MITRE Center for Threat-Informed Defense at MITRE ATT&CKcon 7.0
October 27, 2026 - October 28, 2026
MITRE McLean: 7594 Colshire Dr, McLean, VA 22102
Join us at MITRE headquarters in McLean, VA, for MITRE ATT&CK® and threat-informed defense.
Connect with fellow cyber professionals, hear from expert speakers, and dive into engaging content.
Everything is designed to help you make the most of the ATT&CK framework and advance threat-informed defense. Whether you’re starting your cybersecurity journey or aiming to boost your skills and network, ATT&CKcon is the place for cybersecurity leaders and practitioners.
In addition to the main event on October 27 and 28, the Center will host its advisors and members for strategic discussions of the Center and our roadmap. Then on Thursday, the Center will host a training session, open to all, to drive community-wide advancement to threat detection capabilities.
Event Schedule
ATT&CKcon 7.0
October 28-29
Call for Presentations Now Open
ATT&CKcon is looking for dynamic speakers to present what’s practical, what’s aspirational, and what you should never do with ATT&CK. From manager to operators, we’re looking to hear from the community on any and all applications of ATT&CK.
We like to keep things fairly fast paced at ATT&CKcon, and are looking for submissions for 15 and 30-minute slots. Some suggested things that we’d love to see:
Call for Presentations is now open through Thu., July 2 at 8:00 PM ET/0:00 UTC.To learn more and submit your proposal, visit https://www.openconf.org/ATTACKcon2026/openconf.php.
Threat-Informed Defense Training: Collaborative Attack Modeling Across CTI, Red Team, and SOC
Thursday, October 29 from 8:30 AM - 11:30 AM (ET)
Threat intelligence, red team, and SOC functions are each essential to threat-informed defense. They are most effective when they share talents, data, and workflows.
In many organizations, cyber defense teams analyze the same adversary through disconnected processes. The result is fragmented understanding, duplicated effort, and gaps in detection coverage.
This workshop will show how a collaborative approach to attack modeling can unify these functions into a single, shared workflow using an open-source tool called Attack Flow. By aligning teams around a shared representation of threats and capturing measurable detection outcomes, organizations can improve coverage, accelerate response, and communicate risk more effectively to leadership.
You will be given the option of registering for the Attack Flow training as part of your ATT&CKcon 7.0 registration. Contact Denise denised@mitre.org with questions.
Advisory Council Meeting (advisors only)
Monday, October 26 from 9:00 AM - 12:30 PM (ET)
The Center’s Advisory Council will hold their fall meeting. Advisors provide strategic guidance and executive advocacy in support of the Center’s mission.