| Version | Start Date | End Date | Data | Changelogs |
|---|---|---|---|---|
| ATT&CK v17 | April 22, 2025 | October 27, 2025 | v17.0 on MITRE/CTI v17.1 on MITRE/CTI |
16.1 - 17.0 Details (JSON) 17.0 - 17.1 Details (JSON) |
The April 2025 (v17) ATT&CK release updates Techniques, Groups, Campaigns and Software for Enterprise, Mobile, and ICS.
The biggest changes in ATT&CK v17 are the addition of an ESXi platform to ATT&CK's Enterprise domain describing adversary activity taking place on the VMWare ESXi hypervisor, a dramatic improvement of Enterprise Mitigation descriptions, and the renaming of the Network platform to Network Devices in order to more clearly communicate the scope of the platform. An accompanying blog post describes these changes as well as additional improvements across ATT&CK's various domains and platforms.
In this release we have revoked Hijack Execution Flow: DLL Side-Loading and merged it into Hijack Execution Flow: DLL, which itself was renamed from Hijack Execution Flow: DLL Search Order Hijacking. This change was made to reflect the previously overlapping scope of the two sub-techniques and frequent confusion between them.
This release also includes a human-readable detailed changelog showing more specifically what changed in updated ATT&CK objects, and a machine-readable JSON changelog, whose format is described in ATT&CK's Github.
This version of ATT&CK contains 877 Pieces of Software, 170 Groups, and 50 Campaigns
Broken out by domain: