MITRE ATT&CK · Blog
The MITRE ATT&CK most people are learning was retired in October 2025.
What v18 and v19 changed, and how to read the framework now.
Last week someone messaged me asking a simple question: what should they read to understand MITRE ATT&CK properly, beyond my blog posts and the matrix?
I started typing a list. Then I stopped, because the honest answer is that most of what they would find teaches a version of ATT&CK that no longer exists.
What changed
On 28 October 2025, v18 was released, in which MITRE removed the Detections field and retired Data Sources entirely [1], [2]. Two new object types replaced them. A Detection Strategy describes the adversary behaviour you are trying to catch. It points to Analytics, which are written for one platform each and link to named log sources, which now live directly on Data Components rather than as separate objects [2].

MITRE ATT&CK prior to the change
The reason being the old guidance was too vague to act on. One sentence of detection advice had to cover Windows, Linux, cloud and containers at once, and it usually resolved to something like "use Sysmon" [2].
Then v19 landed on 28 April 2026 and moved the layer above it. Defense Evasion was retired as a tactic and split into Stealth, which inherited TA0005, and Defense Impairment [3], [4]. Stealth covers blending in. Defense Impairment covers switching your controls off.

MITRE ATT&CK v19
What that looks like on one technique
Open T1078, Valid Accounts, the technique behind most of the intrusions you might have read about this year.
Under Tactics it now says Stealth. The description below it still says Defense Evasion, because the prose has not caught up with the restructure yet [5]. I read that page twice before I trusted what I was seeing.

Scroll down and there is no detection paragraph. There is one Detection Strategy, DET0560, Detection of Valid Account Abuse Across Platforms, and it fans out into five analytics [5], [6]:
| Analytic | Platform | What it reads |
|---|---|---|
| AN1543 | Windows | Anomalous logon patterns, abnormal logon types, inconsistent geography or timing |
| AN1544 | Linux | SSH logins, sudo and su abuse, service account anomalies |
| AN1545 | Cross-platform | Interactive and remote logins at unusual hours, unexpected child processes |
| AN1546 | Identity provider | Impossible travel, risky sign-ins, repeated MFA attempts and failures |
| AN1547 | Containers | Service accounts and kubeconfigs used from unexpected nodes or IPs |
Five analytics. Five different sets of telemetry. Under the old model this was one technique with one line of advice, and you could tick it off a coverage map without ever asking which of those five you could actually see.
That is the real change. The framework now forces you to answer the platform question before it will give you anything useful.
How to read it
The habit the matrix teaches is top-down. Pick a tactic, pick a technique, tick the box. It feels like coverage, and it measures nothing.
The new structure lets you go the other way, and the other way is honest:
-
Start with a log source you actually collect. Sign in logs. Sysmon. Auth logs.
-
Find the Data Components it feeds, then the Analytics that read them.
-
Walk up to the Detection Strategies, and from there to the techniques.
What you get is not a coverage map. It is a list of the techniques you are genuinely positioned to see, and the far longer list you are not. AN1546 is available to almost anyone with an identity provider. AN1547 is available to nobody who is not running Kubernetes. The old model let you blur those two together. This one will not.
What to ACTUALLY read
Not the tutorials. Read MITRE's own blog posts on the new detection model [1], [2], then the v19 release notes and the Defense Evasion crosswalk [3], [4]. After that, open Detection Strategies and Analytics on the ATT&CK site directly [6], [7] and pick one technique you care about. An hour spent walking a single technique down to its log sources will teach you more than a week of matrix diagrams.
Why I bothered writing it down
I never sent that list of links.
Instead I went and read the object model properly, walked one technique down to its log sources, and found that a good part of what I would have confidently told them a month ago was out of date.That would be wrong at the level of which objects the framework even has.
That is why I write in public. Publishing makes me check things I would otherwise assume, and being corrected in the open is a far cheaper way to learn than being quietly wrong in front of someone who knows better. Every post I put up is a bet that the checking is worth the exposure. So far it has been.
If any of this was useful to you, there is one small thing you can do with that.
I am a finalist in the AISA Cyber Security Awards 2026, Student of the Year category. Voting closes at midnight on Friday 18 September, and only AISA members can vote, so if that is you and this post earned its place in your afternoon, this is where to say so:
https://aisa.secure-platform.com/awards/gallery?roundId=82008
The link is member gated. Log in first or it will bounce you to a sign in page.
And if you are the person who sent me that message: this is the answer. Sorry it took a week.
References
[1] A. L. Robertson, "ATT&CK v18: Detection Strategies, More Adversary Insights," MITRE ATT&CK, Oct. 28, 2025. [Online]. Available: https://medium.com/mitre-attack/att-ck-v18-detection-strategies-more-adversary-insights-8f82d839ee9e
[2] L. Crumpton, "What Comes After Detection Rules? Smarter Detection Strategies in ATT&CK," MITRE ATT&CK, Oct. 22, 2025. [Online]. Available: https://medium.com/mitre-attack/smarter-detection-strategies-in-attack-7e6738fec31f
[3] A. L. Robertson, "ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI and Social Engineering Coverage, and Detection Strategies for Mobile," MITRE ATT&CK, Apr. 29, 2026. [Online]. Available: https://medium.com/mitre-attack/att-ck-v19-the-defense-evasion-split-ics-sub-techniques-new-ai-social-engineering-coverage-ff329cb65d66
[4] The MITRE Corporation, "Updates: April 2026," MITRE ATT&CK. [Online]. Available: https://attack.mitre.org/resources/updates/updates-april-2026/
[5] The MITRE Corporation, "Valid Accounts, Technique T1078, Enterprise," MITRE ATT&CK. [Online]. Available: https://attack.mitre.org/techniques/T1078/
[6] The MITRE Corporation, "Detection Strategies," MITRE ATT&CK. [Online]. Available: https://attack.mitre.org/detectionstrategies/
[7] The MITRE Corporation, "Analytics," MITRE ATT&CK. [Online]. Available: https://attack.mitre.org/analytics/
**All technique, strategy and analytic details verified against ATT&CK content v19.2 on 9 September 2026.**
Spotted an error or have a suggestion?
Email me