Executive Summary
Facts Only
* Defense Evasion split: Defense Evasion (TA0005) is replaced by Stealth and Defense Impairment (TA0112).
* Techniques previously in Defense Evasion were moved to Stealth or Defense Impairment, or other tactics.
* T1562, T1562.001, and T1562.006 were merged into T1685: Disable or Modify Tools.
* New techniques added include T1687: Exploitation for Defense Impairment and T1686.003: Disable or Modify System Firewall: Windows Host Firewall.
* Social Engineering techniques, T1656: Impersonation and T1672: Email Spoofing, were moved under the new parent technique T1684: Social Engineering.
* New AI-related techniques include T1682: Query Public AI Services and T1683: Generate Content (with sub-techniques).
* New social engineering structure includes T1684: Social Engineering, which incorporates T1684.001 and T1684.002.
* ICS sub-techniques were introduced for parent techniques including Modify Firmware (T1693), Block Communications (T1695), Remote System Discovery (T0846), Program Download (T0843), and Insecure Credentials (T1694).
* Mobile detection strategies are expanded to include platform-specific guidance for Android (AN1739) and iOS (AN1740) persistence monitoring.
Full Take
The restructuring of Defense Evasion into Stealth and Defense Impairment reflects a necessary shift from grouping actions based on the immediate goal of the adversary to grouping them based on the resulting impact on the defensive posture. This split forces analysts to consider not just what the attacker is hiding, but what actions are actively sabotaging controls. The process of mapping older techniques to these new intents inherently creates tension; an action that was purely evasive might now be viewed through the lens of impairment if it directly disables monitoring tools.
The introduction of AI-orchestrated and multi-channel social engineering techniques suggests a move toward behavior-centric defense that transcends channel-specific analysis. By grouping Impersonation and Email Spoofing under Social Engineering, the framework moves away from treating channels as separate silos towards recognizing trust manipulation as a unifying adversary objective. This suggests a pattern of recognition: adversaries use the most permissive vector available to achieve a goal, demanding detection logic focused on the resultant manipulation rather than the delivery mechanism.
The ICS granularization signals an acknowledgement that physical and communication control is increasingly important for operational security. Moving from broad concepts to specific firmware and network layer sub-techniques implies that visibility at the device and protocol level is becoming critical for effective defense. The overarching implication is a push toward contextual awareness: recognizing that modern threats are not just sequences of steps, but interconnected activities where AI accelerates research, social engineering exploits trust gaps, and ICS manipulation affects physical integrity simultaneously. What downstream costs arise if detection strategies remain siloed in either the "stealth" or "impairment" context when an activity bridges both?
From the original · MITRE ATT&CK Blog
ATT&CK v19: The Defense Evasion Split, ICS Sub-Techniques, New AI & Social Engineering Coverage, and Detection Strategies for Mobile ATT&CK v19 is here, and this release has been a long time coming.Read the full story at medium.com
Sentinel — Human
The text reads like a technical summary or release note written by an expert familiar with the MITRE ATT&CK framework, employing precise, structured language typical of official documentation updates.
