MITRE ATT&CK
MITRE ATT&CK is a globally used knowledge base of real-world adversary tactics and techniques, used to describe how attackers operate and to map defensive coverage.
ATT&CK catalogs the tactics (the 'why') and techniques (the 'how') attackers use across the intrusion lifecycle, each with a stable identifier (e.g., T1078, Valid Accounts). Defenders use it to reason about coverage and detection gaps.
Where relevant, Vigil ties findings to the ATT&CK technique an attacker would use to exploit them, connecting a misconfiguration to concrete adversary behavior.
Vigil references the Enterprise matrix, currently ATT&CK v19. Technique identifiers are stable across releases, so a mapping recorded against an earlier version remains valid as the catalog evolves.