Course Overview

MITRE ATT&CK has become a globally recognized knowledge base for understanding how real-world adversaries plan, execute, and sustain cyber-attacks. Instead of focusing only on compliance, it provides a behavior-driven view of threats, helping security teams strengthen detection, response, and defense strategies. This course equips learners with the practical ability to use the ATT&CK framework for threat intelligence, detection engineering, and security operations across modern enterprise environments.

This course begins with an introduction to MITRE ATT&CK, its history, terminology, and how it compares with traditional frameworks like NIST and ISO 27001. It then covers the cyber-attack lifecycle and the Cyber Kill Chain, followed by using ATT&CK for threat intelligence, adversary profiling, and navigating attack.mitre.org. You will learn to map logs and telemetry to ATT&CK techniques, build portable detections using Sigma and YARA, and transform raw data into actionable threat reports. The course also explores ATT&CK Navigator for analysis, visualization, coverage mapping, and SOC maturity assessment. It further introduces active defense concepts using MITRE SHIELD and ENGAGE, before moving into advanced applications like Cyber Analytics Repository, threat hunting, and Active Directory attack techniques.

By the end, you will apply MITRE ATT&CK for threat intelligence, detection engineering, defense planning, and threat hunting with hands-on skills to strengthen organizational security operations.

What You Will Learn

  • Learn everything about the Cyber Kill Chain, as well as how to perform threat intelligence using MITRE ATT&CK.
  • Learn how to map data to ATT&CK and how to implement small and highly portable detection tests mapped to the MITRE ATT&CK.
  • Learn how to use the MITRE ATT&CK Matrix.
  • Learn how to work with MITRE SHIELD and how to generate defensive recommendations with SHIELD.
  • Know how to install and set up MITRE Caldera, the automated cyber adversary emulation system, and how to perform Atomic Red Team tests for MITRE ATT&CK.

Program Curriculum

  • Introduction to MITRE ATT&CK
  • Understanding the Cyber Attack Lifecycle
  • Introduction to Cyber Kill Chain
  • Chapter 1 Quiz

  • Introduction to Threat Intelligence
  • Using MITRE ATT&CK for Threat Intelligence
  • Introduction to attack.mitre.org
  • Understanding ATT&CK Matrices
  • Chapter 2 Quiz

  • Mapping Data to MITRE ATT&CK
  • Creating Portable Detection Tests
  • Raw Data vs. Finished Threat Reports
  • Chapter 3 Quiz

  • Using MITRE ATT&CK for Analysis
  • Using MITRE ATT&CK Navigator
  • Using MITRE ATT&CK Navigator for Analysis
  • Key MITRE ATT&CK Use Cases
  • Chapter 4 Quiz

  • Concept of Active Defense
  • Using MITRE ATT&CK for Defense Strategy
  • Working with MITRE SHIELD/ENGAGE
  • Defensive Recommendations with SHIELD
  • Chapter 5 Quiz

  • Implementing MITRE Cyber Analytics Repository (CAR)
  • Threat Hunting with MITRE ATT&CK
  • TTPs for Active Directory Attacks
  • Chapter 6 Quiz
Load more modules

Instructor

Abdul Mateen

Abdul Mateen is a seasoned Cyber Threat Intelligence Analyst and Information Security Trainer. His professional experience brings over 1,500 hours of hands-on training experience, having successfully trained more than 2,800 students through both in-person and online sessions. With a strong foundation in threat analysis and response, Abdul Mateen

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50