The MITRE Fight Fraud Framework™ (F3) is a curated knowledge base of tactics, techniques, and procedures (TTPs) used by financial fraud actors, derived from real-world observations of cyber fraud incidents. The framework includes behaviors that characterize known fraud TTPs and references existing MITRE ATT&CK® cyber techniques as applicable to financial fraud. MITRE F3™ provides a common structure and taxonomy to consistently describe and enumerate the material events of a cyber fraud incident, enabling stronger collaboration on fraud prevention, detection, and response across organizational teams. The knowledge base is globally accessible, open, and available at no charge to any person or organization.
The website hosts all of the resources for this project. The website is linked below along with some shortcuts to important pages on the website.
| Resource | Description |
|---|---|
| Web Site | The website hosts the F3 matrix, design principles & methodology, and project information. |
| Matrix | The F3 Matrix provides a visual representation of F3 tactics (these are the fraud actor's goals) and the different techniques under each tactic, which are actions fraud actors may use to achieve that goal. |
| About | Learn more about the F3 project. |
| Design Principles & Methodology | An authoritative source of information about F3, describing the motivation behind the creation of F3, its design philosophy, the components contained within the knowledge base, and how it can be used. |
There are several ways that you can get involved with this project and help advance threat-informed defense:
- Review the F3 Financial Matrix. We're particularly interested in feedback on any existing techniques or techniques used by fraud actors in real-world, cyber-based incidents that are not yet represented in F3.
- Spread the word. If you find F3 valuable, share your experience with your industry peers.
We welcome your feedback and contributions to help advance F3. Please see the guidance for contributors if are you interested in contributing or simply reporting issues.
Please submit issues for any technical questions/concerns or contact ctid@mitre.org directly for more general inquiries.
© 2026 MITRE. Approved for public release. Document number(s) PR_25-02691-6.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.