MITRE ATT&CK is the common language security teams use to describe attacker behavior, but that language keeps evolving. Each new version reorganizes tactics and techniques, and a platform that falls behind doesn't just miss updates, it risks misclassifying the threats it's meant to help you understand. With Intelligence Center 3.9, EclecticIQ now supports MITRE ATT&CK v19.1, bringing one of the most significant recent structural updates to the framework into the platform.
MITRE ATT&CK continues to evolve
Since it was first introduced, MITRE ATT&CK has grown from a single Enterprise matrix into a broader framework spanning Enterprise, Mobile, and ICS environments. Each release refines how the framework categorizes attacker behavior, splitting overloaded tactics, adding new techniques, and introducing new ways to structure detection guidance. These updates keep the framework aligned with how adversaries actually operate, but they also mean that threat intelligence platforms need to keep pace. A platform running an outdated version of ATT&CK doesn't just miss new techniques, it risks mapping threats to categories the security community has already moved past.
EclecticIQ now supports ATT&CK v19.1
With Intelligence Center 3.9, EclecticIQ has moved to v19.1. Your threat research, entity tagging, and tactical mappings inside Intelligence Center now reflect this updated structure, replacing the older one they were built on.
What's changed in v19, and why it matters for analysts
A few changes stand out as particularly relevant for day-to-day analysis:
The Enterprise Defense Evasion tactic has been split into two new tactics. What was previously a single, broad Defense Evasion category is now divided into Stealth (hiding artifacts, obfuscation, masquerading, and exploiting for stealth) and Defense Impairment (disabling or modifying tools, firewalls, logs, and command history logging). Most existing Defense Evasion techniques keep their technique IDs and simply move under one of these two new tactics. A smaller set, centered on the former Impair Defenses techniques, has been revoked and reissued under new technique IDs. For analysts, this means most of your existing tags and mappings carry over as is, just under a more precise tactic, with a smaller, well-defined set of techniques needing a closer look.
ICS ATT&CK gains new sub-techniques. Sub-techniques give analysts a more granular way to describe how a technique is carried out, and this update extends that granularity to industrial control systems for the first time.
Mobile ATT&CK introduces detection strategies for the first time. This initial release covers Initial Access and Execution, with more planned in future releases, bringing Mobile closer in structure to what Enterprise ATT&CK already offers.
v19 also adds new techniques for AI-enabled and social engineering threats. New techniques like Query Public AI Services and Generate Content capture how adversaries are already using AI for reconnaissance and content creation, and a new Social Engineering parent technique consolidates related tactics like impersonation and email spoofing.
Taken together, these changes mean analysts working across Enterprise, ICS, and Mobile environments get a more consistent, more precise way to describe attacker behavior, including behavior increasingly shaped by AI. It's a good reminder that as adversaries adopt AI, defenders' tools need to as well, which is part of why this same release also expands Intelligence Center's own AI provider support.
Explore v19 changes with EclecticIQ's ATT&CK Navigator
Structural changes like a tactic split or a wave of new sub-techniques are easy to describe, but harder to actually explore, especially across hundreds of techniques and three separate matrices. That's where EclecticIQ's interactive ATT&CK Navigator comes in.
With the Navigator's matrix view and heatmaps, you can visualize how your threat intelligence maps against the updated framework: see where your organization's detections and coverage concentrate under the new Stealth and Defense Impairment tactics, explore the newly added ICS sub-techniques and Mobile detection strategies alongside your existing data, and quickly spot gaps or hotspots as your mappings shift to reflect v19.1.
If you haven't explored the Navigator yet, our earlier article covers how the matrix view and heatmaps work in more depth. Learn more about EclecticIQ's interactive ATT&CK Navigator and heatmap capabilities.
Stay current, stay precise
MITRE ATT&CK will keep evolving, and so will the way security teams use it. With Intelligence Center 3.9, your threat mappings stay aligned with this structural update, so your analysis keeps reflecting how the industry classifies threats today.
Want to see ATT&CK v19.1 support and the Navigator in action? Book a demo with our team.
