Skip to content

Pyramid of Pain

Definition

A model proposed by David Bianco that ranks IOC types by the cost to an attacker of changing them when defenders start using that indicator. Hash values are at the base (trivial to change); TTPs are at the apex (costly to change).

Proposed by
David Bianco
Base indicator
Hash values (trivial for attacker to change)
Apex indicator
TTPs, tactics, techniques and procedures
Purpose
Prioritise which indicators cause attackers the most disruption
Field of use
Threat intelligence and incident response

Common questions

Why do defenders value TTPs more than hash values in the Pyramid of Pain?+

An attacker can regenerate a file hash in seconds by recompiling malware, but changing their operational tradecraft, such as a lateral-movement technique, requires retraining and retooling. Detecting TTPs forces a costlier response from the adversary.

Where do IP addresses and domain names sit on the pyramid?+

They sit above hash values but below network or host artefacts. IPs and domains cost an attacker more to rotate than a file hash since infrastructure setup takes time, but they are still cheaper to replace than behavioural patterns.

Does the Pyramid of Pain apply outside malware analysis?+

Yes. Investigators use it in any incident-response context to decide where to invest detection effort, since indicators near the apex sustain value across an attacker's campaign even as lower-level artefacts are swapped out.

Related terms

Domain Generation Algorithm (DGA)
Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
MISP (Malware Information Sharing Platform)
An open-source threat intelligence platform that enables structured sharing of IOCs and threat intelligence using STIX and other formats. Widely deployed by...
STIX (Structured Threat Information eXpression)
An OASIS open standard that defines a JSON-based language for describing cyber threat intelligence. STIX 2.1 defines objects for indicators, threat actors,...
TAXII (Trusted Automated eXchange of Intelligence Information)
The transport protocol companion to STIX. TAXII defines how STIX data is exchanged between servers and clients over HTTPS, enabling automated ingestion...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.