Tactics, techniques and procedures (TTPs) describe how an attacker or attacker group operates. Tactics are the goals at each stage of an attack, such as getting in, staying in or stealing data. Techniques are the general methods used to reach each goal, such as phishing or dumping stored passwords. Procedures are the specific, detailed ways a particular group carries out those techniques. Security teams use TTPs to understand attackers, build detections and test whether their defenses work.
At a glance
- TTPs describe attacker behaviour at three levels: the goal (tactic), the method (technique) and the specific implementation (procedure).
- Behaviour is harder for attackers to change than individual addresses or files, so TTP-based detection tends to last longer.
- MITRE ATT&CK, a public knowledge base maintained by MITRE, is the most widely used catalog of tactics and techniques.
- Threat intelligence, MDR services, red teams and penetration testers commonly describe their work in TTP terms.
- For buyers, TTPs are a practical way to ask which attacks a security service would actually detect.
What problem it solves
Early security detection relied heavily on specific evidence: a known malicious file, IP address or domain. These indicators of compromise (IOCs) are useful but short-lived, because attackers can swap infrastructure and recompile malware cheaply. Defenses tuned only to yesterday’s indicators miss today’s attack.
TTPs move the focus to behaviour. An attacker who changes servers still tends to use the same methods to steal credentials, move between systems and send data out. Detection built around those methods catches more variants. TTPs also give buyers, providers and testers a shared vocabulary: instead of “do you detect advanced threats?”, you can ask “which of these techniques do you detect, and how?”
How it works
Tactics. The attacker’s objectives at each stage, for example initial access, persistence, privilege escalation, lateral movement, credential access, exfiltration or impact.
Techniques. The methods used to achieve each tactic. For credential access, techniques might include phishing for passwords, guessing them or extracting them from memory on a compromised machine.
Procedures. The specific way a group performs a technique: the exact tools, commands and sequence it uses. Procedures help analysts link an intrusion to a known group, such as a particular advanced persistent threat (APT).
Frameworks. MITRE ATT&CK organizes tactics and techniques in a matrix with descriptions, examples and suggested detections and mitigations. Vendors and service providers often map their detections and test cases to it.
Use in practice. Cyber threat intelligence (CTI) reports describe the TTPs of active groups. Detection engineers turn them into rules. Threat hunting searches for them in your environment. Red teaming and penetration tests emulate them to see what defenses catch.
When it matters for buyers
- When comparing MDR or SOC providers. Ask them to show which techniques they detect across your data sources, and where they don’t. Our managed detection and response overview explains what to compare.
- When scoping penetration tests or red team exercises. Choosing techniques used by groups that target your industry makes the test more realistic.
- When reading threat advisories. Advisories often list the TTPs of a campaign; the practical question is whether your controls would detect or block them.
- When reporting to the board. A coverage map against known techniques can show gaps more clearly than a list of tools.
Questions to ask vendors
- Can you map your detections to MITRE ATT&CK techniques, and show coverage for our specific data sources?
- Which techniques do you detect poorly or not at all with our current setup?
- How do you turn new threat intelligence about attacker behaviour into detections, and how quickly?
- Do your tests or exercises emulate the techniques of groups that target our industry?
- How do you validate that a detection actually works, not just that a rule exists?
How it differs from indicators of compromise (IOCs)
IOCs are specific pieces of evidence, such as a file hash, IP address or domain, that suggest a particular attack happened. TTPs describe behaviour: how the attacker works, regardless of which file or server they use this time. IOCs are quick to check and useful for confirming a known incident, but attackers can change them easily. TTPs are harder to detect reliably but change slowly, so they make more durable detections. Mature security programs use both.
