Ever wonder which technique is used by the most threat actors? Or how many techniques the average RAT has built into it? Or which adversaries use the same techniques and software? This short talk will help answer these questions – and more! – by showing how we can leverage the vast amount of threat reporting in ATT&CK to try to understand the relationships between techniques, threat actors, and software. We’ll address simple questions such as which techniques and threat actors have been most reported on, as well as more complex ones such as which techniques are dependent on others. Our talk is intended to be both entertaining and informative, with attendees walking away with a better understanding of the relationships held within the ATT&CK knowledge base and how they can run similar analyses with their own data.