Steps 2 to 5 — threat scope
Crown jewels, threat actors, the techniques most likely to be used against you, and the attack paths that make a technique matter.
What these steps establish
These four steps turn a generic catalogue into your catalogue. Scope is an intersection: a technique must be possible on your platforms, used by adversaries you care about, and sit on a path to something worth taking.
Crown jewels
Name what you are protecting and what kind of asset it is — identity, data store, cloud control plane, source code, backups, endpoint fleet, email or OT. The category matters: it determines which tactics are weighted as high impact for you. Declaring domain controllers lifts credential access and lateral movement; declaring backups lifts the ransomware playbook.
Since model 1.6.0 the asset type is a structured choice of sixteen, each mapped to the category the tool has always used, so an assessment saved with an earlier category ranks, scores and exports exactly as before. A type establishes technical relevance: which tactics an adversary must succeed at to reach it, which ATT&CK platforms it is assessed through, which telemetry families see it, which TIR-CMM asset class it maps to, and which scenario templates apply. It never asserts that an adversary targets the asset; actor suggestions stay based on sector and region. A mobile application is assessed through its backend, API, identity and cloud infrastructure, because this dataset is Enterprise ATT&CK and no native Android or iOS coverage is claimed.
| Asset type | Legacy category | ATT&CK platforms | Telemetry families | TIR-CMM class | Scenario templates |
|---|---|---|---|---|---|
| Identity and privileged access | Identity / Active Directory (same weights) | Windows, Identity Provider | Identity and directory audit | A1 Identity & Access Infrastructure | Phishing to identity dominance |
| Business and operational data | Database / data store (same weights) | Windows, Linux, IaaS, SaaS | File, share and object access; Database and application logs | A7 Data Stores & Backup | Credentialed access to a data store; Ransomware with recovery destruction |
| Web applications | Other / not sure | Linux, Windows, IaaS, Containers | Web server and ingress logs; Host telemetry behind the application | A6 Application, Source & CI/CD | Public-facing application to data |
| APIs and integrations | Other / not sure | Linux, Windows, IaaS, SaaS, Containers | API gateway and application logs; Token and key use | A6 Application, Source & CI/CD | Public-facing application to data |
| Mobile applications and mobile backends (assessed through its backend, API, identity and cloud; Enterprise ATT&CK only) | Other / not sure | Linux, IaaS, SaaS, Identity Provider, Containers | API gateway and application logs; Identity and token use | A6 Application, Source & CI/CD, A4 Cloud Control Plane & SaaS | Public-facing application to data; SaaS account takeover to mailbox and document theft |
| SaaS and collaboration platforms | Other / not sure | SaaS, Office Suite, Identity Provider | Tenant audit and sign-in; Collaboration content and sharing | A4 Cloud Control Plane & SaaS | SaaS account takeover to mailbox and document theft |
| Email services | Email / collaboration (same weights) | Office Suite, SaaS, Windows, Linux | Mail flow and mailbox audit | none | SaaS account takeover to mailbox and document theft; Endpoint compromise to command and control |
| Cloud workloads | Cloud account / control plane (same weights) | IaaS, Containers, Linux, Windows | Cloud control-plane audit; Workload and network flow | A4 Cloud Control Plane & SaaS | Cloud control-plane takeover |
| End-user endpoints | Endpoint fleet (same weights) | Windows, macOS, Linux | Endpoint process, file and script telemetry | A2 Endpoint & User Compute | Endpoint compromise to command and control; Phishing to identity dominance |
| Servers and data centres | Other / not sure | Windows, Linux, ESXi | Server host telemetry; Hypervisor and management | A3 Server & Datacentre Workload | Ransomware with recovery destruction; Credentialed access to a data store |
| Network and perimeter infrastructure | Other / not sure | Network Devices | Network device audit and configuration; Flow, firewall and DNS | A5 Network & Edge | Edge device compromise to internal access |
| Source code, repositories and CI/CD | Source code / build pipeline (same weights) | SaaS, Linux, Containers | Repository and pipeline events; Secrets and credential use | A6 Application, Source & CI/CD | Repository to build pipeline |
| Data platforms and databases | Database / data store (same weights) | Linux, Windows, IaaS, SaaS | Database and query audit; Object storage access | A7 Data Stores & Backup | Credentialed access to a data store; Cloud control-plane takeover |
| Backups and recovery systems | Backups / recovery (same weights) | Windows, Linux, IaaS | Backup platform and job logs; Host telemetry on backup servers | A7 Data Stores & Backup | Ransomware with recovery destruction |
| OT, ICS and IoT | OT / ICS / physical process (same weights) | Windows, Linux, Network Devices | Network flow and protocol inspection at the IT/OT boundary; Engineering workstation and jump-host telemetry | A8 OT / ICS / IoT / Specialist | IT-to-OT pivot |
| Other / custom critical service | Other / not sure | — | — | none | — |
Each declared crown jewel shows what its type changes downstream, and the telemetry step and the roadmap tag every source with the crown jewel it serves. Tactic weights for the new types are on the data model page.
Threat actors
Select the groups and campaigns that plausibly target your sector and geography, from ATT&CK's own actor data. Their combined technique set becomes your candidate pool.
This is where assessments stall. Choosing from 232 documented groups and campaigns with no starting point is the reason scoping gets skipped, and a technique set chosen by tooling rather than by threat is the failure the whole model exists to expose. So the tool offers a suggested threat profile: declare your sector and region on the previous step and it ranks the adversaries ATT&CK documents against organisations like yours, with the reason for each.
Accepting the suggestion unchanged caps TI.2 at level 2. TI.2 asks who you are defending against and how you know. If the tool answered it, you inherited the answer rather than producing it, and constraint C5 records that. The ceiling lifts the moment you engage with the list — add an adversary it missed, remove one that does not apply, or record why you accepted one. The constraint is not there to discourage using the feature; it is there so that using it without thinking cannot look identical to doing the analysis.
What the suggestion cannot tell you
ATT&CK has no structured targeting field. Sector and region are stated only in the
prose of each group's description, so the mapping in
data/actor_sectors.yaml is extracted from that text and, where the text is
truncated or silent, restored by hand from public attribution. Each entry carries its
confidence and is open to challenge.
44 of the 232 documented groups and campaigns carry no reliable targeting information and are excluded entirely. Their absence from your profile says nothing about whether they would target you. ATT&CK also documents intrusions that were investigated and published, which over-represents victims with mature incident response — so a short list means the reporting is thin, not that few adversaries care about your sector.
Likely attacks
The model ranks candidates by probability × impact — observed use across 1,057 documented actors, weighted toward the actors you chose, against tactic severity weighted by the crown jewels you declared. Nothing is selected for you.
What this ranking cannot tell you. ATT&CK documents intrusions that were investigated and published, which over-represents victims with mature incident response. A technique rare in ATT&CK is not rare in the world. Treat it as an informed starting point that saves reading 697 technique pages.
Attack paths
Mark the techniques that sit on a modelled route to a crown jewel. This is the attack-tree step reduced to its essence, and it is what separates Tier A — the set worth being excellent at — from everything else.