MITRE ATT&CK Mapper

Search ATT&CK tactics, techniques and sub-techniques and map your detections or incident findings to them, with the framework version recorded.

Runs locally

Everything happens in your browser. What you paste or drop here is never uploaded, logged or stored.

Use the tool

From notes to techniques, with a person in the loop

Paste what happened, in your own words or copied from a report. The mapper finds explicit technique ids and Sigma attack.t#### tags, which it treats as high confidence. It also recognises about sixty curated phrases, such as "password spray", "vssadmin delete shadows" or "scheduled task", and multi-word technique names that appear verbatim. Every suggestion shows the text that triggered it. Only the explicit ones start as reviewed. Tick the ones you agree with, change the tactic when a technique spans several, and add anything it missed.

Current ATT&CK, with revocations handled

The mapper uses the ATT&CK Enterprise dataset bundled with this page; the version is shown above. A revoked technique id is replaced by its successor, with a note saying so, and a deprecated one is flagged. ATT&CK 19 split Defense Evasion into Stealth and Defense Impairment, so older mappings and tags that use defense-evasion are explained rather than silently dropped.

Export to the Navigator

The layer export follows the ATT&CK Navigator layer format, so it opens directly in the Navigator, with one entry per technique and tactic, and your evidence as the comment. Only reviewed mappings are exported unless you choose otherwise. CSV and JSON exports include the confidence and the evidence for every mapping.

Frequently asked questions

Is this an AI classifier?

No. It is deterministic: the same text always gives the same suggestions, and each shows exactly why. That makes it predictable, but a phrase it does not know will not be found - review is essential.

Are my incident notes uploaded?

No. The ATT&CK dataset is bundled with the page and matching runs in your browser. Notes never leave this tab.

Can I map to sub-techniques?

Yes. Suggestions use sub-techniques where the phrase is specific (PowerShell is T1059.001), and you can add any id directly.

References

© The MITRE Corporation. ATT&CK data is reproduced and distributed with the permission of The MITRE Corporation.

What this tool can and cannot tell you. It reports what is present in the input you provide. It cannot see anything you did not give it, and a clean result means nothing was found in that input - not that the wider system is secure.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.