⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · Threat-informed defense reference

MITRE ATT&CK coverage, not just a compliance checkbox.

MITRE ATT&CK is a globally-used knowledge base of adversary tactics and techniques, increasingly cited inside compliance and risk programmes as evidence that detection capability is real, not assumed. grComply seeds the Enterprise matrix's 14 tactics with sample techniques, and — because it's a control-agnostic tree like every other framework in the platform — a scan finding or SIEM alert can map to a specific technique such as T1190 Exploit Public-Facing Application, showing exactly what's detected rather than a generic "we have EDR" claim.

14 Enterprise tactics · sample techniques — findings map to specific techniques, not a generic claim.
Back to all frameworks WhatsApp us
14Enterprise tactics
2024ATT&CK version seeded
Threat-informedNot a certification
StructuralSeed depth

What is MITRE ATT&CK? MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations, maintained by the MITRE Corporation. It's not a compliance framework in the traditional sense — there's no certification — but it's widely used to structure threat-informed defense and to demonstrate detection coverage inside a broader risk or compliance programme.

Why it's different

How grComply benefits your MITRE ATT&CK programme

Threat-informed defense, not a compliance checklist

14 Enterprise tactics as domains, techniques as controls — used to show detection coverage, not tick boxes.

Findings map to real techniques

A scan finding or SIEM alert can map to specific ATT&CK techniques — like T1190 Exploit Public-Facing Application — showing what's actually detected, not assumed.

Sub-techniques for precise coverage

Phishing (T1566) breaks into Spearphishing Attachment and Spearphishing Link, so a coverage gap is specific, not vague.

Feeds risk and control mapping, not a standalone silo

ATT&CK coverage cross-maps into NIST CSF's Detect/Protect Functions or CIS Controls, reinforcing compliance posture rather than living apart from it.

EDR and SIEM evidence types built in

Dedicated evidence categories for EDR reports and SIEM logs exist specifically for this kind of technical, tool-based proof.

A living map, versioned as MITRE updates it

ATT&CK changes yearly; framework versioning means an update doesn't silently invalidate prior coverage evidence.

Structure

Fourteen Enterprise tactics, seeded with real technique examples

Seeded from the ATT&CK Enterprise matrix — tactics as the domain layer in kill-chain order, sample techniques and sub-techniques underneath.

Reconnaissance & Resource Development

Active Scanning and Acquire Infrastructure — the earliest stages of an attack, before an adversary ever touches your environment.

Initial Access & Execution

Phishing (with Spearphishing Attachment and Spearphishing Link sub-techniques), Exploit Public-Facing Application, and Command and Scripting Interpreter.

Persistence, Privilege Escalation & Defense Evasion

Create Account, Exploitation for Privilege Escalation, and Indicator Removal — the techniques adversaries use to stay and hide.

Credential Access, Discovery & Lateral Movement

Brute Force, OS Credential Dumping, Account Discovery, and Remote Services — how an adversary expands their foothold.

Collection, Command and Control, Exfiltration & Impact

Data from Local System, Application Layer Protocol C2, Exfiltration Over C2 Channel, and Data Encrypted for Impact (ransomware).

Evidence, mapped

Evidence grComply already models for MITRE ATT&CK

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
T1566 — PhishingNarrative documentDetection coverage narrative for phishing
T1190 — Exploit Public-Facing ApplicationWAF / IDS alert sampleEvidence of alerting for public-facing exploit attempts
T1003 — OS Credential DumpingEDR reportEDR credential-dumping detection rule evidence
T1486 — Data Encrypted for ImpactProcedure documentRansomware playbook / backup recovery evidence

Why this matters: ATT&CK isn't something you get "certified" against — its value inside grComply is that a finding or alert can point at a specific technique, turning "we have detection capability" from a claim in a security questionnaire into a mapped, evidenced fact tied to real tooling.

Product screens

MITRE ATT&CK, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to MITRE ATT&CK.

FAQ

MITRE ATT&CK in grComply

What is MITRE ATT&CK?

MITRE ATT&CK is a globally-accessible knowledge base of real-world adversary tactics and techniques, used to structure threat-informed defense — it's a reference model, not a certifiable compliance framework.

Is MITRE ATT&CK a compliance requirement?

Not on its own — but it's increasingly referenced inside security questionnaires, risk assessments, and other frameworks as evidence of detection maturity, which is why grComply models it alongside certifiable standards.

How does grComply map findings to ATT&CK techniques?

A scan finding, SIEM alert, or EDR detection can be mapped to a specific technique (with a confidence score a human confirms), showing precisely which adversary behaviour your controls actually detect.

Does grComply cover the full ATT&CK Enterprise matrix?

The seeded structure includes all 14 Enterprise tactics with representative techniques and sub-techniques as a structural library, expandable via import for full technique-level coverage.

How does ATT&CK coverage relate to NIST CSF or CIS Controls?

Cross-framework mapping lets ATT&CK technique coverage credit an equivalent NIST CSF Detect Function subcategory or a CIS Control, so threat-informed defense reinforces rather than duplicates compliance evidence.

What evidence types are specific to MITRE ATT&CK in grComply?

EDR report and SIEM log evidence categories are modelled specifically for this kind of technical, tool-based detection proof, distinct from policy or procedure documents.

Does ATT&CK content stay current as MITRE updates it?

Yes — the same framework-versioning discipline applied to every seeded standard applies here, so an ATT&CK matrix update creates a new version rather than silently invalidating prior coverage evidence.

Who typically uses ATT&CK inside a GRC programme?

Security operations and detection engineering teams, and increasingly compliance teams responding to customer or auditor questions about detection maturity. See the full catalog on the Compliance Frameworks page.

See MITRE ATT&CK mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about MITRE ATT&CK

Tell us where your MITRE ATT&CK programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring MITRE ATT&CK into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us