Skip to content

TTPs (Tactics, Techniques, and Procedures)

Definition

The behavioural fingerprint of a threat actor: the broad goals and approaches they pursue (tactics), the specific methods they use to achieve each tactic (techniques), and the granular implementation details (procedures). TTPs are harder to change than tools or infrastructure and are therefore the most reliable layer of attribution evidence.

Tactics
Broad goals an actor pursues
Techniques
Specific methods used to achieve each tactic
Procedures
Granular implementation details
Attribution value
Most reliable layer, harder to change than tools or infrastructure

Common questions

Why are TTPs considered more reliable for attribution than malware samples or IP addresses?+

Tools and infrastructure can be swapped between campaigns cheaply, sometimes reused across unrelated actors, while behavioural habits, preferred techniques, and operational sequencing tend to persist because they reflect trained procedure, making them a sturdier basis for linking incidents to the same group.

Can two unrelated threat actors share the same TTPs by coincidence?+

Yes, some techniques are common tradecraft used broadly across many unrelated groups, so attribution analysts typically require a distinctive combination or sequence of TTPs, not a single shared technique, before drawing a confident link between incidents.

Related terms

Attribution
The process of identifying the threat actor responsible for a cyberattack. Attribution is a confidence-weighted analytical conclusion, not a binary fact. It...
Confidence Level
An explicit label attached to an attribution assessment indicating how strongly the available evidence supports the conclusion. Standard tiers are low, medium,...
False Flag
A deliberate deception in which an attacker plants indicators designed to make the intrusion appear to originate from a different actor. Common...
Technical vs Legal Attribution
Technical attribution identifies the infrastructure and tooling used in an attack and may link it to a known cluster or actor profile....
Threat Actor Cluster
A named collection of observed activity linked by shared infrastructure, malware, and TTPs, without necessarily having confirmed the real-world identity of the...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.