Security
MITRE ATT&CK ID Checker
Enter a MITRE ATT&CK technique ID (T1059 or T1059.001) to validate the format, identify the sub-technique, and get a direct link to the ATT&CK framework entry. Used for threat modeling and compliance control mapping.
No data is transmitted — everything runs locallyTool
About this tool
MITRE ATT&CK ID Checker
The MITRE ATT&CK ID Checker validates technique and sub-technique IDs, identifies the tactic category, and links to the ATT&CK framework entry.
• Validate technique IDs in a threat intelligence report
• Look up the tactic category for a technique ID in an IR report
• Map ATT&CK techniques to compliance controls
• Check sub-technique format before adding to a detection rule
Next step
Alerting Threshold Calculator — Compute multi-window SLO burn rate alert thresholds from the Google SRE Workbook method.
Open Alerting Threshold Calculator →
FAQ
What does this tool tell you?
The MITRE ATT&CK ID Checker validates technique and sub-technique IDs, identifies the tactic category, and links to the ATT&CK framework entry.
What affects the result most?
Format: T followed by 4-digit technique ID. Sub-techniques: T1059.001 (technique.sub format). 14 tactic categories (Reconnaissance through Impact).
How should I use the result?
Treat the tool's output as a first-pass check, not a proof of correctness. A clean pass means no issues in the patterns this tool recognizes; a failure points to a specific problem you can investigate in your source. The underlying spec is the authoritative source for edge cases.
Related tools