Skip to main content
QUIETLYTIC
Cybersecurity

ATT&CK Technique Lookup

Find a MITRE ATT&CK technique by ID or name from a bundled dataset.

Local · nothing leaves this browser Type to search
Esc Clear
Techniques

Type an ATT&CK ID, a technique name, or a keyword.

How it works

Search by ID, by name, by tactic, or by a phrase from the description. Searching a parent ID returns its sub-techniques with it — T1566 brings back Phishing and every T1566.00x beneath it, because the question behind that search is almost never about the parent alone.

Nothing you type is sent anywhere

The technique dataset is downloaded once, on your first search, and every query after that is matched inside your own tab. No search term reaches a server. That matters more here than it looks: the technique someone searches for during an incident is a statement about what they think is happening.

Tactic names come from the data, never from a list here

ATT&CK renames tactics — TA0005 became Stealth in the May 2026 release — so tactic labels are derived from the shortnames in the dataset rather than a table written into this page. A tactic added upstream appears correctly the day the data carries it, instead of rendering under a name that stopped being true.

Reference data, not detection coverage

This tells you what a technique is. It does not tell you whether you detect it, which groups use it, or how it has been seen in the wild — that last question is what Quietlytic's threat actor profiles and malware coverage are for. Descriptions are trimmed; the authoritative text is on MITRE's own page for each technique.

Example

credential dumping returns T1003 by name. login material returns the same technique by description, because the phrase appears in MITRE's own text and not in the title. Both results say which field matched, so a description hit is never mistaken for a name.

MITRE ATT&CK® — attack.mitre.org . Used under the ATT&CK Terms of Use . Technique descriptions are MITRE's; the search, ranking and presentation here are not, and nothing on this page is endorsed by MITRE. Descriptions are trimmed, and MITRE's inline citation markers and footnote link syntax are removed because neither resolves outside their own bundle — no wording is rewritten.

Frequently asked questions

Is my search sent to a server?

No. The dataset is downloaded once on your first search and every query after that is matched inside your own tab. The technique someone looks up during an incident says a lot about what they think is happening, so nothing typed here leaves the page.

Why does searching a parent ID return sub-techniques too?

Because the question behind a search for T1566 is almost never about the parent alone. Sub-technique IDs begin with the parent’s, so they are matched as a prefix and sorted beneath it.

Where does the data come from?

MITRE ATT&CK, ingested into this site’s own database on its own refresh schedule. The page reports when that data was last synced, so a stale dataset is visible rather than silent.

Why are tactic names not listed in the tool?

Because ATT&CK renames them — TA0005 became Stealth in the May 2026 release. Labels are derived from the shortnames in the data, so a rename or a new tactic appears correctly the day the data carries it.

Can I search by something other than an ID?

Yes — technique name, tactic, or a phrase from the description. Each result says which field matched, so a description hit is never mistaken for a name.

Related tools

From the intelligence desk