Adversary Tactics & Techniques
Walk through all 12 ATT&CK tactic phases as the attacker — from reconnaissance to impact. Understand how real APTs operate and how defenders detect each phase using the industry-standard adversary framework.
Certificate Paths
These stages map to Network+, Security+, ISC² CC, and CySA+ exam domains →
This module references MITRE ATT&CK® content. MITRE ATT&CK® is a registered trademark of The MITRE Corporation. Content is based on ATT&CK® knowledge base, licensed under CC BY 4.0. Learn more ↗CC BY 4.0
MITRE Corporation HQ
The Intelligence Gathering
Dark Web Infrastructure
The Arsenal Builder
RSA Conference
The First Foothold
NSA
The Code Runner
Mandiant HQ
The Squatter
SolarWinds HQ
The Crown Grabber
CrowdStrike HQ
The Ghost
NotPetya Attack
The Key Thief
Colonial Pipeline HQ
The Spreader
APT29 Operations
The Cartographer
Equifax HQ
The Data Smuggler
Kaseya VSA Attack
The Detonator