> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/getting-started/attack-lifecycle/mitre-att-and-ck.md).

# MITRE ATT\&CK

The most popular and widely-used framework today is probably that of MITRE ATT\&CK

* A knowledge base of behaviour and taxonomy reflecting the various phases of an adversary's attack lifecycle.
* ATT\&CK focuses on how adversaries interact with sytems during an operation and the platforms they are known to target.

\
Popular tools provided by MITRE are:

* Navigator  - [click](https://mitre-attack.github.io/attack-navigator/)
* Workbench - [click](https://github.com/mitre-attack/attack-workbench-frontend)
* STIX database - [click](https://github.com/mitre-attack/attack-stix-data)&#x20;

{% embed url="<https://attack.mitre.org/resources/attack-data-and-tools/>" %}
