[Bug] Update MITRE ATT&CK technique references - #33
Merged
Conversation
Aegrah
approved these changes
Feb 26, 2026
imays11
approved these changes
Feb 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Updates deprecated and revoked MITRE ATT&CK technique IDs across the repo so RTA metadata and comments align with current ATT&CK (v17+).
Changes
# ATT&CK:technique IDs with current equivalents (e.g. T1022 → T1560, T1088 → T1548.002, T1140 → T1027/T1059.001, T1064/T1192/T1193 → T1566). Where there is no single replacement, comments now note the ID is deprecated and point to relevant techniques.techniques=arrays and used T1027 (Obfuscated Files or Information) and/or T1059.001 (PowerShell) as appropriate. T1574.002 (DLL Side-Loading, revoked in v17) was already replaced with T1574.001 in a prior change.Reference
Deprecated Post 2018
Deprecated Techniques (No Replacement)
These techniques were deprecated (no longer in use, not replaced by another object). When a replacement is commonly used in practice, it is noted.
Other commonly referenced deprecated/revoked technique IDs
The following IDs are frequently cited in legacy content or rule sets as deprecated or superseded. The exact version and replacement (if any) are in the official changelogs; this table is a quick reference.
Revoked Techniques (Replaced By Another Object)
These techniques were revoked and replaced by another technique or sub-technique.
Enterprise
July 2020 (v7) revocations: Dozens of former standalone techniques were revoked and folded into sub-techniques. Examples (from the July 2020 release):
The complete list of v6→v7 revocations is in the machine-readable changelog (e.g.
changelog.jsonfor the v6.3–v7.0 or v7.2–v8.0 transition, under “revoked_by” or equivalent).Mobile
Other Mobile technique revocations/deprecations are in the Mobile-specific changelogs (e.g. v11.2→v11.3, v13.1→v14.0).
Deprecated Tactics
Since 2018, tactics have been given TA#### IDs and reorganized (e.g. PRE-ATT&CK merged into Enterprise, Mobile “Obtain Device Access” folded into Initial Access). There is no single “deprecated tactic” list in the same way as techniques; old tactic names/structures were superseded by the current matrix.
For exact tactic renames or structural changes, check the release notes and changelogs for the relevant version.
How to Get the Complete List
Changelog index: attack.mitre.org/resources/updates
Each release links to:
Detailed changelogs (examples):
JSON changelogs (for scripts and full deprecation/revocation lists):
https://attack.mitre.org/docs/changelogs/v16.1-v17.0/changelog.jsonVersioned ATT&CK: attack.mitre.org/versions
Links to preserved versions (e.g. v6 pre–sub-techniques, v17, v18).
Summary Table (Deprecated / Revoked Since 2018)