Pith. sign in

REVIEW 3 cited by

SoK: The MITRE ATT&CK Framework in Research and Practice

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2304.07411 v1 pith:K2TOYHFT submitted 2023-04-14 cs.CR

classification cs.CR
keywords researchapplicationsworkframeworkindustryliteraturemitresystematization
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The MITRE ATT&CK framework, a comprehensive knowledge base of adversary tactics and techniques, has been widely adopted by the cybersecurity industry as well as by academic researchers. Its broad range of industry applications include threat intelligence, threat detection, and incident response, some of which go beyond what it was originally designed for. Despite its popularity, there is a lack of a systematic review of the applications and the research on ATT&CK. This systematization of work aims to fill this gap. To this end, it introduces the first taxonomic systematization of the research literature on ATT&CK, studies its degree of usefulness in different applications, and identifies important gaps and discrepancies in the literature to identify key directions for future work. The results of this work provide valuable insights for academics and practitioners alike, highlighting the need for more research on the practical implementation and evaluation of ATT&CK.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Quantifying Loss Aversion in Cyber Adversaries via LLM Analysis

    cs.CR 2025-08 conditional novelty 6.0 of 10

    Using LLM-annotated operator notes from 17 hackers, the authors report a borderline negative correlation between general risk propensity and persistence technique use, but the overall model does not reach significance.

  2. Can LLMs Hack Enterprise Networks? Autonomous Assumed Breach Penetration-Testing Active Directory Networks

    cs.CR 2025-02 conditional novelty 6.0 of 10

    An autonomous LLM-driven agent can compromise accounts in a realistic Active Directory testbed, with reasoning models outperforming non-reasoning ones at competitive cost.

  3. Automated Repeatable Adversary Threat Emulation with Effects Language (EL)

    cs.CR 2025-10 conditional novelty 5.0 of 10

    A graph-based visual coordination language with formal execution semantics is used to automate and repeat adversary threat emulation and to produce proof-of-attack traces.

Pith tools