
Sophos achieves 100% detection in the MITRE ATT&CK® Enterprise 2025 Evaluation
MITRE ATT&CK® Evaluations: Enterprise 2025
MITRE ATT&CK® Evaluations emulate the tactics, techniques, and procedures (TTPs) leveraged by real-world adversarial groups and evaluate each participating vendor’s ability to detect, analyze, and describe threats, with output aligned to the language and structure of the MITRE ATT&CK® Framework.
The Enterprise 2025 evaluation included MITRE’s first-ever cloud adversary emulation and addressed the sophisticated, multi-platform threats organizations face from both financially motivated cyber criminals and state-sponsored espionage groups:
- Scattered Spider: A financially motivated cybercriminal syndicate
Known for their expertise in social engineering, this threat group persistently targets victims’ cloud resources to establish footholds, conduct reconnaissance, and access sensitive systems and data. - Mustang Panda: A PRC-linked cyber espionage group
An active People's Republic of China state-sponsored cyber espionage group that employs living-off-the-land techniques, custom malware, and cloud-hosted infrastructure.
Evaluation results
Sophos successfully detected and provided actionable alerts for 100% of sub-steps1 across two comprehensive attack scenarios:











