ToolsCVE trackerATT&CKCIDRDNSEmail securityHeadersTrackersTLSMy connectionCSP builderEmail headersJWTCert decoderPassphrasePassword checkHash & encodesecurity.txtDNSSEC & CAA

d4 · tools · attack

The ATT&CK matrix.

MITRE ATT&CK catalogues the tactics and techniques adversaries actually use, drawn from real intrusions. This is the Enterprise matrix: 15 tactics in kill-chain order, each listing the techniques used to achieve it. Open a CVE from the tracker to see a vulnerability's techniques highlighted here.

CVE-2026-48908 on the matrix

inferred from weakness class no curated mapping exists; these techniques are typical for CWE-434 vulnerabilities

4 techniques across 4 tactics - highlighted below, everything else dimmed. An unlit tactic is not missing data: a CVE maps only to the techniques its exploitation enables, so preparatory stages such as reconnaissance and resource development light up only when the vulnerability itself plays a part in them. Full detail on the tracker page.

Reconnaissance12
Resource Development9
Initial Access11
Execution20
Persistence22
Privilege Escalation13
Stealth30
Defense Impairment18
Credential Access17
Discovery34
Lateral Movement9
Collection17
Command and Control18
Exfiltration9
Impact15

Each cell links to the full technique page on attack.mitre.org; the count next to a technique id is its number of sub-techniques. Tactics answer "why" (what the adversary is after); techniques answer "how". Data: ATT&CK Enterprise v19.1, loaded from a seed generated 2026-07-15; CVE mappings from the CTID KEV mappings project (07/28/2025). ATT&CK is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. CVE-to-technique mappings © the Center for Threat-Informed Defense, Apache 2.0.