Blog

Attack Flow: From Diagrams to Decisions

Attack Flow: From Diagrams to Decisions

By Mike Cunningham and Allison Robbins • July 30, 2026

Imagine you are responding to an intrusion. The investigation has established several important facts: an initial foothold, discovery activity, movement to another system, and then exfiltration. Each observation matters, but a list of techniques alone does not show how those actions relate. It does not make clear what enabled the next step, where a defender could have interrupted the sequence, or which gaps deserve attention first.

With Attack Flow, you represent the event as a connected sequence of actions, conditions, and decision points. The flow becomes a living artifact for investigation and remediation, then a shared visual account that will determine future actions.

Incidents do not arrive as a clean sequence of labeled techniques. They arrive as alerts, logs, case notes, endpoint evidence, and questions. What happened first? What did the adversary do next? Which systems were affected? What has been detected, patched, or remediated, and conversely, what still needs attention?

Too often, defenders answer those questions one technique at a time. That approach can make it difficult to see how separate observations form a larger operation or to explain why a particular defensive action matters now. Attack Flow gives you the language to describe how adversary behavior unfolds as a connected flow. It makes the relationships between actions visible and presents your team a shared comprehensive picture.

Today, we are announcing the release of Attack Flow v4, the latest evolution of our language and tooling for understanding adversary behavior. If you’re already familiar with Flow, go straight to the Attack Flow Builder. If you’d prefer to read the docs, you can do that here!

Developed in collaboration with AttackIQ, Aviation ISAC, Citigroup, Cyber Threat Alliance, Fortinet, Fujitsu, JPMorganChase, and Lloyds Banking Group, this release brings new capabilities that help defenders create flows faster, add richer context, and use those flows to make decisions.

Instead of starting with a blank canvas, AI-assisted flow generation takes the source material you already use, such as a PDF, URL, or plain-text, and captures the likely sequence of actions described in the evidence.

AI-assisted Flow Generation
AI-assisted Flow Generation.

Once the flow is generated, it is possible that some techniques are missing either through analyst omission or they have not been detected yet. The Technique Inference Engine (TIE) is a machine-learning model, trained on threat reports and detection data, that suggests techniques likely to co-occur with a given set of techniques. This feature has been integrated into Attack Flow.

As you build a path through an event, TIE suggests related ATT&CK techniques. A selected recommendation can be added directly as a connected action, helping analysts explore plausible next steps and fill in gaps. Your team can then review the result, validate it against the source material, correct assumptions, add missing context, and refine the flow for the decisions at hand.

This saves significant time for defenders laying the foundation for a flow in a matter of seconds, giving you and your team a usable visual model early in the investigation. By reducing the manual effort required to create an initial flow, analysts spend their valuable time evaluating what happened, testing hypotheses, identifying defensive opportunities, and communicating the findings.

A sequence of techniques. So what?

Once you have defined the intrusion, then you add context to the flow with tags. Your team can define a tag once and reuse it across flow objects. A tag shows that activity was detected or still needs review. You can also tag the current remediation state such as patching needed, patched, or validated. Another tag identifies the compensating control already in place. In a single view, the flow shows what the adversary did, whether you saw it done, where remediation is incomplete, and which parts of the sequence need follow-up.

Attack Flow Tagging Feature
Attack Flow Tagging Feature.

Attack Flow also adds mitigation and detection support. Attack Flow attaches ATT&CK mitigations and detection strategies to the flow, and Attack Flow’s recommendation engine suggests relevant options from existing ATT&CK relationships. The flow is a hub where investigations are stored, defenses are planned, and decisions are made. This is the difference between documenting an event and defending your assets.

Flow across enterprise, AI, fraud, and more

Attack Flow now supports MITRE ATLAS™, MITRE D3FEND™, and the MITRE Fight Fraud Framework™ with MITRE ATT&CK® to help describe adversary behavior and defensive measures across domains. You select which frameworks are enabled, initially see tactics and techniques from those frameworks, and receive warnings when a flow includes tactics or techniques from a non-selected framework. The ability to work across relevant frameworks lets you adapt Attack Flow to the incidents, risks, and operating environments relevant to your role. Explore the updated Attack Flow Builder and use it to turn the evidence from an event into a clearer path toward remediation and resilience.

The right information for the audience

Different roles require different views of the same event. An investigator needs the full sequence. A program lead needs to document coverage gaps. An executive needs a concise explanation of what happened, why it matters, and what is being done next.

Attack Flow’s visualization capability has expanded to a library with a shared interface to resize, download, copy, and enable full-screen use. Available views include presentation, treemap, tactic table, timeline, matrix, and an IOC table.

Banner Marking Feature

Banner Marking Feature
For sensitive information, banner markings are fully supported. Support for common TLP markings, as well as UNCLASSIFIED and CUI, helps teams preserve that context when flows are shared. An optional group field can add further direction, such as TLP:AMBER:CTID. Exported visualizations retain TLP markings, preserving handling guidance as the information moves between teams.

The presentation visualization is especially useful when a complex flow must fit into a briefing. It focuses on action, condition, and operator blocks; uses a horizontal layout that moves between rows; and includes a scale control. The goal is not to simplify away the substance, but to help the audience see the story without losing its structure.

Attack Flow Presentation View
Attack Flow Presentation View

CTID-hosted or Flow-to-go

This new capability is designed to fit different operating environments. Teams can use CTID’s hosted Attack Flow, bring their own API key, and generate flows through the same interface they have used in the past (the API key is encrypted upon entry and is never saved). For teams that prefer more control over their tools, we have built a standalone option to run the service internally and operate it through a locally hosted API. This flexibility makes it possible to use automated flow generation in the environment that best fits a team’s security, privacy, and operational requirements.

Get Involved

We welcome your feedback and contributions. There are several ways that you can get involved with Attack Flow and help advance threat-informed defense:

  • Learn about Attack Flow on our project website. The site has everything you need to learn about Attack Flow from first principles and get started building your own flows.
  • Review our example flows. The example flows are based on public reporting of well-known attacks such as NotPetya. You can use this library of flows to learn more about these historical attacks and/or to learn how to use Attack Flow itself.
  • Build your own flows. Use the Attack Flow Builder to turn threat intelligence into a flow of your own. If your threat intelligence is public, you can submit your flow to our GitHub repository, and we will add it to our example flows.
  • Join the community. Sign up for Stay Informed emails and follow us on LinkedIn for updates.

Please submit issues for any technical questions or contact us directly for general inquiries.


© 2026 The MITRE Corporation. Approved for Public Release. ALL RIGHTS RESERVED. Document number 26-1599.


About the Authors

Mike Cunningham

As R&D Program Manager in MITRE’s Center for Threat-Informed Defense, Mike is responsible for project execution and vision. He continuously advances the state of the art and the state of practice in threat-informed defense through cutting-edge research and innovation. Before joining MITRE, Mike was an Interactive On-Net Operator in Tailored Access Operations at the NSA. In his spare time, Mike cherishes quality time with his wife and three daughters. He also enjoys playing music, staying fit, and basking in the San Diego sun.

More by Mike Cunningham
Allison Robbins

As a UX Engineer for the Center, Allison is responsible for the design and implementation of the Center's web properties, including this site, Mappings Explorer, ATT&CK Sync, Top ATT&CK Techniques, and more!

More by Allison Robbins

Recent Blog Posts:

Attack Flow: From Diagrams to Decisions

Attack Flow v4 helps defenders turn incident evidence into connected flows, add the context needed for action, and communicate decisions across …

Continue reading

MITRE ATLAS Grows through Collaboration with CTID and Industry

Secure AI expanded MITRE ATLAS™ with new techniques, mitigations, case studies, a Technique Maturity filter, and rapid-response and emulation …

Continue reading

Fraud Fighters United with MITRE F3

MITRE Fight Fraud Framework (F3) is a behavior-based model of fraud actor tactics and techniques that gives fraud and cyber defenders a shared …

Continue reading