MITRE ATT&CK coverage, not just a compliance checkbox.
MITRE ATT&CK is a globally-used knowledge base of adversary tactics and techniques, increasingly cited inside compliance and risk programmes as evidence that detection capability is real, not assumed. grComply seeds the Enterprise matrix's 14 tactics with sample techniques, and — because it's a control-agnostic tree like every other framework in the platform — a scan finding or SIEM alert can map to a specific technique such as T1190 Exploit Public-Facing Application, showing exactly what's detected rather than a generic "we have EDR" claim.
What is MITRE ATT&CK? MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations, maintained by the MITRE Corporation. It's not a compliance framework in the traditional sense — there's no certification — but it's widely used to structure threat-informed defense and to demonstrate detection coverage inside a broader risk or compliance programme.
How grComply benefits your MITRE ATT&CK programme
Threat-informed defense, not a compliance checklist
14 Enterprise tactics as domains, techniques as controls — used to show detection coverage, not tick boxes.
Findings map to real techniques
A scan finding or SIEM alert can map to specific ATT&CK techniques — like T1190 Exploit Public-Facing Application — showing what's actually detected, not assumed.
Sub-techniques for precise coverage
Phishing (T1566) breaks into Spearphishing Attachment and Spearphishing Link, so a coverage gap is specific, not vague.
Feeds risk and control mapping, not a standalone silo
ATT&CK coverage cross-maps into NIST CSF's Detect/Protect Functions or CIS Controls, reinforcing compliance posture rather than living apart from it.
EDR and SIEM evidence types built in
Dedicated evidence categories for EDR reports and SIEM logs exist specifically for this kind of technical, tool-based proof.
A living map, versioned as MITRE updates it
ATT&CK changes yearly; framework versioning means an update doesn't silently invalidate prior coverage evidence.
Fourteen Enterprise tactics, seeded with real technique examples
Seeded from the ATT&CK Enterprise matrix — tactics as the domain layer in kill-chain order, sample techniques and sub-techniques underneath.
Reconnaissance & Resource Development
Active Scanning and Acquire Infrastructure — the earliest stages of an attack, before an adversary ever touches your environment.
Initial Access & Execution
Phishing (with Spearphishing Attachment and Spearphishing Link sub-techniques), Exploit Public-Facing Application, and Command and Scripting Interpreter.
Persistence, Privilege Escalation & Defense Evasion
Create Account, Exploitation for Privilege Escalation, and Indicator Removal — the techniques adversaries use to stay and hide.
Credential Access, Discovery & Lateral Movement
Brute Force, OS Credential Dumping, Account Discovery, and Remote Services — how an adversary expands their foothold.
Collection, Command and Control, Exfiltration & Impact
Data from Local System, Application Layer Protocol C2, Exfiltration Over C2 Channel, and Data Encrypted for Impact (ransomware).
Evidence grComply already models for MITRE ATT&CK
Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.
| Control | Evidence type | Example |
|---|---|---|
| T1566 — Phishing | Narrative document | Detection coverage narrative for phishing |
| T1190 — Exploit Public-Facing Application | WAF / IDS alert sample | Evidence of alerting for public-facing exploit attempts |
| T1003 — OS Credential Dumping | EDR report | EDR credential-dumping detection rule evidence |
| T1486 — Data Encrypted for Impact | Procedure document | Ransomware playbook / backup recovery evidence |
Why this matters: ATT&CK isn't something you get "certified" against — its value inside grComply is that a finding or alert can point at a specific technique, turning "we have detection capability" from a claim in a security questionnaire into a mapped, evidenced fact tied to real tooling.
MITRE ATT&CK, in the live workspace
The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to MITRE ATT&CK.






MITRE ATT&CK in grComply
What is MITRE ATT&CK?
MITRE ATT&CK is a globally-accessible knowledge base of real-world adversary tactics and techniques, used to structure threat-informed defense — it's a reference model, not a certifiable compliance framework.
Is MITRE ATT&CK a compliance requirement?
Not on its own — but it's increasingly referenced inside security questionnaires, risk assessments, and other frameworks as evidence of detection maturity, which is why grComply models it alongside certifiable standards.
How does grComply map findings to ATT&CK techniques?
A scan finding, SIEM alert, or EDR detection can be mapped to a specific technique (with a confidence score a human confirms), showing precisely which adversary behaviour your controls actually detect.
Does grComply cover the full ATT&CK Enterprise matrix?
The seeded structure includes all 14 Enterprise tactics with representative techniques and sub-techniques as a structural library, expandable via import for full technique-level coverage.
How does ATT&CK coverage relate to NIST CSF or CIS Controls?
Cross-framework mapping lets ATT&CK technique coverage credit an equivalent NIST CSF Detect Function subcategory or a CIS Control, so threat-informed defense reinforces rather than duplicates compliance evidence.
What evidence types are specific to MITRE ATT&CK in grComply?
EDR report and SIEM log evidence categories are modelled specifically for this kind of technical, tool-based detection proof, distinct from policy or procedure documents.
Does ATT&CK content stay current as MITRE updates it?
Yes — the same framework-versioning discipline applied to every seeded standard applies here, so an ATT&CK matrix update creates a new version rather than silently invalidating prior coverage evidence.
Who typically uses ATT&CK inside a GRC programme?
Security operations and detection engineering teams, and increasingly compliance teams responding to customer or auditor questions about detection maturity. See the full catalog on the Compliance Frameworks page.
See MITRE ATT&CK mapped into your control library
Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →
Talk to us about MITRE ATT&CK
Tell us where your MITRE ATT&CK programme stands today, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to bring MITRE ATT&CK into one control library?
We respond within one working day — or reach us instantly on WhatsApp.