MITRE ATT&CK
MITRE ATT&CK is a very well-recognized, freely available framework created by the non-profit MITRE Corporation. It defines a standardized way to use real-world observations for cyber threat analysis. It is organized into matrices and further refined to specific technologies, such as Windows, Linux, and iOS. The main matrices are enterprise, mobile, and industrial control systems (ICSs). There is also a new draft matrix specific to AI technologies called ATLAS.
The main components defined within the model are tactics, techniques, and sub-techniques. These are organized into a hierarchical structure, with tactics at the top and sub-techniques at the bottom. Tactics are the primary objectives of an attacker and are organized at the highest level of the model. Tactics include reconnaissance, resource development, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, C2, exfiltration...