MITRE Engenuity
MITRE Engenuity is a non-profit cyber research foundation and MITRE subsidiary that develops threat-informed defense frameworks — most notably MITRE ATT&CK — and runs collaborative R&D programs for industry, government, and academic members.
- Company typePrivate
- Founded2019
- HeadquartersMclean, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What MITRE Engenuity does
MITRE Engenuity is a non-profit technology foundation established in 2019 as a subsidiary of MITRE Corporation, headquartered in McLean, Virginia. The organization operates R&D and standards programs that advance threat-informed defense across the cybersecurity ecosystem, with MITRE ATT&CK as its foundational contribution. Active programs include the Center for Threat-Informed Defense (a 50+ member research consortium), ATT&CK Evaluations (vendor benchmarking), the embedded Capture the Flag (eCTF) workforce-pipeline program, SOAR, the Semiconductor Alliance, and the Open Generation 5G Consortium. Methdodology is provided openly to the security community while monetization flows through membership dues, sponsorships, and managed services.
The organization's core technology is the ATT&CK knowledge base — a curated taxonomy of adversary tactics, techniques, and procedures — augmented by emulation tooling (CALDERA), adversary emulation plans, and the Technique Inference Engine, which uses ML to automate technique mapping from unstructured reports. Recent launches extend ATT&CK into operational technology (OT), AI/ML systems (Secure AI, MITRE ATLAS), semiconductors (CWE Environmental CVSS Calculator), and 5G. Revenue mechanics rely on member contributions, government grants, and a recently introduced Managed Services model for ATT&CK Evaluations. Customer base spans major cybersecurity vendors (Microsoft, CrowdStrike, Fortinet, Intel), financial institutions (JPMorgan Chase, Bank of America, Citi), and telecommunications (Verizon, Siemens), indicating a balanced, multi-industry membership base.
The foundation is positioned as a neutral convener between government, industry, and academia, leveraging MITRE Corporation's FFRDC heritage and brand trust. Its strategic posture is to expand ATT&CK coverage into new technology domains while maintaining the open-source ethos that has driven adoption; commercial-style product monetization is pursued selectively (e.g., Managed Services, MAD20 spinout) rather than as the primary model.
MITRE Engenuity firmographics
Firmographics- Name
- MITRE Engenuity
- Legal name
- MITRE Engenuity, LLC
- Website
- https://mitre-engenuity.org
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- MITRE Engenuity is a non-profit cyber research foundation and MITRE subsidiary that develops threat-informed defense frameworks — most notably MITRE ATT&CK — and runs collaborative R&D programs for industry, government, and academic members.
- Ownership category
- akta.pro rank
MITRE Engenuity industry classification
Industry- Product category
- Cybersecurity Research & Threat Intelligence
- NAICS
- Scientific Research and Development Services (5417), Management, Scientific, and Technical Consulting Services (5416)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Membership Organizations (8600)
- akta.pro primary industry
- Access Security & Identity Threat Detection (ITDR, UEBA for Identity) (HDADAAAI)
- akta.pro secondary industries
- Defense R&D, Test, Evaluation & Innovation (BPAIAHAC), STEM Assessment, Badging & Competition Platforms (EDAFANAJ)
Keywords
Where MITRE Engenuity is headquartered
LocationHeadquarters
- HQ city
- Mclean
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
MITRE Engenuity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations
Revenue model
- Center for Threat-Informed Defense Membership: The Center for Threat-Informed Defense is a privately funded R&D organization. Organizations with sophisticated security teams join as participant organizations, funding collaborative R&D. Results are freely available to the public.
- R&D Consortia: Bridging competitive organizations and thought leaders to collaborate for public good, leading to groundbreaking discoveries in cyber, semiconductors, telecommunications, and health.
- Impact Projects: Special research projects with industry to enable advancement of technology in the public interest.
- Grant-funded Studies: Strategic relationships with philanthropic foundations investing in public issues, such as the Bill and Melinda Gates Foundation grant for mDFS work.
- Subscription Platforms: Driving impact directly to individuals through fairly priced services.
- Startup Incubation: Incubating MITRE IP and innovating external venture-backed start-ups.
- MITRE ATT&CK Defender (MAD): Training and credentialing program for threat-informed defense. Now managed by MAD20 Technologies as a spinout from MITRE Engenuity.
Go-to-market motion3 records
Distribution channels7 records
Marketing channels11 records
MITRE Engenuity product offering
Product offeringCore offering
MITRE Engenuity is a non-profit technology organization and subsidiary of MITRE Corporation that conducts collaborative research and development to strengthen U.S. critical infrastructure and address pressing public-interest challenges in cybersecurity, semiconductors, 5G, and health. It operates programs such as the Center for Threat-Informed Defense, ATT&CK Evaluations, the embedded capture-the-flag (eCTF) program, the Semiconductor Alliance, and the Open Generation 5G consortium, and manages the MITRE ATT&CK knowledge base.
Differentiator
Problem solved
Functional benefit
Brands
- ATT&CK Evaluations: Objective analysis of cybersecurity products and features using the MITRE ATT&CK framework with threat-informed purple teaming approach.
- Center for Threat-Informed Defense
- MITRE ATT&CK Defender (MAD)
- Embedded Capture the Flag (eCTF)
- SOAR (Safely Operating Aircraft Remotely)
- Semiconductor Alliance
- Open Generation 5G Consortium
- Circuit Talk
Products and services
- MITRE ATT&CK Evaluations
Quantifiable outcome
- Nearly 800 students from 94 academic institutions participated in eCTF 2024
- +3 more outcomes
Companies that use MITRE Engenuity
Customer profileNamed customers8 records
Segments5 records
Ideal customer profiles2 records
MITRE Engenuity technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability10 records
Feature9 records
MITRE Engenuity partnerships and signals
Strategic signalPartnerships
30 partnerships are on record, tiered strategic spinout, core research partner, major sponsor, benefactor, non-profit participant and core members.
- MAD20 Technologiesstrategic spinoutMITRE Engenuity partnered with MAD20 Technologies to transfer management and scaling of the MITRE ATT&CK Defender (MAD) training and credentialing program. This was a strategic spinout where MAD20, a completely independent company, now has full responsibility for MAD operations.
- AttackIQcore research partnerAttackIQ is a Research Partner in the Center for Threat-Informed Defense, participating in collaborative R&D to advance threat-informed defense globally.
- Bank of Americacore research partnerBank of America is a Research Partner in the Center for Threat-Informed Defense, contributing to collaborative cybersecurity R&D.
- Citicore research partnerCiti is a Research Partner in the Center for Threat-Informed Defense, participating in collaborative cybersecurity research.
- CrowdStrikecore research partnerCrowdStrike is a Research Partner in the Center for Threat-Informed Defense, contributing to threat-informed defense advancement.
- Fortinetcore research partnerFortinet is a Research Partner in the Center for Threat-Informed Defense, participating in collaborative cybersecurity R&D.
- HCA Healthcarecore research partnerHCA Healthcare is a Research Partner in the Center for Threat-Informed Defense, contributing to healthcare-focused cybersecurity research.
- JPMorgan Chasecore research partnerJPMorgan Chase is a Research Partner in the Center for Threat-Informed Defense, participating in collaborative cybersecurity R&D.
- Lloyds Banking Groupcore research partnerLloyds Banking Group is a Research Partner in the Center for Threat-Informed Defense.
- Microsoftcore research partnerMicrosoft is a Research Partner in the Center for Threat-Informed Defense, contributing to collaborative cybersecurity research.
- Verizon Businesscore research partnerVerizon Business is a Research Partner in the Center for Threat-Informed Defense.
- Booz Allen Hamiltonmajor sponsorBooz Allen Hamilton is a Research Sponsor in the Secure AI project, collaborating on AI security research.
- Cato Networksmajor sponsorCato Networks is a Research Sponsor in the Secure AI project.
- Fujitsumajor sponsorFujitsu is a Research Sponsor in the Secure AI project, collaborating on AI security research.
- Infineonmajor sponsorInfineon is a Research Sponsor in the Center for Threat-Informed Defense.
- National Australia Bankmajor sponsorNAB is a Research Sponsor in the Center for Threat-Informed Defense.
- Safe Securitymajor sponsorSafe Security is a Research Sponsor in the Center for Threat-Informed Defense.
- Siemensmajor sponsorSiemens is a Research Sponsor in the Center for Threat-Informed Defense, contributing to OT security research.
- Standard Charteredmajor sponsorStandard Chartered is a Research Sponsor in the Center for Threat-Informed Defense.
- Tenablemajor sponsorTenable is a Research Sponsor in the Center for Threat-Informed Defense.
- AcalviobenefactorAcalvio is a Benefactor supporting the Center for Threat-Informed Defense.
- CoalfirebenefactorCoalfire is a Benefactor supporting the Center for Threat-Informed Defense.
- NVISObenefactorNVISO is a Benefactor supporting the Center for Threat-Informed Defense.
- SOC PrimebenefactorSOC Prime is a Benefactor supporting the Center for Threat-Informed Defense.
- Tidal CyberbenefactorTidal Cyber is a Benefactor supporting the Center for Threat-Informed Defense.
- ZimperiumbenefactorZimperium is a Benefactor supporting the Center for Threat-Informed Defense.
- Center for Internet Securitynon-profit participantCIS is a Non-Profit Participant in the Center for Threat-Informed Defense.
- FS-ISACnon-profit participantFS-ISAC (Financial Services Information Sharing and Analysis Center) is a Non-Profit Participant in the Center for Threat-Informed Defense.
- Global Cyber Alliancenon-profit participantGlobal Cyber Alliance is a Non-Profit Participant in the Center for Threat-Informed Defense.
- Intel, Micron, and Analog Devicescore membersThese semiconductor companies have joined MITRE Engenuity's Semiconductor Alliance, working to secure U.S. semiconductor technology innovation, manufacturing leadership, and supply chain resilience.
Scale indicators7 records
Recent moves8 records
Expansion highlights6 records
MITRE Engenuity competitors and assessment
Company assessmentOthers
- OASIS Open: OASIS Open is a non-profit standards organization that develops open standards for security, IoT, and other domains. It is comparable as a non-profit standards body but operates in adjacent rather than overlapping territory with MITRE Engenuity's threat-informed defense mission.
Direct peers
- SANS Institute: SANS Institute is a non-profit cybersecurity research and training organization that operates in the same threat-informed defense and workforce-development space as MITRE Engenuity — running GIAC certifications, research, and a global training community with strong overlap in mission and target audiences.
- MITRE Corporation: MITRE Corporation is the parent organization and direct operating peer. It operates federally funded R&D centers (FFRDCs) for the U.S. government and shares the same mission-driven non-profit structure, talent pool, and government-convener positioning that MITRE Engenuity leverages.
- FS-ISAC: FS-ISAC is the Financial Services Information Sharing and Analysis Center, a non-profit industry consortium for threat-intel sharing in financial services. It is comparable in operating model and is already a CTID non-profit participant, sharing MITRE Engenuity's convener-and-standards orientation.
- Center for Internet Security (CIS): CIS is a non-profit that develops widely adopted cybersecurity standards (CIS Controls, CIS Benchmarks) and operates the MS-ISAC. It is comparable to MITRE Engenuity as a non-profit creator of freely available cyber standards consumed by both public and private sectors, and is also a CTID non-profit participant.
- Software Engineering Institute (SEI) / CERT Division: SEI's CERT Division at Carnegie Mellon is a federally funded R&D center focused on cybersecurity research, software assurance, and workforce development — closely analogous to MITRE's FFRDC role and a natural peer for MITRE Engenuity's cyber R&D mission.
- Global Cyber Alliance: Global Cyber Alliance is a non-profit that builds practical, freely available cybersecurity toolkits and partnerships to reduce cyber risk. It mirrors MITRE Engenuity's model of producing open resources and is itself a CTID non-profit participant.
- Cyber Threat Alliance: The Cyber Threat Alliance is a non-profit industry consortium where cybersecurity vendors share threat intelligence — directly analogous to MITRE Engenuity's convener role at the Center for Threat-Informed Defense, with comparable membership structure and mission.
Regional players
- ENISA (European Union Agency for Cybersecurity): ENISA is the EU's cybersecurity agency, supporting member states and developing European cybersecurity frameworks and exercises. It is comparable in mission and public-sector orientation but operates regionally in Europe rather than competing directly with MITRE Engenuity's primarily U.S.-anchored programs.
Broad incumbents
- NIST (National Institute of Standards and Technology): NIST is the U.S. government's primary standards body and develops widely adopted cybersecurity frameworks (NIST CSF, SP 800-53). It overlaps with MITRE Engenuity's standards-and-frameworks work but operates at much broader scope across all of physical, cyber, and emerging-technology standards.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks7 records
Key highlights7 records
Customer concentration
MITRE Engenuity social profiles
Digital presenceMITRE Engenuity financial estimates
Financial estimateRevenue estimate
Valuation estimate
MITRE Engenuity leadership team
Management profileNumber of profiles
Profiles5 records
MITRE Engenuity subsidiaries and ownership
Company hierarchySubsidiaries1 record
MITRE Engenuity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
MITRE Engenuity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about MITRE Engenuity
What does MITRE Engenuity do?
MITRE Engenuity is a non-profit technology organization and subsidiary of MITRE Corporation that conducts collaborative research and development to strengthen U.S. critical infrastructure and address pressing public-interest challenges in cybersecurity, semiconductors, 5G, and health. It operates programs such as the Center for Threat-Informed Defense, ATT&CK Evaluations, the embedded capture-the-flag (eCTF) program, the Semiconductor Alliance, and the Open Generation 5G consortium, and manages the MITRE ATT&CK knowledge base.
Is MITRE Engenuity a public or private company?
MITRE Engenuity is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was MITRE Engenuity founded?
MITRE Engenuity was founded in 2019. It employs 11 to 50 people.
Where is MITRE Engenuity based?
MITRE Engenuity is headquartered in Mclean, United States, in the North America region.
How does MITRE Engenuity make money?
Seven revenue lines are on record. Center for Threat-Informed Defense Membership is the primary driver. The others are R&D Consortia, impact Projects, grant-funded Studies, subscription Platforms, startup Incubation and MITRE ATT&CK Defender (MAD).
Who are MITRE Engenuity's main competitors?
OASIS Open is listed as an others. Direct peers are SANS Institute, MITRE Corporation, FS-ISAC, Center for Internet Security (CIS), Software Engineering Institute (SEI) / CERT Division, Global Cyber Alliance and Cyber Threat Alliance. ENISA (European Union Agency for Cybersecurity) is listed as a regional player. NIST (National Institute of Standards and Technology) is listed as a broad incumbent.
Does MITRE Engenuity have an API?
No public API is recorded for MITRE Engenuity.
What industry is MITRE Engenuity in?
MITRE Engenuity's product category is Cybersecurity Research & Threat Intelligence. Its primary akta.pro industry code is HDADAAAI, Access Security & Identity Threat Detection (ITDR, UEBA for Identity), with a secondary code of BPAIAHAC, Defense R&D, Test, Evaluation & Innovation. Its NAICS code is 5417 and its SIC code is 8700.