This HUD is an interactive map of the MITRE ATT&CK Enterprise matrix, the industry reference for adversary tactics, techniques, and procedures (TTPs). The fifteen tactics around the core represent why an adversary acts; techniques represent how.
This map is a curated teaching subset: 42 of the 222 Enterprise v19 techniques, chosen to illustrate each tactic.
New in v19 (28 Apr 2026): the old Defense Evasion tactic was split in two. Stealth keeps the TA0005 ID and covers blending in with legitimate activity; the new Defense Impairment (TA0112) covers actively breaking security controls. If you learned the 14-tactic matrix, this is the change to unlearn. It is now the reference for interviews and certification exams.
Two frameworks frequently confused. Both describe adversary progression, but they answer different questions:
• Click a tactic node for its strategic intent, an example, and the techniques it contains.
• Click a technique for platforms, observed threat actors, data sources, mitigations, and framework mappings (NIST CSF 2.0 + CIS v8).
• Query the Forensic Vault for a reference Sigma/KQL/SPL detection rule.
• Press ESC at any time to step back one level.