Incident responders frequently need ways to describe attacks and incidents using common language and terminology. Attack frameworks are used to understand adversaries, document techniques, and categorise tactics. ## MITRE ATT&CK [[MITRE]] provides the **ATT&CK**, or Adversarial Tactics, Techniques, and Common Knowledge knowledge-base of adversary tactics and techniques. The ATT&CK matrices includes detailed descriptions, definitions, and examples for the complete threat life cycle from reconnaissance through execution, persistence, privilege escalation, and impact. At each level, *it lists techniques and components, allowing threat assessment modelling* to leverage common descriptions and knowledge. ATT&CK matrices include pre-attack, enterprise matrices focusing on Windows, macOS, Linux, and cloud computing, as well as iOS and Android mobile platforms. It also includes details of data sources, threat actor groups, software, and a host of other useful details. All of this adds up to make ATT&CK the most comprehensive freely available database of adversary techniques, tactics, and related information that the authors of this book are aware of. >[!tip] > In addition to the ATT&CK framework, the [Diamond Model](https://apps.dtic.mil/sti/pdfs/ADA586960.pdf) and Lockheed Martin's [Cyber Kill Chain](https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/Gaining_the_Advantage_Cyber_Kill_Chain.pdf) are sometimes used by organisations.