Data AnalysisVerified
Reviewed and published by trentmaziarz, July 7, 2026. Discovered and drafted by our automated research pipeline.
MITRE's Center for Threat-Informed Defense offers TRAM (Threat Report ATT&CK Mapper), an open-source tool that uses machine learning and large language models to automatically identify and classify adversary tactics and techniques in cybersecurity threat intelligence reports. The tool assists security analysts who previously had to map reports manually.
Details
TRAM takes prose-based cyber threat intelligence (CTI) reports as input and outputs classifications mapping sentences or phrases to specific MITRE ATT&CK techniques. The latest version uses fine-tuned large language models to improve speed and accuracy of technique identification. The platform works out of the box to identify up to 50 common ATT&CK techniques and supports analyst validation of results. TRAM was developed in collaboration with industry partners including CrowdStrike, JPMorgan Chase, and HCA. The tool is freely available on GitHub and is actively maintained.
Products affected
TRAM (Threat Report ATT&CK Mapper)
Sources & Evidence
Company Disclosure
Cite this record
Trace Foundation. (2026). MITRE: MITRE's Center for Threat-Informed Defense offers TRAM (Threat Report ATT&CK Mapper), an open-source tool that uses machine learning and large language models to automatically identify and classify adversary tactics and techniques in cybersecurity threat intelligence reports. The tool assists security analysts who previously had to map reports manually (data as of 2026-07-07) [Data set record]. AI Trace. https://www.aitrace.org/r/practice/39537c26-3e9f-4038-8c20-9bebe3896992. Accessed October 6, 2026.
- Stable link
- https://www.aitrace.org/r/practice/39537c26-3e9f-4038-8c20-9bebe3896992
- Data as of
- July 7, 2026
- Last verified
- Not recorded
Other practices by MITRE
OtherMITRE deployed its AI Assurance and Discovery Lab in March 2024 at its McLean, Virginia headquarters to evaluate risks in AI-enabled systems for federal agencies and private companies. The lab uses simulated environments, AI red teaming, and large language model evaluation to identify security, bias, and performance risks before agencies adopt AI systems.OtherMITRE announced in December 2025 that it will operate two new AI Economic Security Centers on behalf of NIST, funded by a $20 million NIST investment, focused on applying AI to U.S. manufacturing productivity and securing critical infrastructure from cyberthreats. Both centers will leverage MITRE's Federal AI Sandbox and existing tools.OtherMITRE offers ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems), a publicly available knowledge base launched in June 2021 that catalogs the tactics and techniques adversaries use to attack AI and machine learning systems. It is freely accessible to security teams worldwide and is continuously updated.
Have evidence about MITRE's AI practices? Submit a report.
Report a Sighting →