---
title: SecurityTactic enum | Wartiva GraphQL API
description: Security tactics correspond to MITRE ATT&CK tactics. Wartiva GraphQL API reference with arguments, fields, and examples.
url: https://wartiva.com/api-docs/types/security-tactic.html
updated: 2026-10-07
---

Policies and findings · GraphQL enum

# `SecurityTactic` enum

Security tactics correspond to [MITRE ATT&CK tactics](https://attack.mitre.org/).

## Values

| Enum Value | Description |
|---|---|
| `RECONNAISSANCE` | MITRE ATT&CK TA0043: adversary is trying to gather information. |
| `INITIAL_ACCESS` | MITRE ATT&CK TA0001: adversary is trying to get into your network. |
| `DISCOVERY` | MITRE ATT&CK TA0007: adversary is trying to figure out your environment. |
| `EXECUTION` | MITRE ATT&CK TA0002: adversary is trying to run malicious code. |
| `PERSISTENCE` | MITRE ATT&CK TA0003: adversary is trying to maintain their foothold. |
| `PRIVILEGE_ESCALATION` | MITRE ATT&CK TA0004: adversary is trying to gain higher-level permissions. |
| `DEFENSE_EVASION` | MITRE ATT&CK TA0005: adversary is trying to avoid being detected. |
| `CREDENTIAL_ACCESS` | MITRE ATT&CK TA0006: adversary is trying to steal account credentials. |
| `C2_AND_EXFILTRATION` | MITRE ATT&CK TA0011/TA0010: command and control and data exfiltration. |
| `IMPACT` | MITRE ATT&CK TA0040: adversary is trying to manipulate, interrupt, or destroy systems. |

## Used by

- [`Rule`](https://wartiva.com/api-docs/types/rule.html) type: A policy rule evaluated against graph objects.
- [`RuleInput`](https://wartiva.com/api-docs/types/rule-input.html) input: Input variant of Rule carrying its writable fields.

## Example

### Example

```json
"RECONNAISSANCE"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
