Ontology field guide
By NOSIBLE Research
MITRE ATT&CK Enterprise
MITRE ATT&CK separates reported cyber operations by objective, technique and implementation detail across an attack sequence.
Cyber incidents are not interchangeable. Credential theft, persistence, lateral movement, command and control, exfiltration and operational impact describe different parts of an intrusion. ATT&CK provides a common hierarchy. Tactics state why an adversary acts. Techniques state how. Sub-techniques add implementation detail.[1][2]
World applies Enterprise ATT&CK to event reporting. Researchers can test whether technique mix improves incident triage, vendor-risk estimates or market-response models beyond a generic cyber-event flag. This guide provides the hierarchy, World coverage, three example usages and downloadable observations.[4][5][6]
- Categories
- 866 categories
- Structure
- 3 levels
- World events labelled
- 9.7%
- Stable codes
- Since v1
- Release data
- CC0
Foundations
ATT&CK classifies observed behaviour without measuring severity or attacker capability
Enterprise ATT&CK organises observed adversary behaviour into tactics, techniques and sub-techniques. A tactic is an operational goal. A technique is a method used to reach that goal. A sub-technique is a more specific method. ATT&CK is maintained from documented real-world observations across known operations.[1][2]
World classifies the behaviour described in an event record. It does not verify an attack, reconstruct the complete attack chain or infer attacker skill. A deeper path can mean that reporting contains more implementation detail. It does not prove that the attacker was more capable or the attack more damaging.[1]
Categories
ATT&CK maps 866 attack categories across tactics, techniques and sub-techniques
World uses Enterprise ATT&CK v16.1 with 14 tactic roots, 866 path-specific categories, 731 leaves and a maximum depth of two. Techniques can appear under several tactics because one method can serve several goals. The explorer preserves each path, definition and World count for direct comparison across phases.[2]
1,488,001 of 15,311,040 World events carry labels from MITRE ATT&CK Enterprise. Select a category to see its count and both relevant shares.
Execution
Execution
Definition
Adversaries execute code or commands on target systems.
Potential research use
Code or command execution on a target system
- Code
- Execution
- Events with label
- 46,109
- Share of labelled
- 3.1%
- Share of World
- 0.3%
Events with label is the selected count. Label share divides it by 1,488,001 assigned events; World share divides it by all 15,311,040 events.
Representative World V1.2 events
One strong classified example per available year, with up to ten years shown.
HSBC Fires Six Staff Over Mock ISIS Execution Video in Birmingham
Coverage 88Oklahoma Grand Jury Condemns Careless Execution Drug Mix-Up
Coverage 32Critical ESET Antivirus Flaw Enables Mac Remote Code Execution
Coverage 16Iran Executes Former Defense Contractor for Alleged CIA Spying
Coverage 39Federal Execution Prep Worker Tests Positive for Coronavirus
Coverage 19Alabama Faces COVID-19 Execution Risks for Smith
Coverage 53Death Penalty Execution Workers Face Secret Toll and Political Shifts
Coverage 317Iran Executes German-Iranian Dissident Jamshid Sharmahd on Terrorism Charges
Coverage 159South Carolina Botched Firing Squad Execution Causes Extreme Pain
Coverage 89British Influencer Faces Execution in Dubai for Alleged Murder of Partner
Coverage 96
Browse categories to compare definitions, World V1.2 statistics and representative classified events.
Example usage 1 of 3
Example Usage: Three cyber incidents clearly expose different operational and financial risk channels
SolarWinds, MOVEit and Change Healthcare are major cyber incidents, but their ATT&CK profiles differ. Entry preparation accounts for 60% of SolarWinds tactic assignments. Exfiltration reaches 20% for MOVEit. Impact accounts for 63% of Change Healthcare assignments after the ransomware disruption affected payment and claims infrastructure.[3][7][8]
These three incidents create different exposure maps. SolarWinds shows software and credential risk. MOVEit shows stolen-data liability. Change Healthcare shows operational cash flow and service disruption. ATT&CK separates these mechanisms before tests of suppliers, customers, insurers, spreads, revisions and incident duration across firms and time.[1][5][6]
Each fixed English cohort requires an explicit incident name. The chart pools all ATT&CK tactic assignments inside the stated study windows. Entry preparation combines Reconnaissance, Resource Development and Initial Access. It describes classified reporting, not confirmed attack paths, losses or attacker capability.
Example usage 2 of 3
Example Usage: Ransomware impact fades quickly in 2017 but persists after Change Healthcare
WannaCry and NotPetya create sharp Impact-classified reporting spikes in 2017. Their seven-day normalized rates peak at 1,644 and 883 events per million, then return to zero within 30 days. Change Healthcare peaks later at 536 per million and remains elevated 60 days after the February 2024 disruption.[9][10]
Peak attention alone misses the difference. A fast global malware wave and a persistent payment-system outage create different cash-flow, counterparty and operational-risk windows. ATT&CK's Impact tactic provides a common behavioural denominator for comparing incident duration without raw coverage or generic cyber keywords.[11]
- Change day 60
- +143 per million
- WannaCry peak
- +1,644 per million
Each line aligns a fixed English incident cohort to public disclosure day. Counts assigned to the ATT&CK Impact tactic are pooled across the current and prior six days, divided by all English World events in the same window and plotted from event day -14 to +60.
Example usage 3 of 3
Example Usage: MOVEit reporting shifts from command traffic into exfiltration and operational impact
MOVEit reporting changes after the initial vulnerability disclosure. Command and Control dominates the first month. Exfiltration rises from 4.8% to 23.8% during the follow-on period, while Transfer Data to Cloud Account reaches 19.1%. The classified focus moves from exploit communication toward stolen-data handling and transfer paths.[7]
That shift changes the financial question. Vulnerability disclosure concerns immediate exposure and remediation. Exfiltration creates notification, litigation, customer and insurance liabilities that can surface later. ATT&CK supplies the transition clock, starting exposed-company tests when reported behaviour changes rather than at the initial breach headline or disclosure before data theft appears across exposed firms.[8]
- Exfiltration
- +19.0pp
- Transfer to cloud
- +14.3pp
- Global baseline
- +0.2pp
- Normalized coverage
- -243 per million
The fixed English MOVEit cohort contains 21 ATT&CK-assigned events from 31 May to 30 June 2023 and 34 from July through December. The chart shows 15 June through 31 August. Lines pool tactic counts across the current and prior 55 days, then divide by all tactic assignments in the same window.
Data and sources
Download MITRE ATT&CK and References
Downloads
Download categories and counts as CSV, or the complete machine-readable release as JSON.
Release details and citation files
ManifestRelease READMECC0 license and scopeCitation fileChangelog
Need the complete World event schema? Open the World data dictionary.
References
- [1]MITRE. ATT&CK: Get Started. Enterprise ATT&CK knowledge base and usage guidance.
- [2]Strom, B. E. et al. (2020). The Design and Philosophy of MITRE ATT&CK. MITRE Technical Report MP180360R1.
- [3]Cybersecurity and Infrastructure Security Agency. (2020). Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations.
- [4]U.S. Securities and Exchange Commission. (2023). Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure. Release 33-11216.
- [5]Kamiya, S., Kang, J.-K., Kim, J., Milidonis, A., & Stulz, R. M. (2021). Risk management, firm reputation, and the impact of successful cyberattacks on target firms. Journal of Financial Economics, 139(3), 719-749.
- [6]Jamilov, R., Rey, H., & Tahoun, A. (2025). The Anatomy of Cyber Risk. NBER Working Paper 28906, revised December 2025.
- [7]Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. (2023). CL0P ransomware gang exploits MOVEit vulnerability.
- [11]UnitedHealth Group. (2024). Change Healthcare cyber response and restoration updates.
- [9]Cybersecurity and Infrastructure Security Agency. (2017). Indicators associated with WannaCry ransomware.
- [10]Cybersecurity and Infrastructure Security Agency. (2017). Petya ransomware technical alert.
- [7]Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation. (2023). CL0P ransomware gang exploits MOVEit vulnerability.
- [8]Cybersecurity and Infrastructure Security Agency. Known Exploited Vulnerabilities catalog.
Continue exploring
Complementary ontologies
416 categories
NOSIBLE Event Ontology
Follow attack behavior into outages, lawsuits, fraud, remediation and other corporate consequences.
Explore ontology →
237 categories
GICS Industry Classification
Measure which industries carry the greatest exposure to specific attack tactics and techniques.
Explore ontology →