ATT&CK v19 shipped on April 28, 2026, and it did something the framework has largely avoided in its previous releases: it retired a tactic. Defense Evasion — for years the largest and most unwieldy column in the Enterprise matrix — no longer exists as a tactic. Its techniques now live under two successors, Stealth and Defense Impairment.

For teams that treat ATT&CK as a wall poster, this is trivia. For teams that have wired tactic IDs into detection rules, coverage dashboards, purple-team scorecards, or customer-facing reports, it is a breaking change with a specific and enumerable blast radius.

What actually changed

Per MITRE’s April 2026 release notes, the split produced:

  • Stealth — TA0005. This inherits the old Defense Evasion tactic ID. It covers techniques where the adversary is trying to blend into legitimate behavior or avoid producing a signal at all.
  • Defense Impairment — TA0112. A newly issued tactic ID. It covers techniques where the adversary actively degrades, disables, or tampers with a security control.

The ID inheritance is the part that will bite people. TA0005 did not get retired — it got redefined. A query, dashboard, or report that filters on TA0005 will keep returning results and will keep looking healthy. It is simply answering a narrower question than it was before, and the techniques that moved to TA0112 have quietly fallen out of the result set. Nothing errors. The number just gets smaller, or worse, stays plausible.

This is a different failure mode from a deprecated ID, which announces itself. Silent scope reduction on a still-valid identifier is the kind of change that survives a release-notes skim.

Note also that the correct new tactic name is Defense Impairment (TA0112). A good deal of the secondary commentary published around the release called it “Impair Defenses,” which is understandable — Impair Defenses (T1562) is a long-standing ATT&CK technique — but the two are not the same object, and mixing them up in a mapping document produces a tactic-to-technique reference that does not resolve.

The conceptual line MITRE drew

The distinction is worth internalizing because it maps onto genuinely different detection strategies.

Stealth is about the absence of a signal. Masquerading, obfuscated files, valid-account abuse, living-off-the-land binaries — the adversary’s goal is that the activity looks like something you would never alert on. Detecting it is a baselining and anomaly problem. You are looking for the legitimate-looking thing that is legitimate-looking in the wrong context: the right binary in the wrong parent process, the right account at the wrong hour from the wrong host.

Defense Impairment is about interference with the signal. Disabling event logging, killing EDR processes, modifying security tool configurations, clearing Windows event logs. Detecting it is closer to an integrity and telemetry-health problem. The high-value detections here are frequently meta-detections: not “did something bad happen” but “did my ability to see whether something bad happened just degrade.”

That second category is chronically under-instrumented. Most SOCs alert well on malicious activity and poorly on the disappearance of telemetry. If the split prompts one change in your program, make it this one — build detections for your own sensors going quiet. An EDR agent that stops reporting is either a broken build, a decommissioned host, or an adversary, and you should be able to tell which without a human noticing the gap on a dashboard days later.

The migration work, in priority order

1. Inventory every place a tactic ID is stored, not just where it is displayed. Detection rule metadata, SIEM content packs, case-management templates, coverage-heatmap tooling, threat-intel platform mappings, and any report template that renders tactic names. In most environments the tactic ID has leaked into more places than the detection engineering team owns.

2. Re-map the techniques that moved to TA0112. This is mechanical but must be done against the current ATT&CK STIX bundle rather than by hand — the technique-to-tactic relationships are the authoritative record, and a hand-built list will drift on the next release.

3. Re-baseline your coverage metrics before you report them. If you publish a coverage percentage to leadership or to customers, that number changed on April 28 for reasons that have nothing to do with your defensive posture. Publishing a v18-basis figure next to a v19-basis figure as if they were a trend line is the sort of thing that gets noticed later and retroactively discredits the whole metric. Re-baseline, and say in the report that you re-baselined.

4. Check your vendor content packs before assuming they migrated. Detection content shipped by security vendors updates on the vendor’s schedule, not MITRE’s. It is entirely normal for a platform to be several ATT&CK versions behind in its bundled mappings. Ask specifically which ATT&CK version a content pack targets.

What else landed in v19

The Defense Evasion split absorbed most of the attention, but two other additions matter for threat modeling.

ATT&CK added explicit AI-related techniques, including Query Public AI Services (T1682) and Generate Content (T1683), alongside a restructured Social Engineering (T1684) with sub-techniques for Impersonation and Email Spoofing. The framework is beginning to model adversary use of generative tooling as first-class technique behavior rather than as a footnote to phishing.

MITRE also added a new campaign entry, Anthropic AI-orchestrated Campaign (C0062). Campaign entries are worth watching as a category: they are where ATT&CK records that a specific set of techniques was actually observed in sequence, which is more useful for scenario design than a flat technique list.

MITRE has described this release as phase one, with further technique-description updates and scope realignment in subsequent releases. That is a reason to build your mapping process to be re-runnable rather than to treat this migration as a one-time cleanup.

The practical read

The split is a genuine improvement to the framework. Defense Evasion had become a catch-all that grouped “hid from the sensor” and “turned the sensor off” under a single heading, which are not the same adversary behavior and do not call for the same detection engineering. Separating them makes coverage gaps more legible.

But the framework getting clearer does not make your mappings correct. The specific risk in this release is a redefined identifier that still resolves, so the work is to go find every stored TA0005 and decide, deliberately, whether it still means what the person who wrote it intended.