AI Buyer Insights:

Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

Michelin, an e2open customer evaluated Oracle Transportation Management

Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

Wayfair, a Korber HighJump WMS customer just evaluated Manhattan WMS

Moog, an UKG AutoTime customer evaluated Workday Time and Attendance

Michelin, an e2open customer evaluated Oracle Transportation Management

Cantor Fitzgerald, a Kyriba Treasury customer evaluated GTreasury

Swedbank, a Temenos T24 customer evaluated Oracle Flexcube

Westpac NZ, an Infosys Finacle customer evaluated nCino Bank OS

Citigroup, a VestmarkONE customer evaluated BlackRock Aladdin Wealth

List of MITRE ATT&CK Customers

loading spinner icon

Apply Filters For Customers

Logo Customer Industry Empl. Revenue Country Vendor Application Category When SI Insight
Elliott Investment Management Banking and Financial Services 657 $120M United States MITRE MITRE ATT&CK Threat Modeling 2020 n/a
In 2020, Elliott Investment Management implemented MITRE ATT&CK to formalize Threat Modeling within its security operations and cybersecurity teams. The initiative served as the canonical tactics and techniques framework for two documented red teaming projects executed by the security operations organization, aligning adversary emulation activities with detection and response planning. MITRE ATT&CK was used to map attack techniques to detection controls and to drive detection engineering, with analysts developing Splunk queries and risk rules explicitly tied to ATT&CK tactics. Automated Cymulate penetration testing was leveraged to assess a range of MITRE ATT&CK tactics and techniques, while Vulcan Cyber was used in the vulnerability management workflow to prioritize remediation against mapped adversary behavior. Automation and tooling were extended through PowerShell and low-level Python scripting to operationalize tests and rule deployment. Operational coverage focused on security operations, detection engineering, red team exercises, and vulnerability management, with workflows structured to feed test results and detection rules into the SOC. MITRE ATT&CK functioned as the central Threat Modeling artifact that linked adversary emulation, automated testing, and Splunk-based detection across Elliott Investment Management security teams.
ExxonMobil Oil, Gas and Chemicals 57900 $323.9B United States MITRE MITRE ATT&CK Threat Modeling 2021 n/a
In 2021 ExxonMobil implemented the MITRE ATT&CK framework as a core element of its Threat Modeling capability to standardize Tactics, Techniques, and Procedures mapping across SOC operations. The deployment anchored threat hunting and incident response workflows, integrating threat intelligence outputs into detection engineering and operational playbooks. The implementation focused on functional modules for TTP mapping, detection rule development, threat hunting, and SOAR orchestration. MITRE ATT&CK was used to drive creation of custom detection rules and dashboards in Splunk, and to inform playbooks in Splunk Phantom SOAR, enabling automated alert triage and workflow escalation. Priority Intelligence Requirements were formalized to guide collection and analysis, and detection content was aligned with ISO 27001 control assessments. Integrations were explicit and extensive, ingesting CTI feeds into Splunk and Anomali ThreatStream, and operationalizing intelligence from Recorded Future for actor profiling. Endpoint telemetry from SentinelOne, web controls via iBoss Proxy, vulnerability data from Nexpose and InsightVM, and cloud posture signals from Palo Alto Prisma Cloud were correlated to MITRE ATT&CK techniques. Nozomi Networks data extended coverage into ICS and OT environments, and tools such as Maltego supported investigative enrichment. Python and PowerShell scripting were used to automate data ingestion, log parsing, and endpoint management tasks. Operational scope covered enterprise SOC workflows, incident response teams, cloud security for Azure and AWS environments, and ICS/OT security monitoring. Governance and process changes included codifying PIRs, authoring detection playbooks, integrating CTI into dashboards and SentinelOne views, and collaborating with third party red teams to validate mapped adversary behaviors. The initiative expressly improved detection capabilities and streamlined SOC operations, enabling faster triage and response for high priority incidents.
HCA Healthcare Healthcare 230000 $75.6B United States MITRE MITRE ATT&CK Threat Modeling 2019 n/a
In 2019, HCA Healthcare joined the Center for Threat-Informed Defense as a founding Research Partner and adopted MITRE ATT&CK to drive threat-informed defense across its healthcare security operations in the United States. HCA Healthcare implemented MITRE ATT&CK as a central Threat Modeling reference to structure detection logic and threat hunting workflows across its security operations centers. The deployment used ATT&CK mappings to prioritize detections and to drive detection engineering, threat hunting, and SOC playbook adjustments. HCA contributed to R&D projects such as the ATT&CK Workbench, leveraging the ATT&CK framework to codify observed adversary behaviors and map those behaviors to analytic and telemetry requirements. Operational scope included enterprise security operations across HCA Healthcare sites in the United States, where ATT&CK-aligned mappings were incorporated into detection content and SOC procedures. The implementation focused on aligning defensive controls and monitoring use cases to observed tactics, techniques, and procedures, and on operationalizing ATT&CK terminology within incident response and monitoring workflows. Governance and rollout were coordinated through research partnership activities and internal SOC process updates, with ATT&CK serving as the common taxonomy for prioritization and control alignment. As a result of the adoption HCA Healthcare prioritized detections, improved SOC processes, and aligned defensive controls to observed adversary behaviors as part of its Threat Modeling practice using MITRE ATT&CK.
Inspira Enterprise Professional Services 1500 $200M India MITRE MITRE ATT&CK Threat Modeling 2022 n/a
In 2022, Inspira Enterprise implemented MITRE ATT&CK for Threat Modeling to formalize adversary technique mapping within its Security Operations Center and threat intelligence practice. The MITRE ATT&CK deployment was positioned to support SOC analysts and information security analysts in Maharashtra, India, aligning the application with incident triage, threat hunting, and IOC enrichment workflows. The implementation focused on mapping detection use cases and playbooks to ATT&CK techniques, developing correlation rules, parsers, and dashboards that reflect attacker tactics and techniques. Functional capabilities implemented include threat hunting workflows driven by hypothesis-led analysis, IOC enrichment using telemetry and OSINT, and structured ATT&CK-based incident classification for consistent triage and remediation guidance. MITRE ATT&CK was integrated into an existing telemetry and detection stack, including SIEM tools RSA NetWitness, Splunk, and QRadar, a Threat Intelligence Platform, iZOOlogic brand monitoring, Zscaler logs, deception platforms, UEBA, NBAD, and packet capture analysis. These integrations enabled correlation of external intelligence feeds and internal alerts, allowing SOC teams to connect IOCs such as IPs, hashes, and domains to ATT&CK techniques and to surface potential targeted attacks within SIEM alert streams. Governance and operationalization included creation of SOPs, incident handling documents, and playbooks that reference ATT&CK mapping, weekly and monthly SOC performance reporting, and shift management practices to ensure continuity during SOC lead absence. The ATT&CK-based workflows were explicitly used to enhance detection and to improve detection accuracy through refined correlation rules and ongoing tuning of detection use cases.
JPMorganChase Banking and Financial Services 317233 $180.6B United States MITRE MITRE ATT&CK Threat Modeling 2019 n/a
In 2019, JPMorgan Chase joined MITRE Engenuity's Center for Threat-Informed Defense and began using MITRE ATT&CK for Threat Modeling. The collaboration concentrated on ATT&CK-based research and cloud security mappings conducted with MITRE in the United States, establishing a formal channel for shared mappings and tooling contributions. JPMorgan Chase applied the MITRE ATT&CK framework to inform SOC operations, cloud control assessments, and broader threat informed defense improvements. Implementation activities centered on mapping adversary tactics and techniques to detection coverage and control gaps, aligning telemetry and detection engineering workflows, and developing threat hunting playbooks consistent with Threat Modeling practices. Operationally, the ATT&CK-based mappings were integrated into SOC workflows and cloud control assessment processes, supporting cloud security evaluations and incident detection across the bank's U.S. environments. JPMorgan Chase contributed expertise and telemetry-derived data back to public mappings and tools, reinforcing the two way flow between the bank and MITRE's community resources. Governance and rollout focused on embedding ATT&CK nomenclature into existing assessment and detection change processes, enabling standardized threat modeling across security teams and cloud program owners. The engagement with MITRE and adoption of MITRE ATT&CK supported ongoing threat informed defense improvements while maintaining alignment with institutional security assessment and SOC governance processes.
Transportation 70000 $21.3B United States MITRE MITRE ATT&CK Threat Modeling 2019 n/a
Professional Services 228000 $331.8B United States MITRE MITRE ATT&CK Threat Modeling 2019 n/a
Healthcare 45000 $11.0B United States MITRE MITRE ATT&CK Threat Modeling 2020 n/a
Banking and Financial Services 2185 $1.3B Canada MITRE MITRE ATT&CK Threat Modeling 2021 n/a
Showing 1 to 9 of 9 entries

Buyer Intent: Companies Evaluating MITRE ATT&CK

ARTW Buyer Intent uncovers actionable customer signals, identifying software buyers actively evaluating MITRE ATT&CK. Gain ongoing access to real-time prospects and uncover hidden opportunities. Companies Actively Evaluating MITRE ATT&CK for Threat Modeling include:

  1. MITRE Corporation, a United States based Non Profit organization with 9000 Employees

Discover Software Buyers actively Evaluating Enterprise Applications

Logo Company Industry Employees Revenue Country Evaluated
MITRE Corporation Non Profit 9000 $2.4B United States 2026-02-27
FAQ - APPS RUN THE WORLD MITRE ATT&CK Coverage

MITRE ATT&CK is a Threat Modeling solution from MITRE.

Companies worldwide use MITRE ATT&CK, from small firms to large enterprises across 21+ industries.

Organizations such as Microsoft, ExxonMobil, JPMorganChase, HCA Healthcare and Metropolitan Transportation Authority (MTA) are recorded users of MITRE ATT&CK for Threat Modeling.

Companies using MITRE ATT&CK are most concentrated in Professional Services, Oil, Gas and Chemicals and Banking and Financial Services, with adoption spanning over 21 industries.

Companies using MITRE ATT&CK are most concentrated in United States, with adoption tracked across 195 countries worldwide. This global distribution highlights the popularity of MITRE ATT&CK across Americas, EMEA, and APAC.

Companies using MITRE ATT&CK range from small businesses with 0-100 employees - 0%, to mid-sized firms with 101-1,000 employees - 11.11%, large organizations with 1,001-10,000 employees - 22.22%, and global enterprises with 10,000+ employees - 66.67%.

Customers of MITRE ATT&CK include firms across all revenue levels — from $0-100M, to $101M-$1B, $1B-$10B, and $10B+ global corporations.

Contact APPS RUN THE WORLD to access the full verified MITRE ATT&CK customer database with detailed Firmographics such as industry, geography, revenue, and employee breakdowns as well as key decision makers in charge of Threat Modeling.