Missiora
MITRE ATT&CK Explained (for Interviews)

Cyber Security Careers

MITRE ATT&CK Explained (for Interviews)

3 min readPublished 22 Jul 2026

MITRE ATT&CK is one of the most talked-about frameworks in cyber security interviews, particularly for defensive roles. If you can explain it clearly and show how you would use it, you stand out. This guide gives you an interview-ready understanding.

What is MITRE ATT&CK?

MITRE ATT&CK is a free, globally-recognised knowledge base of real-world adversary behaviour, organised as tactics (the attacker's goal — the "why") and techniques (how they achieve it — the "how"). For example, the tactic Credential Access includes techniques like Brute Force and Kerberoasting. It is built from observed attacks, which makes it practical rather than theoretical.

Tactics, techniques and procedures (TTPs)

  • Tactics are the columns of the ATT&CK matrix: Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defence Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact.
  • Techniques (and sub-techniques) sit under each tactic and describe specific behaviours, each with a T-number (e.g. T1110 Brute Force).
  • Procedures are the specific implementations a given threat actor uses.

How SOC analysts use ATT&CK

  • Mapping alerts to techniques so you understand what stage of an attack you are seeing.
  • Finding detection gaps — which techniques you can and cannot currently detect.
  • Threat hunting — hypothesising which techniques an adversary might use and searching for evidence.
  • Communicating clearly — a shared vocabulary across the team and with stakeholders.

Common interview questions

  • What is MITRE ATT&CK and how would you use it day to day?
  • Give an example of a technique and how you would detect it. For instance, T1059 (Command and Scripting Interpreter) via process-creation logging.
  • How does ATT&CK differ from the Cyber Kill Chain? The Kill Chain is a linear, high-level model; ATT&CK is a detailed, non-linear matrix of behaviours.
  • What is ATT&CK Navigator? A tool for visualising coverage and gaps.

How to prepare

Learn the tactics in order, pick two or three techniques you can discuss in depth, and be ready to link each to a detection idea. This ties directly into SOC analyst interview questions and the broader cyber security interview guide.

Rehearse these under realistic pressure with AI Interview™, decode a specific vacancy with Job Intelligence™, close any gaps with Career Coach, and evidence your progress in your Career Passport™.

How to talk about ATT&CK in an interview

Don't just define it — show how you'd use it. Strong answers connect tactics and techniques to real detection: "I'd map our alerts to ATT&CK techniques to find coverage gaps — for example, if we detect T1059 (Command and Scripting Interpreter) but not the credential-access techniques that usually precede it." Interviewers want to see the framework as a practical tool for detection engineering and threat-informed defence, not a memorised glossary.

A practical use case

Explain how a SOC uses ATT&CK to prioritise: overlay recent threat-intel on the matrix, identify which techniques matter most for your sector, and check detection coverage for each. This ties neatly to SIEM detection and the broader cyber security interview.

Frequently asked questions

What is MITRE ATT&CK in simple terms?

It is a free knowledge base of how real attackers behave, organised into tactics (their goals) and techniques (how they achieve them). Defenders use it to map alerts, find detection gaps and guide threat hunting.

What is the difference between MITRE ATT&CK and the Cyber Kill Chain?

The Cyber Kill Chain is a linear, high-level model of an attack's stages. MITRE ATT&CK is a detailed, non-linear matrix of specific attacker behaviours (techniques) grouped by tactic, built from observed real-world attacks.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.