Attack Flow: From Diagrams to Decisions
Attack Flow v4 helps defenders turn incident evidence into connected flows, add the context needed for action, and communicate decisions across …
By Mike Cunningham and Allison Robbins • July 30, 2026
Imagine you are responding to an intrusion. The investigation has established several important facts: an initial foothold, discovery activity, movement to another system, and then exfiltration. Each observation matters, but a list of techniques alone does not show how those actions relate. It does not make clear what enabled the next step, where a defender could have interrupted the sequence, or which gaps deserve attention first.
With Attack Flow, you represent the event as a connected sequence of actions, conditions, and decision points. The flow becomes a living artifact for investigation and remediation, then a shared visual account that will determine future actions.
Incidents do not arrive as a clean sequence of labeled techniques. They arrive as alerts, logs, case notes, endpoint evidence, and questions. What happened first? What did the adversary do next? Which systems were affected? What has been detected, patched, or remediated, and conversely, what still needs attention?
Too often, defenders answer those questions one technique at a time. That approach can make it difficult to see how separate observations form a larger operation or to explain why a particular defensive action matters now. Attack Flow gives you the language to describe how adversary behavior unfolds as a connected flow. It makes the relationships between actions visible and presents your team a shared comprehensive picture.
Today, we are announcing the release of Attack Flow v4, the latest evolution of our language and tooling for understanding adversary behavior. If you’re already familiar with Flow, go straight to the Attack Flow Builder. If you’d prefer to read the docs, you can do that here!
Developed in collaboration with AttackIQ, Aviation ISAC, Citigroup, Cyber Threat Alliance, Fortinet, Fujitsu, JPMorganChase, and Lloyds Banking Group, this release brings new capabilities that help defenders create flows faster, add richer context, and use those flows to make decisions.
Instead of starting with a blank canvas, AI-assisted flow generation takes the source material you already use, such as a PDF, URL, or plain-text, and captures the likely sequence of actions described in the evidence.
Once the flow is generated, it is possible that some techniques are missing either through analyst omission or they have not been detected yet. The Technique Inference Engine (TIE) is a machine-learning model, trained on threat reports and detection data, that suggests techniques likely to co-occur with a given set of techniques. This feature has been integrated into Attack Flow.
As you build a path through an event, TIE suggests related ATT&CK techniques. A selected recommendation can be added directly as a connected action, helping analysts explore plausible next steps and fill in gaps. Your team can then review the result, validate it against the source material, correct assumptions, add missing context, and refine the flow for the decisions at hand.
This saves significant time for defenders laying the foundation for a flow in a matter of seconds, giving you and your team a usable visual model early in the investigation. By reducing the manual effort required to create an initial flow, analysts spend their valuable time evaluating what happened, testing hypotheses, identifying defensive opportunities, and communicating the findings.
Once you have defined the intrusion, then you add context to the flow with tags. Your team can define a tag once and reuse it across flow objects. A tag shows that activity was detected or still needs review. You can also tag the current remediation state such as patching needed, patched, or validated. Another tag identifies the compensating control already in place. In a single view, the flow shows what the adversary did, whether you saw it done, where remediation is incomplete, and which parts of the sequence need follow-up.
Attack Flow also adds mitigation and detection support. Attack Flow attaches ATT&CK mitigations and detection strategies to the flow, and Attack Flow’s recommendation engine suggests relevant options from existing ATT&CK relationships. The flow is a hub where investigations are stored, defenses are planned, and decisions are made. This is the difference between documenting an event and defending your assets.
Attack Flow now supports MITRE ATLAS™, MITRE D3FEND™, and the MITRE Fight Fraud Framework™ with MITRE ATT&CK® to help describe adversary behavior and defensive measures across domains. You select which frameworks are enabled, initially see tactics and techniques from those frameworks, and receive warnings when a flow includes tactics or techniques from a non-selected framework. The ability to work across relevant frameworks lets you adapt Attack Flow to the incidents, risks, and operating environments relevant to your role. Explore the updated Attack Flow Builder and use it to turn the evidence from an event into a clearer path toward remediation and resilience.
Different roles require different views of the same event. An investigator needs the full sequence. A program lead needs to document coverage gaps. An executive needs a concise explanation of what happened, why it matters, and what is being done next.
Attack Flow’s visualization capability has expanded to a library with a shared interface to resize, download, copy, and enable full-screen use. Available views include presentation, treemap, tactic table, timeline, matrix, and an IOC table.
The presentation visualization is especially useful when a complex flow must fit into a briefing. It focuses on action, condition, and operator blocks; uses a horizontal layout that moves between rows; and includes a scale control. The goal is not to simplify away the substance, but to help the audience see the story without losing its structure.
This new capability is designed to fit different operating environments. Teams can use CTID’s hosted Attack Flow, bring their own API key, and generate flows through the same interface they have used in the past (the API key is encrypted upon entry and is never saved). For teams that prefer more control over their tools, we have built a standalone option to run the service internally and operate it through a locally hosted API. This flexibility makes it possible to use automated flow generation in the environment that best fits a team’s security, privacy, and operational requirements.
We welcome your feedback and contributions. There are several ways that you can get involved with Attack Flow and help advance threat-informed defense:
Please submit issues for any technical questions or contact us directly for general inquiries.
© 2026 The MITRE Corporation. Approved for Public Release. ALL RIGHTS RESERVED. Document number
26-1599.
Attack Flow v4 helps defenders turn incident evidence into connected flows, add the context needed for action, and communicate decisions across …
Secure AI expanded MITRE ATLAS™ with new techniques, mitigations, case studies, a Technique Maturity filter, and rapid-response and emulation …
MITRE Fight Fraud Framework (F3) is a behavior-based model of fraud actor tactics and techniques that gives fraud and cyber defenders a shared …