---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# MITRE-ATT\&CK framework overview

# MITRE-ATT\&CK framework overview {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 min. de leitura

The MITRE-ATT\&CK framework is a knowledge base of common tactics,
techniques, and procedures (TTP) that your organization can access to develop specific threat
models and methodologies against cyberattacks.

## Overview {#about-mitre-attack__section_gmv_kxr_tnb}

The MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT\&CK)
framework documents and tracks various adversarial techniques that are used during different
stages of a cyberattack.

By using the MITRE-ATT\&CK framework's knowledge base, the
cyberthreat intelligence community can quickly identify threats and coordinate cyberattack
responses.{#about-mitre-attack__p_v2q_dfz_xnb}

## MITRE-ATT\&CK and Security
Operations {#about-mitre-attack__section_vhp_vxx_xnb}

See the following diagram to learn how the MITRE-ATT\&CK
information flows with Security Operations applications.  
* The [pre-loaded TAXII client](https://servicenow-prod.fluidtopics.net/xg52lX94BZD3qpqUTW0IEg "Activate the MITRE-ATT&CK profile, and set up a scheduled job so that you can set up MITRE-ATT&CK collections for threat detection in your organization.") connects to the TAXII server to ingest the [data
  collections](https://servicenow-prod.fluidtopics.net/rbLNoqo8gfPe9w6zsgyY6Q "Manage the matrices that have been imported from the MITRE TAXII collections. Matrices are a collection of tactics and techniques. You can view the matrices to review if your collections are available in the MITRE-ATT&CK repository.") to Threat Intelligence.
* Existing [Security
  Information and Event Manager (SIEM) integrations](https://servicenow-prod.fluidtopics.net/XsPwHlYjG~1z8q8gVLMF4A#auto-extract-technique-rules "Use the base system auto-extraction rules to import the MITRE-ATT&CK information from any existing third-party integrations.") ingest their threat data (alerts and events), with relevant TTPs and are [associated with security
  incidents](https://servicenow-prod.fluidtopics.net/5XC5i1TU7IPszBOxDO7nxg#associate-mitre-with-sir "Associate the MITRE-ATT&CK tactics and techniques to the security incident for better security incident and threat analysis.").
* When an [IoC is
  associated to a security incident](https://servicenow-prod.fluidtopics.net/Ps0LyrplA8TCR~ulg1zVkw "Associate MITRE-ATT&CK tactics and techniques to an observable for better security incident and threat analysis at a granular level."), Threat Intelligence automatically searches threat feeds for relevant information and sends IoCs to third-party sources such as EDR, Sandbox, or TIP for additional analysis.
* If any third-party source contains the MITRE-ATT\&CK information, then [Threat Intelligence extracts the technique information](https://servicenow-prod.fluidtopics.net/SZhmVVNdHVmzAYl2oCsSXw "Create detection rules and map them against the tactics and techniques. With this mapping, you can see the coverage for the detection rules in your organization.") and enriches the data in the Threat Intelligence repository for correlation and analysis.
* MITRE-ATT\&CK also shares [CVE context
  information](https://servicenow-prod.fluidtopics.net/NqBC1kkhFYwHlGsn3gvBHQ#advanced-heatmap-and-navigator-features "You can use a heat map with advanced filters to perform an analysis by correlating security incidents with MITRE-ATT&CK information.") for each technique. Your security team can review the exploited techniques in Vulnerability Response to determine if your business-critical assets are threatened.
{#about-mitre-attack__ul_erz_r1y_xnb}

## MITRE-ATT\&CK matrices, tactics, and techniques {#about-mitre-attack__section_cyg_zqr_tnb}

The core of the MITRE-ATT\&CK framework is a matrix of adversary tactics and techniques. The sequence of the tactics represents what an adversary is trying to accomplish at the stage of an incident. When your security team understands this sequence, you have an opportunity to anticipate an adversary's next move and break the kill chain. ATT\&CK consists of the following matrices:

* Enterprise ATT\&CK: Describes the behaviors and actions that an adversary takes to compromise and operate in an enterprise network and cloud.  
  Nota:  
  The Pre ATT\&CK matrix has been deprecated by MITRE and is merged with the Enterprise matrix.
* ICS ATT\&CK: Describes the actions that an adversary takes while operating within an Industrial Control Systems (ICS) network.
* Mobile ATT\&CK: Describes the adversary behaviors and actions that focus on mobile devices.
{#about-mitre-attack__ul_m4c_j2c_znb}

Tactics represent the why of an ATT\&CK technique. It is the adversary's tactical
objective for performing an action.

Techniques represent how an adversary achieves a tactical objective by performing an
action.

Techniques may be associated with more than one tactic. For example, Access Token
Manipulation is used by an adversary to achieve either the tactic of Privilege Escalation or
Defense Evasion.

## Using an intent-based approach for incident responses {#about-mitre-attack__section_bz5_vvx_xnb}

An intent-based response uses a dynamic and contextual kill chain framework that can help
your organization to correlate security incidents and to identify a large scope of attacks.
Your security team can use an intent-based response to understand how the organization is
being attacked and what the attacker might do next. This type of response enables you to
predict an attacker's behavior so that you can focus your resources effectively.

Using Security Incident Response, your security team can manage the life cycle of each
security incident from analysis to containment by focusing on indicators of compromise
(IOCs) like IP addresses, file hashes, and domains.

By integrating Security Incident Response with the MITRE-ATT\&CK framework,
security incidents are handled as links in a larger enterprise-wide attack.

## How your organization can benefit from MITRE-ATT\&CK in Security Operations {#about-mitre-attack__section_ilp_p5x_xnb}

Using the MITRE-ATT\&CK framework can help your organization do the
following:

* Equip security analysts with MITRE-ATT\&CK tactics, techniques, and procedures (TTPs) to better analyze and respond to security incidents.
* Automate the incident workflows using the playbook for detecting and containing threats in the context of the MITRE-ATT\&CK framework.
* Prioritize indicators of compromise and threat hunting with MITRE-ATT\&CK information.
* Understand the high-level security posture of your organization in the context of the MITRE-ATT\&CK framework.
{#about-mitre-attack__ul_xjv_hpx_xnb}
* **[MITRE-ATT\&CK administration](https://servicenow-prod.fluidtopics.net/Y9nbTYdnv4qWjggxu0D75g)**   
  You can set up, map data sources, map overall technique detection coverage, and maintain the MITRE-ATT\&CK repository in the ServiceNow AI Platform.
* **[Using MITRE-ATT\&CK to detect and analyze threats](https://servicenow-prod.fluidtopics.net/XiK8RYd1GCOM~i9JkSF5AQ)**   
  Use the MITRE-ATT\&CK framework across the Threat Intelligence and the SIR module to detect and analyze threats to your organization.

**Conceitos relacionados**   

* [Understanding Threat Intelligence](https://servicenow-prod.fluidtopics.net/wnkIRx9~PzuNijr5Dll6dg "The Threat Intelligence application allows you to access and provide a point of reference for your company's Structured Threat Information Expression (STIX) data. Included in Threat Intelligence is the Security Case Management application, which provides a means for analyzing threats to your organization posed by targeted campaigns or state actors.")
* [Set up Threat Intelligence](https://servicenow-prod.fluidtopics.net/sfMp70weBwCOyElcZDpN_w#c_GetStartedWithThreatIntel "Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.")
* [IoC Repository](https://servicenow-prod.fluidtopics.net/TErerwQZq8Il39pwj7OvLQ "IoC repository contains STIX objects, each of these objects contain a specific piece of information.")
* [MITRE D3FEND framework](https://servicenow-prod.fluidtopics.net/JBfoHfw9axvfkN0abb1GEw "MITRE D3FEND is a knowledge graph of cybersecurity countermeasure techniques that complements the MITRE-ATT&CK framework by providing defensive techniques.")
* [Threat Intelligence integrations](https://servicenow-prod.fluidtopics.net/Z0pFC1Jt12TL_zv3l~VRLA "The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.")
* [Threat Intelligence Orchestration](https://servicenow-prod.fluidtopics.net/xBwCUSrsJDHQhjKUmHEdpw "Threat Intelligence Orchestration activities allow users to determine whether a threat has been seen before in other security incidents or on other systems using workflow orchestration.")
* [Security Case Management](https://servicenow-prod.fluidtopics.net/8~oSpKYVRK_sT~Mn6MYIEQ "Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.")  
**Referência relacionada**   

* [Threat Intelligence administration](https://servicenow-prod.fluidtopics.net/vHi5VenfgqKflmfc9AP5Vw "The Threat Intelligence base system is ready to use on activation. You can add records to certain modules in the Administration application menu, but most are already populated with industry-standard information.")

