
MITRE ATT&CK
Map the Adversary's Playbook
Solve logic puzzles that teach you to map adversary behavior to MITRE ATT&CK techniques. Learn to think like a defender — identify coverage gaps, connect the dots, and see the full picture.
Guided by The Cartographer
What it is
MITRE ATT&CK, defined
MITRE ATT&CK is the shared language of adversary behavior — a framework that classifies what attackers do into tactics, techniques, and sub-techniques. Mapping activity to ATT&CK is how defenders measure coverage, brief a response, and talk about threats without talking past each other.
The career
A skill you get hired for
You can't defend what you don't understand. Mapping the adversary's playbook to ATT&CK is how teams see what's coming next and where their coverage has holes.
Builds toward
Threat Intelligence Analyst
Typical salary
$120K/yr avg
Market demand
500K+ open US roles
Who you'd work alongside
- Threat intelligence analysts
- Detection engineers mapping coverage
- Purple teams and adversary emulation
- SOC leads doing gap analysis and reporting
The DefendTheOrg approach
How you'll learn it
Under The Cartographer — who contributed to ATT&CK before most teams knew it existed — you work scenarios that tell real attack stories and map each step to the framework:
Stories, not flashcards
Every mapping connects to a narrative — what the attacker was trying to achieve and why they chose that move — reflecting real campaigns and APT behavior.
Tactic → technique → sub-technique
You build precision as you climb the tiers, from naming the tactic to pinning the exact sub-technique.
Sequence matters
Real attacks have an order. You learn to lay the techniques out in the sequence they actually happened.
Stuck? Get walked through it.
Every Easy and Medium lab has a walkthrough from The Cartographer — one hint at a time, with a chance to try each step yourself before the answer. You get three a week, and using one never touches your score. It teaches the reasoning, not the solution.
Try it yourself
A taste of the real lab
This is a simplified, no-signup slice of a MITRE ATT&CK lab — make your call and see how it's graded. The real labs go deeper.
Map the attack to ATT&CK
Three steps of one intrusion — match each to the correct technique.
A finance user opens an invoice attachment; a macro runs.
The macro spawns PowerShell with an encoded command.
It writes a Run key so it launches at every logon.
Push yourself
Where Hard and Expert labs take you
Every skill scales from your first lab to genuinely hard reasoning. Difficulty isn't a bigger wall — it's deeper thinking.
Hard
Hard labs require technique and sub-technique precision, and your mappings must be ordered in attack sequence — scored half on the right selections, half on the right order.
Expert
Expert labs remove the guardrails: full ATT&CK depth, any number of mappings, and all-or-nothing scoring — you need the correct selections AND the correct order to pass.
Start mitre att&ck training
Hands-on labs built from real engagement data. Learn by doing — guided by The Cartographer.