Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations

Eleven companies took part in the evaluations and several have boasted 100% detection and coverage rates.

MITRE

MITRE has published the results of the 2025 ATT&CK Evaluations for enterprise cybersecurity solutions.

Eleven companies took part this year: Acronis, AhnLab, CrowdStrike, Cyberani, Cybereason, Cynet, ESET, Sophos, Trend Micro, WatchGuard, and WithSecure.

The MITRE ATT&CK Evaluations are independent assessments designed to test the effectiveness of commercial cybersecurity products against real-world attack scenarios.

This year’s evaluations focused on two scenarios: one inspired by attacks conducted by the notorious cybercrime group Scattered Spider, and one inspired by the Chinese state-sponsored threat actor Mustang Panda.

The Scattered Spider scenario marked the first time MITRE’s assessment tested cybersecurity products against attacks involving cloud infrastructure.

The federally funded research center also tested the ability of products to detect adversary reconnaissance activities for the first time. 

Advertisement. Scroll to continue reading.

“The evaluation framework has been enhanced to place greater emphasis on protection, focusing on a solution’s ability to block adversaries and contain threats in real time. The detection evaluation has been rebalanced to prioritize high-fidelity alerts that deliver actionable context for security operations teams, helping to reduce alert fatigue,” MITRE explained.

The results of the 2025 ATT&CK Evaluations are available on the MITRE website.

As always, MITRE has pointed out that “the evaluations do not rank vendors but provide objective, evidence-based results that enable organizations to determine which cybersecurity solutions fit their specific needs”.

Several participating cybersecurity companies have boasted about the results they obtained in the latest MITRE ATT&CK Evaluations. Although they avoided outright declarations of victory, as some did in past years, several firms highlighted their attainment of 100% detection and protection rates within specific evaluation categories.

Allie Mellen, principal analyst at Forrester, pointed out after last year’s evaluations that vendor claims about getting 100% should not be trusted

“If a vendor says that it achieved 100% on the evaluations, it is likely doing one or more of the following: manipulating the results by only showing parts of results that they feel benefit them; turning on settings in the product that are unrealistic for a real-world environment so as to appear more effective; treating the results as a competition instead of a learning opportunity and a chance to improve the product.”

Major companies such as Microsoft, Palo Alto Networks, and SentinelOne withdrew from the evaluations this year, stating that the MITRE program requires a resource-intensive commitment, leading them to allocate resources elsewhere.

Related: MITRE Unveils ATT&CK v18 With Updates to Detections, Mobile, ICS

Related: AMTSO Releases Sandbox Evaluation Framework

Related: MITRE Updates List of Most Common Hardware Weaknesses

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.