LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1017: User Training

User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modules tailored to the organization's risk profile, covering topics such as phishing, password management, and incident reporting. - Provide role-specific training for high-risk employees, such as helpdesk staff or executives.

Use Simulated Exercises:

- Conduct phishing simulations to measure user susceptibility and provide targeted follow-up training. - Run social engineering drills to evaluate employee responses and reinforce protocols.

Leverage Gamification and Engagement:

- Introduce interactive learning methods such as quizzes, gamified challenges, and rewards for successful detection and reporting of threats.

Incorporate Security Policies into Onboarding:

- Include cybersecurity training as part of the onboarding process for new employees. - Provide easy-to-understand materials outlining acceptable use policies and reporting procedures.

Regular Refresher Courses:

- Update training materials to include emerging threats and techniques used by adversaries. - Ensure all employees complete periodic refresher courses to stay informed.

Emphasize Real-World Scenarios:

- Use case studies of recent attacks to demonstrate the consequences of successful phishing or social engineering. - Discuss how specific employee actions can prevent or mitigate such attacks.

EnterpriseM1017MitigationObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

User Training is a broad mitigation for attacks that depend on people taking an action, misreading a prompt, trusting a disguised file, installing an extension, using cloud/software deployment workflows, or mishandling credentials. Its business value is not “awareness” by itself; it is whether employees and contractors can recognize, avoid, and report behaviors that may lead to credential theft, valid account abuse, user execution, drive-by compromise, and persistence through extensions.

Executive priority

Treat this as a resilience and evidence program, not a one-time compliance exercise. Leaders should ask whether training is tailored to the organization’s real risk profile, whether high-risk roles such as executives and helpdesk staff receive role-specific content, and whether simulations produce measurable follow-up. Because ATT&CK maps this mitigation to credential access, valid accounts, cloud accounts, malicious links/files/images, browser or IDE extensions, and software deployment tools, training should be prioritized where a single user action could affect identity security, cloud access, or enterprise-wide administration.

Technical view

MITRE provides no detection guidance for this mitigation, so SOC and IR teams should validate operational outcomes rather than treat training as telemetry. Confirm that user reporting channels feed triage workflows, that phishing and social-engineering simulation results are reviewed with detection engineers, and that role-specific scenarios cover the related ATT&CK behaviors: OS credential dumping and LSASS/SAM/NTDS/LSA/cached credential risks, Valid Accounts including Domain and Cloud Accounts, User Execution via malicious links/files/images, MFA interception, masquerading including double extensions, drive-by compromise, browser/IDE extensions, browser session hijacking, and abuse of software deployment tools.

Likely telemetry

  • Training completion and refresher records for employees and contractors
  • Role-specific training records for high-risk users such as executives and helpdesk staff
  • Phishing simulation results, susceptibility metrics, and targeted follow-up records
  • Social engineering drill outcomes and exception handling records
  • User-submitted reports of suspicious emails, links, files, prompts, extensions, or cloud images

Detection direction

  • Do not measure coverage by completion rate alone; validate whether user reports create timely, actionable SOC cases.
  • Tune reporting workflows to reduce noise while preserving low-friction escalation for suspected phishing, malicious files, suspicious credential prompts, unauthorized extensions, and questionable cloud/container images.
  • Compare simulation outcomes with real incident reports to identify departments, roles, or workflows that need targeted follow-up.
  • Use relationship context to test whether users recognize double extensions, masqueraded files, unexpected MFA or credential prompts, malicious links, and risky extension or image installation paths.
  • Account for blind spots: training does not detect OS credential dumping, valid account abuse, or software deployment tool misuse by itself; those require technical telemetry and response playbooks.

Mitigation priorities

  • Start with a risk-profile-based training program covering phishing, password management, incident reporting, and user-driven execution scenarios.
  • Add role-specific training for high-risk populations, including executives, helpdesk staff, administrators, developers, and users of cloud or software deployment workflows when applicable.
  • Run recurring phishing simulations and social engineering drills, then provide targeted follow-up rather than generic reminders.
  • Embed security training into onboarding with clear acceptable-use and reporting procedures.
  • Refresh content regularly to include emerging adversary techniques and realistic scenarios tied to credential theft, account abuse, malicious files/links/images, extensions, and deceptive prompts.
Additional notes and limits

The most important decision point is whether the organization can prove behavior change and reporting effectiveness. For Glexia-style defensive planning, this mitigation should be mapped to identity and access management, SOC intake, incident response readiness, cloud governance, and compliance evidence. Its relationship set is broad, so local prioritization should be based on which related techniques are most relevant to the organization’s users, platforms, and business-critical workflows.

The ATT&CK object does not specify platforms or tactics for the mitigation and provides no official detection text. The relationships indicate techniques this mitigation may help address, but local evidence is required to determine effectiveness. No claims are made about active exploitation, attribution, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

User Training

User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modules tailored to the organization's risk profile, covering topics such as phishing, password management, and incident reporting. - Provide role-specific training for high-risk employees, such as helpdesk staff or executives.

Use Simulated Exercises:

- Conduct phishing simulations to measure user susceptibility and provide targeted follow-up training. - Run social engineering drills to evaluate employee responses and reinforce protocols.

Leverage Gamification and Engagement:

- Introduce interactive learning methods such as quizzes, gamified challenges, and rewards for successful detection and reporting of threats.

Incorporate Security Policies into Onboarding:

- Include cybersecurity training as part of the onboarding process for new employees. - Provide easy-to-understand materials outlining acceptable use policies and reporting procedures.

Regular Refresher Courses:

- Update training materials to include emerging threats and techniques used by adversaries. - Ensure all employees complete periodic refresher courses to stay informed.

Emphasize Real-World Scenarios:

- Use case studies of recent attacks to demonstrate the consequences of successful phishing or social engineering. - Discuss how specific employee actions can prevent or mitigate such attacks.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

60 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.003Spearphishing via ServiceSub-technique

Users can be trained to identify social engineering techniques and spearphishing messages with malicious links.

EnterpriseT1566.004Spearphishing VoiceSub-technique

Users can be trained to identify and report social engineering techniques and spearphishing attempts, while also being suspicious of and verifying the identify of callers.[1]

EnterpriseT1204User Execution

Use user training as a way to bring awareness to common phishing and spearphishing techniques and how to raise suspicion for potentially malicious events.

EnterpriseT1213.003Code RepositoriesSub-technique

Develop and publish policies that define acceptable information to be stored in code repositories.

EnterpriseT1552Unsecured Credentials

Ensure that developers and system administrators are aware of the risk associated with having plaintext passwords in software configuration files that may be left on endpoint systems or servers.

EnterpriseT1213.006DatabasesSub-technique

Develop and publish policies that define acceptable information to be stored in databases and acceptable handling of customer data. Only store information required for business operations.

EnterpriseT1036Masquerading

Train users not to open email attachments or click unknown links (URLs). Such training fosters more secure habits within your organization and will limit many of the risks.

EnterpriseT1213Data from Information Repositories

Develop and publish policies that define acceptable information to be stored in repositories.

EnterpriseT1598Phishing for Information

Users can be trained to identify social engineering techniques and spearphishing attempts.

EnterpriseT1213.001ConfluenceSub-technique

Develop and publish policies that define acceptable information to be stored in Confluence repositories.

EnterpriseT1078.002Domain AccountsSub-technique

Applications may send push notifications to verify a login as a form of multi-factor authentication (MFA). Train users to only accept valid push notifications and to report suspicious push notifications.

EnterpriseT1557.002ARP Cache PoisoningSub-technique

Train users to be suspicious about certificate errors. Adversaries may use their own certificates in an attempt to intercept HTTPS traffic. Certificate errors may arise when the application’s certificate does not match the one expected by the host.

EnterpriseT1598.003Spearphishing LinkSub-technique

Users can be trained to identify social engineering techniques and spearphishing attempts. Additionally, users may perform visual checks of the domains they visit; however, homographs in ASCII and in IDN domains and URL schema obfuscation may render manual checks difficult. Phishing training and other cybersecurity training may raise awareness to check URLs before visiting the sites.

EnterpriseT1213.005Messaging ApplicationsSub-technique

Develop and publish policies that define acceptable information to be posted in chat applications.

EnterpriseT1598.004Spearphishing VoiceSub-technique

Users can be trained to identify and report social engineering techniques and spearphishing attempts, while also being suspicious of and verifying the identify of callers.[1]

EnterpriseT1213.004Customer Relationship Management SoftwareSub-technique

Develop and publish policies that define acceptable information to be stored in CRM databases and acceptable handling of customer data. Only store customer information required for business operations.

EnterpriseT1684.001ImpersonationSub-technique

Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-person, to reduce risk.

EnterpriseT1598.001Spearphishing ServiceSub-technique

Users can be trained to identify social engineering techniques and spearphishing attempts.

EnterpriseT1557Adversary-in-the-Middle

Train users to be suspicious about certificate errors. Adversaries may use their own certificates in an attempt to intercept HTTPS traffic. Certificate errors may arise when the application’s certificate does not match the one expected by the host.

EnterpriseT1003.005Cached Domain CredentialsSub-technique

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

EnterpriseT1003OS Credential Dumping

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

EnterpriseT1003.003NTDSSub-technique

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

EnterpriseT1185Browser Session Hijacking

Close all browser sessions regularly and when they are no longer needed.

EnterpriseT1072Software Deployment Tools

Have a strict approval policy for use of deployment systems.

EnterpriseT1204.003Malicious ImageSub-technique

Train users to be aware of the existence of malicious images and how to avoid deploying instances and containers from them.

EnterpriseT1657Financial Theft

Train and encourage users to identify social engineering techniques used to enable financial theft. Also consider training users on procedures to prevent and respond to swatting and doxing, acts increasingly deployed by financially motivated groups to further coerce victims into satisfying ransom/extortion demands.[2][3]

EnterpriseT1555.005Password ManagersSub-technique

Provide user training on secure practices for managing credentials, including avoiding storing sensitive passwords in browsers and using password managers securely. Users should also be educated on identifying phishing attempts that could steal session cookies or credentials.

EnterpriseT1552.001Credentials In FilesSub-technique

Ensure that developers and system administrators are aware of the risk associated with having plaintext passwords in software configuration files that may be left on endpoint systems or servers.

EnterpriseT1036.007Double File ExtensionSub-technique

Train users to look for double extensions in filenames, and in general use training as a way to bring awareness to common phishing and spearphishing techniques and how to raise suspicion for potentially malicious events.

EnterpriseT1111Multi-Factor Authentication Interception

Remove smart cards when not in use.

EnterpriseT1204.005Malicious LibrarySub-technique

Train developers to be aware of the existence of malicious libraries and how to avoid installing them.

EnterpriseT1528Steal Application Access Token

Users need to be trained to not authorize third-party applications they don’t recognize. The user should pay particular attention to the redirect URL: if the URL is a misspelled or convoluted sequence of words related to an expected service or SaaS application, the website is likely trying to spoof a legitimate service. Users should also be cautious about the permissions they are granting to apps. For example, offline access and access to read emails should excite higher suspicions because adversaries can utilize SaaS APIs to discover credentials and other sensitive communications.

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Provide user training on secure practices for managing credentials, including avoiding storing sensitive passwords in browsers and using password managers securely. Users should also be educated on identifying phishing attempts that could steal session cookies or credentials.

EnterpriseT1598.002Spearphishing AttachmentSub-technique

Users can be trained to identify social engineering techniques and spearphishing attempts.

EnterpriseT1176.002IDE ExtensionsSub-technique

Train users to minimize IDE extension use, and to only install trusted extensions.

EnterpriseT1176Software Extensions

Train users to minimize extension use, and to only install trusted extensions.

EnterpriseT1221Template Injection

Train users to identify social engineering techniques and spearphishing emails that could be used to deliver malicious documents.

EnterpriseT1003.001LSASS MemorySub-technique

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

EnterpriseT1056.002GUI Input CaptureSub-technique

Use user training as a way to bring awareness and raise suspicion for potentially malicious events and dialog boxes (ex: Office documents prompting for credentials).

EnterpriseT1556.001Domain Controller AuthenticationSub-technique

Train users to recognize and handle suspicious email attachments. Emphasize the importance of caution when opening attachments from unknown or unexpected sources, even if they appear legitimate. Implement email warning banners to alert users about emails originating from outside the organization or containing attachments, reinforcing awareness and helping users identify potential spearphishing attempts.

EnterpriseT1557.004Evil TwinSub-technique

Train users to be suspicious about access points marked as “Open” or “Unsecure” as well as certificate errors. Certificate errors may arise when the application’s certificate does not match the one expected by the host.

EnterpriseT1176.001Browser ExtensionsSub-technique

Close out all browser sessions when finished using them to prevent any potentially malicious extensions from continuing to run.

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Users can be trained to identify social engineering techniques and spearphishing emails.

EnterpriseT1189Drive-by Compromise

Train users to be aware of access or manipulation attempts by an adversary to reduce the risk of successful spearphishing, social engineering, and other techniques that involve user interaction.

EnterpriseT1078.004Cloud AccountsSub-technique

Applications may send push notifications to verify a login as a form of multi-factor authentication (MFA). Train users to only accept valid push notifications and to report suspicious push notifications.

EnterpriseT1213.002SharepointSub-technique

Develop and publish policies that define acceptable information to be stored in SharePoint repositories.

EnterpriseT1566.002Spearphishing LinkSub-technique

Users can be trained to identify social engineering techniques and spearphishing emails with malicious links which includes phishing for consent with OAuth 2.0. Additionally, users may perform visual checks of the domains they visit; however, homographs in ASCII and in IDN domains and URL schema obfuscation may render manual checks difficult. Use email warning banners to alert users when emails contain links from external senders, prompting them to exercise caution and reducing the likelihood of falling victim to spearphishing attacks. Phishing training and other cybersecurity training may raise awareness to check URLs before visiting the sites.

EnterpriseT1684Social Engineering

Reduces success of phishing/vishing/impersonation and modern “human interface” lures.[4][5][6]

EnterpriseT1552.008Chat MessagesSub-technique

Ensure that developers and system administrators are aware of the risk associated with sharing unsecured passwords across communication services.

EnterpriseT1204.001Malicious LinkSub-technique

Use user training as a way to bring awareness to common phishing and spearphishing techniques and how to raise suspicion for potentially malicious events.

EnterpriseT1204.002Malicious FileSub-technique

Use user training as a way to bring awareness to common phishing and spearphishing techniques and how to raise suspicion for potentially malicious events.

EnterpriseT1003.002Security Account ManagerSub-technique

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

EnterpriseT1003.004LSA SecretsSub-technique

Limit credential overlap across accounts and systems by training users and administrators not to use the same password for multiple accounts.

EnterpriseT1078Valid Accounts

Applications may send push notifications to verify a login as a form of multi-factor authentication (MFA). Train users to only accept valid push notifications and to report suspicious push notifications.

EnterpriseT1566Phishing

Users can be trained to identify social engineering techniques and phishing emails.

EnterpriseT1667Email Bombing

Train users to be aware of access or manipulation attempts by an adversary to reduce the risk of successful social engineering via e-mail bombing.

EnterpriseT1027Obfuscated Files or Information

Ensure that a finite amount of ingress points to a software deployment system exist with restricted access for those required to allow and enable newly deployed software.

EnterpriseT1547.007Re-opened ApplicationsSub-technique

Holding the Shift key while logging in prevents apps from opening automatically.[7]

EnterpriseT1539Steal Web Session Cookie

Train users to identify aspects of phishing attempts where they're asked to enter credentials into a site that has the incorrect domain for the application they are logging into. Additionally, train users not to run untrusted JavaScript in their browser, such as by copying and pasting code or dragging and dropping bookmarklets.

EnterpriseT1621Multi-Factor Authentication Request Generation

Train users to only accept 2FA/MFA requests from login attempts they initiated, to review source location of the login attempt prompting the 2FA/MFA requests, and to report suspicious/unsolicited prompts.

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
b8d3c5e787238b0e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundleb8d3c5e78723…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA Phishing

    CISA. (2021, February 1). Avoiding Social Engineering and Phishing Attacks. Retrieved September 8, 2023.

    Open source URL
  2. [2]
    Cyber Safety Review Board: Lapsus

    CISA. (2023, August). Cyber Safety Review Board: Lapsus. Retrieved January 5, 2024.

    Open source URL
  3. [3]
    SWAT-hospital

    Giles, Bruce. (2024, January 4). Hackers threaten to send SWAT teams to Fred Hutch patients' homes. Retrieved January 5, 2024.

    Open source URL
  4. [4]
    SE SentinelOne 2

    SentinelOne. (2025, August 19). 15 Types of Social Engineering Attacks. Retrieved April 15, 2026.

    Open source URL
  5. [5]
    Sophos User Interaction

    Jagadeesh Chandraiah, Tonmoy Jitu, Dmitry Samosseiko, Matt Wixey. (2026, March 11). Evil evolution: ClickFix and macOS infostealers. Retrieved April 15, 2026.

    Open source URL
  6. [6]
    Unit 42 Global Incident Response Report 2026

    Palo Alto Networks Unit 42. (n.d.). Global Incident Response Report 2026. Retrieved April 15, 2026.

    Open source URL
  7. [7]
    Re-Open windows on Mac

    Apple. (2016, December 6). Automatically re-open windows, apps, and documents on your Mac. Retrieved July 11, 2017.

    Open source URL
  8. [8]
    mitre-attackM1017
    Open source URL
  9. [9]
    mitre-attackM1017
    Open source URL
  10. [10]
    mitre-attackM1017
    Open source URL
  11. [11]
    CISA Phishing

    CISA. (2021, February 1). Avoiding Social Engineering and Phishing Attacks. Retrieved September 8, 2023.

    Open source URL
  12. [12]
    CISA Phishing

    CISA. (2021, February 1). Avoiding Social Engineering and Phishing Attacks. Retrieved September 8, 2023.

    Open source URL
  13. [13]
    CISA Phishing

    CISA. (2021, February 1). Avoiding Social Engineering and Phishing Attacks. Retrieved September 8, 2023.

    Open source URL
  14. [14]
    Cyber Safety Review Board: Lapsus

    CISA. (2023, August). Cyber Safety Review Board: Lapsus. Retrieved January 5, 2024.

    Open source URL
  15. [15]
    SWAT-hospital

    Giles, Bruce. (2024, January 4). Hackers threaten to send SWAT teams to Fred Hutch patients' homes. Retrieved January 5, 2024.

    Open source URL
  16. [16]
    SE SentinelOne 2

    SentinelOne. (2025, August 19). 15 Types of Social Engineering Attacks. Retrieved April 15, 2026.

    Open source URL
  17. [17]
    Sophos User Interaction

    Jagadeesh Chandraiah, Tonmoy Jitu, Dmitry Samosseiko, Matt Wixey. (2026, March 11). Evil evolution: ClickFix and macOS infostealers. Retrieved April 15, 2026.

    Open source URL
  18. [18]
    Unit 42 Global Incident Response Report 2026

    Palo Alto Networks Unit 42. (n.d.). Global Incident Response Report 2026. Retrieved April 15, 2026.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.