Skip to content

Tactics, Techniques, and Procedures (TTPs)

Definition

A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash). Procedures are the step-by-step actions observed in a particular campaign. The MITRE ATT&CK framework organises TTPs across 14 tactic categories.

Levels
Tactics, techniques, procedures
Tactics example
Initial access, persistence, exfiltration
Techniques example
Spear-phishing, pass-the-hash
Framework
MITRE ATT&CK, 14 tactic categories
Used for
Threat intelligence and detection engineering

Common questions

Why do defenders focus on TTPs rather than indicators like IP addresses?+

Indicators such as IP addresses or file hashes change frequently and are easy for an attacker to rotate, but the underlying tactics, techniques, and procedures reflect behavioural patterns that are far more costly for an adversary to change, making TTP-based detection more durable.

How is the MITRE ATT&CK framework used with TTPs in practice?+

Analysts map observed adversary behaviour to specific ATT&CK techniques and tactics, which lets teams compare incidents against known threat actor profiles, identify detection gaps, and prioritise defences around techniques seen in prior campaigns.

What is the difference between a technique and a procedure in this model?+

A technique is the general method used to achieve a tactic, such as spear-phishing for initial access, while a procedure is the specific, detailed implementation observed in an actual campaign, such as the exact email template and payload used by a particular group.

Related terms

Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
MITRE ATT&CK
A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
CSIRT (Computer Security Incident Response Team)
A dedicated team responsible for coordinating the response to confirmed security incidents. The CSIRT manages containment, forensic investigation, communication to stakeholders, and...
Diamond Model
An analytic framework that structures a cyber intrusion event around four linked elements: adversary, capability, infrastructure, and victim. The model makes explicit...
Dwell Time
The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
Escalation Path
The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
Hunting Hypothesis
A testable statement specifying what adversary behaviour might be present, which data source would show it, and what analytic would surface it....
SOC (Security Operations Centre)
A function providing continuous monitoring, alert triage, and early detection of security events. The SOC is the first tier of response: it...
STIX
Structured Threat Information eXpression. A standardised, machine-readable language for encoding and sharing threat intelligence objects such as indicators, threat actors, campaigns, and...
TAXII
Trusted Automated eXchange of Intelligence Information. The transport protocol used to share STIX content between organisations. TAXII defines server and client roles,...
Threat Actor
An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction)...
Threat Hunting
A proactive, human-led process that searches for evidence of adversary activity in an environment under the assumption that automated controls have been...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.