconnaissance, Resource Development and Initial Access. It describes classified reporting, not confirmed attack paths, losses or attacker capability.

Example usage 2 of 3

### Example Usage: Ransomware impact fades quickly in 2017 but persists after Change Healthcare

WannaCry and NotPetya create sharp Impact-classified reporting spikes in 2017. Their seven-day normalized rates peak at 1,644 and 883 events per million, then return to zero within 30 days. Change Healthcare peaks later at 536 per million and remains elevated 60 days after the February 2024 disruption. [[ 9 ]](https://www.cisa.gov/news-events/alerts/2017/05/12/indicators-associated-wannacry-ransomware) [[ 10 ]](https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a)

Peak attention alone misses the difference. A fast global malware wave and a persistent payment-system outage create different cash-flow, counterparty and operational-risk windows. ATT&CK's Impact tactic provides a common behavioural denominator for comparing incident duration without raw coverage or generic cyber keywords. [[ 11 ]](https://www.unitedhealthgroup.com/ns/changehealthcare.html)

Change day 60 +143 per million WannaCry peak +1,644 per million

Seven-day normalized ATT&CK Impact rate by event day · per million

Change Healthcare

WannaCry

NotPetya

Each line aligns a fixed English incident cohort to public disclosure day. Counts assigned to the ATT&CK Impact tactic are pooled across the current and prior six days, divided by all English World events in the same window and plotted from event day -14 to +60.

Example usage 3 of 3

### Example Usage: MOVEit reporting shifts from command traffic into exfiltration and operational impact

MOVEit reporting changes after the initial vulnerability disclosure. Command and Control dominates the first month. Exfiltration rises from 4.8% to 23.8% during the follow-on period, while Transfer Data to Cloud Account reaches 19.1%. The classified focus moves from exploit communication toward stolen-data handling and transfer paths. [[ 7 ]](https://www.cisa.gov/sites/default/files/2023-06/aa23-158a-stopransomware-cl0p-ransomware-gang-exploits-moveit-vulnerability_2.pdf)

That shift changes the financial question. Vulnerability disclosure concerns immediate exposure and remediation. Exfiltration creates notification, litigation, customer and insurance liabilities that can surface later. ATT&CK supplies the transition clock, starting exposed-company tests when reported behaviour changes rather than at the initial breach headline or disclosure before data theft appears across exposed firms. [[ 8 ]](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

Exfiltration +19.0pp Transfer to cloud +14.3pp Global baseline +0.2pp Normalized coverage -243 per million

Fifty-six-day pooled share of ATT&CK tactic assignments · %

Exfiltration

Command and Control

Impact

The fixed English MOVEit cohort contains 21 ATT&CK-assigned events from 31 May to 30 June 2023 and 34 from July through December. The chart shows 15 June through 31 August. Lines pool tactic counts across the current and prior 55 days, then divide by all tactic assignments in the same window.

Data and sources

## Download MITRE ATT&CK and References

### Downloads

Download categories and counts as CSV, or the complete machine-readable release as JSON.

[**CSV** Definitions and counts Download ↓](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/nodes.csv)

[**JSON** Full machine-readable release Download ↓](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/statistics.json)

Release details and citation files

[Manifest](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/manifest.json) [Release README](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/README.md) [CC0 license and scope](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/LICENSE.md) [Citation file](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/CITATION.cff) [Changelog](https://nosible.com/data/world-v1.2/ontologies/mitre-attack/v1/CHANGELOG.md)

Need the complete World event schema? [Open the World data dictionary.](https://nosible.com/data-dictionaries#world)

### References

1. [ 1 ][MITRE. ATT&CK: Get Started. Enterprise ATT&CK knowledge base and usage guidance.](https://attack.mitre.org/resources/)
2. [ 2 ][Strom, B. E. et al. (2020). The Design and Philosophy of MITRE ATT&CK. MITRE Technical Report MP180360R1.](https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf)
3. [ 3 ][Cybersecurity and Infrastructure Security Agency. (2020). Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations.](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-352a)
4. [ 4 ][U.S. Securities and Exchange Commission. (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure. Release 33-11216.](https://www.sec.gov/rules-regulations/2023/07/s7-09-22)
5. [ 5 ][Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719-749.](https://doi.org/10.1016/j.jfineco.2019.05.019)
6. [ 6 ][Jamilov, R., Rey, H., & Tahoun, A. (2025). The Anatomy of Cyber Risk. NBER Working Paper 28906, revised December 2025.](https://doi.org/10.3386/w28906)
7. [ 7 ][Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. (2023). CL0P ransomware gang exploits MOVEit vulnerability.](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a)
8. [ 11 ][UnitedHealth Group. (2024). Change Healthcare cyber response and restoration updates.](https://www.unitedhealthgroup.com/ns/changehealthcare.html)
9. [ 9 ][Cybersecurity and Infrastructure Security Agency. (2017). Indicators associated with WannaCry ransomware.](https://www.cisa.gov/news-events/alerts/2017/05/12/indicators-associated-wannacry-ransomware)
10. [ 10 ][Cybersecurity and Infrastructure Security Agency. (2017). Petya ransomware technical alert.](https://www.cisa.gov/news-events/cybersecurity-advisories/aa17-181a)
11. [ 7 ][Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. (2023). CL0P ransomware gang exploits MOVEit vulnerability.](https://www.cisa.gov/sites/default/files/2023-06/aa23-158a-stopransomware-cl0p-ransomware-gang-exploits-moveit-vulnerability_2.pdf)
12. [ 8 ][Cybersecurity and Infrastructure Security Agency. Known Exploited Vulnerabilities catalog.](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

Continue exploring

## Complementary ontologies

[416 categories NOSIBLE Event Ontology Follow attack behavior into outages, lawsuits, fraud, remediation and other corporate consequences. Explore ontology →](https://nosible.com/ontologies/nosible-events)

[237 categories GICS Industry Classification Measure which industries carry the greatest exposure to specific attack tactics and techniques. Explore ontology →](https://nosible.com/ontologies/gics)

> Explore 866 MITRE ATT&CK categories and example usages separating ransomware persistence, exfiltration and operational impact across major cyber incidents.

**URL:** https://nosible.com/ontologies/mitre-attack
