Attack Flow
Attack Flow helps defenders capture the entire scope of a cyber attack and communicate what matters. By representing actions, conditions, and …
July 30, 2026
Attack Flow helps defenders capture the entire scope of a cyber attack and communicate what matters. By representing actions, conditions, and relationships as a connected flow, teams can move from isolated observations to a shared view of how an event unfolded.
The latest project release helps defenders create and enrich flows more quickly with automated layout, LLM-assisted flow generation, Technique Inference Engine recommendations, tags, TLP markings, mitigation and detection support, and new visualizations. Attack Flow also supports additional TTP frameworks, including MITRE ATLAS™, MITRE D3FEND™, and the MITRE Fight Fraud Framework™, so teams can add the context needed to prioritize detection, patching, remediation, and communication.
Tracking adversary behaviors one action at a time makes it hard to build effective defenses against multi-phased attacks.
Create a language, and associated tooling, to describe flows of ATT&CK techniques and combine those flows into patterns of behavior.
Visualize and communicate how adversaries operate to define defensive actions.
Attack Flow helps defenders capture the entire scope of a cyber attack and communicate what matters. By representing actions, conditions, and …
A collaboration with MITRE ATLAS™ to advance security for AI–enabled systems that takes a threat-informed approach, enables rapid exchange of new …
The Fight Fraud Framework strengthens fraud analysis by giving teams a clear behavioral structure to identify risks, focus investigations, and …
Sign up for our "Stay Informed" mailing list to receive announcements for project publications, upcoming events, and other news about the Center.