TTP (Tactics, Techniques, and Procedures)
Definition
The three levels of specificity used to describe attacker behaviour. Tactics are the goal (e.g., persistence). Techniques are the method (e.g., scheduled task creation). Procedures are the specific implementation used by a particular threat actor or malware family.
- Tactics
- The adversary's goals
- Techniques
- The methods used to achieve a goal
- Procedures
- Specific implementation details, e.g. an exact PowerShell command
- Framework
- Codified in MITRE ATT&CK
Common questions
Why do threat hunters prioritise TTPs over indicators like IP addresses or file hashes?+
Indicators such as IPs and hashes change easily and cheaply between campaigns, while an adversary's underlying goals and methods are harder and costlier to change, so detections built around TTPs stay effective across more of an attacker's operations.
How does ATT&CK make TTPs actionable for a defender?+
ATT&CK organises observed real-world tactics and techniques into a shared matrix with unique identifiers, which lets a hunter map detections and gaps to specific attacker behaviours and compare coverage across investigations consistently.
Related terms
- ATT&CK Navigator
- A free, browser-based visualisation tool from MITRE that renders the ATT&CK matrix as an interactive heat map. Teams use it to annotate...
- Cyber Kill Chain
- A seven-phase linear model of an intrusion developed by Lockheed Martin in 2011. The phases are: Reconnaissance, Weaponisation, Delivery, Exploitation, Installation, Command...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...
- MITRE ATT&CK
- A publicly available knowledge base of adversary tactics, techniques, and procedures derived from real-world intrusion observations. Maintained by the MITRE Corporation. Techniques...
- Sub-Technique
- A finer-grained variation of a technique, identified with a decimal suffix such as T1059.001 for PowerShell under the Command and Scripting Interpreter...
- Tactic
- The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK...
- Technique
- A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...
- Threat Group Profile
- An ATT&CK entry for a named threat actor, listing the techniques attributed to that group based on public reporting. Analysts use group...
- Unified Kill Chain
- An 18-phase model by Paul Pols (2017, updated 2021) that extends the Cyber Kill Chain by integrating MITRE ATT&CK and adding coverage...
Explained in these topics
- MITRE ATT&CK in Threat Hunting and Incident ResponseThe full description of how an adversary operates. Tactics are goals, techniques are methods, and procedures are the specific implementation details, such as t...
- The Cyber Attack Lifecycle