Definition · External Attack Surface Management

What is MITRE ATT&CK?

ATT&CK — Adversarial Tactics, Techniques, and Common Knowledge — is maintained by MITRE, a US not-for-profit that operates federally funded research centres. It documents what attackers actually do, drawn from public reporting of real intrusions, and gives each behaviour a stable identifier so that defenders, vendors and threat intelligence reports can refer to the same thing.

How it is organised

Behaviour is arranged into matrices for different technology domains, including Enterprise, Mobile and ICS. Within a matrix:

  • Tactics are the attacker’s goals, such as Reconnaissance, Initial Access, Persistence or Exfiltration
  • Techniques are the ways a tactic is achieved, each with an identifier such as T1190, Exploit Public-Facing Application
  • Sub-techniques break a technique into more specific variants
  • Groups and software pages map named threat actors and tooling to the techniques they have been observed using

Coverage is descriptive, not predictive: a technique appears because it has been seen and reported, and the model is revised as reporting accumulates.

The parts that touch your external attack surface

Two tactics sit largely outside the perimeter. Reconnaissance covers work an attacker does before touching anything privileged — active scanning, gathering victim host and network information, and searching open technical databases, which is the same OSINT and passive DNS material available to anyone. Resource Development covers infrastructure an attacker prepares, including lookalike domains used for typosquatting.

Initial Access is where external exposure becomes entry: exploiting a public-facing application, abusing external remote services such as a VPN gateway or RDP, and phishing. Reducing what is reachable narrows that column directly — see attack surface reduction.

ATT&CK describes adversary behaviour; CVE identifies specific flaws, the KEV catalogue records which are being exploited, and the OWASP Top Ten groups classes of software weakness. Red teams commonly use ATT&CK to plan and report exercises.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.