b2KIT

MITRE ATT&CK Navigator

Interactive MITRE ATT&CK matrix viewer. Map techniques to tactics, highlight coverage, and export layer files.

Tested tool guide Tested browser tools Checked August 16, 2026

What MITRE ATT&CK Navigator does and how it behaves

MITRE ATT&CK Navigator presents ATT&CK tactics as matrix columns and their associated techniques as selectable entries. Use the layer to mark techniques, visually distinguish coverage or findings, and export those selections for later review or sharing. The most important interpretive detail is that a technique can appear under more than one tactic. Those placements represent different tactical contexts for the same technique, not separate techniques or evidence that the actions occurred in that order.

How the result is produced

1

Matrix mapping

The viewer places ATT&CK techniques beneath the tactics to which MITRE associates them. Technique identifiers such as T1059 identify parent techniques, while dotted identifiers such as T1059.001 identify sub-techniques. Selecting or highlighting a matrix entry creates an analyst-defined view of relevant ATT&CK concepts. It does not establish that the technique was observed, tested, detected, or prevented.

2

Layer export

An exported Navigator layer preserves technique identifiers and the layer's visual selections so the mapping can be reopened or exchanged as a layer. The layer is an annotation over an ATT&CK matrix, not a complete copy of the ATT&CK knowledge base. Technique descriptions, relationships, and other supporting intelligence still depend on the ATT&CK release used to interpret the layer.

Good uses

  • Mark the ATT&CK techniques addressed by a set of detection rules, then inspect tactics or technique families where the documented detection coverage is sparse.
  • Translate techniques identified during an incident investigation into a matrix layer that responders and threat analysts can review without reducing the findings to an unstructured list of IDs.
  • Compare the scope of a purple-team exercise, threat assessment, or security-control review against the ATT&CK matrix and export the resulting technique map as a reusable artifact.

Limits and checks

  • Treat a highlight as a claim made by the layer author. The matrix does not verify that a control detects or blocks the technique, and it does not measure the quality of supporting evidence.
  • Check whether a marked identifier is a parent technique or a dotted sub-technique. Coverage assigned only to a parent should not automatically be interpreted as coverage of every sub-technique beneath it.
  • Confirm the ATT&CK domain and version associated with a shared layer. Techniques can be added, changed, deprecated, or mapped differently between ATT&CK releases, so an older layer may not match the matrix currently being reviewed.

Common questions

Does highlighting a technique mean my organization is protected against it?

No. A highlight records how the layer author classified that technique. It may mean detected, tested, observed, prioritized, or merely in scope, depending on the layer's stated convention. The Navigator does not inspect hosts, logs, alerts, or network traffic. Document the meaning of the highlighting and retain evidence outside the matrix.

Can the matrix show the chronological order of an attack?

No. ATT&CK tactic columns organize techniques by adversary objective, not by timestamp or a guaranteed execution sequence. A technique may support several tactics, and real activity can revisit objectives or occur in a different order. Use an incident timeline or attack-flow representation when sequence and dependencies are the question being investigated.

References and verification

The behavioral notes were checked against the browser implementation. Standards and primary references below define the relevant format, formula, or platform behavior.

Related Tools