TTPs, short for tactics, techniques, and procedures, describe how a cyber attacker behaves: the goal they pursue (the tactic), the general method they use to reach it (the technique), and the exact steps they carry out (the procedure). Security teams study TTPs to recognize an adversary by behavior, not just by the tools they leave behind.
For years, defending a network meant blocking known bad things: a malicious file, a flagged IP address, a suspicious email attachment. That approach is now failing, because attackers have stopped relying on obvious malware. In 2024, 79% of the intrusions CrowdStrike observed used no malware at all, and instead mimicked legitimate user activity. When the tools look normal, the only thing that gives an attacker away is their behavior. That behavior is what TTPs capture, and understanding them is the difference between detecting a breach in minutes and discovering it months later.

The term comes from military doctrine and was adopted into cybersecurity to describe adversary behavior in a structured way. The U.S. National Institute of Standards and Technology defines it cleanly in NIST’s glossary of TTPs: a tactic is the highest-level description of behavior, a technique gives a more detailed description within that tactic, and a procedure is an even lower-level, highly detailed description within a technique. The three layers move from broad intent down to precise execution.
Think of a bank robbery. The goal is to steal the money. The general method might be tunneling in through the vault floor. The exact steps are how one specific crew does it: which street they access the sewer from, the drill they use, the night they pick, how they disable the alarm. A different crew with the same goal and the same general method would still have its own recognizable habits. Cyber attackers work the same way.
A tactic is the adversary’s objective at a given stage of an attack. It answers the question of what they are trying to achieve right now. Gaining initial access, escalating privileges, moving laterally across the network, and stealing data are all tactics. They describe intent, not method, and they stay remarkably consistent across attackers because the goals of an intrusion rarely change.
A technique is the general way an attacker accomplishes a tactic. If the tactic is initial access, the technique might be phishing, exploiting a public-facing application, or abusing valid stolen credentials. Techniques are more numerous than tactics but still describe a category of behavior rather than a single implementation.
A procedure is the specific, observed sequence a particular attacker uses to carry out a technique. Two groups may both use phishing, but one sends a fake invoice with a macro-enabled attachment while another sends a fake login page hosted on a lookalike domain. Procedures are the fingerprint. They are the most detailed and the most revealing, because they reflect the habits, tooling, and tradecraft of a specific adversary.
Source: NIST Computer Security Resource Center, TTP glossary (SP 800-150)
The layers are easiest to grasp when you follow a single, realistic attack from top to bottom. Imagine a business email compromise that ends in ransomware. Here is how the same event reads at each level of detail.
| Layer | Question it answers | In this attack |
|---|---|---|
| Tactic | What is the goal? | Initial access to the network |
| Technique | How, in general? | Phishing with a malicious attachment |
| Procedure | How, exactly? | A finance employee receives a fake invoice; the attached document runs a hidden macro that launches a PowerShell command to download a loader, which then quietly installs remote-access tooling |
Notice how the value shifts as you move down. The tactic (initial access) is shared by almost every attacker on earth, so it tells a defender little on its own. The technique (phishing) narrows things but is still extremely common. The procedure, the specific chain of a macro launching PowerShell to pull down a loader, is concrete enough to write a detection rule against and to link to a known threat actor. This is why mature security teams care most about procedures: they turn a vague category into an identifiable, catchable behavior.
The single most common point of confusion is the difference between TTPs and indicators of compromise. Both are used in threat intelligence, but they describe very different things, and treating them as interchangeable leaves dangerous gaps.
An indicator of compromise is a static artifact left behind by an attack: a malicious file hash, a specific IP address or domain, a registry key, a filename. IOCs are concrete and easy to act on, which is exactly why they are also easy for an attacker to discard. Recompiling a file changes its hash. Renting a new server changes the IP. A blocklist built on IOCs is always one step behind.
A TTP describes behavior instead of an artifact, and behavior is far harder to change. An attacker can swap infrastructure in minutes, but abandoning a proven method (their phishing style, their use of living-off-the-land tools, their lateral-movement habits) means retraining, retooling, and rebuilding a workflow that works. That cost is the whole point.
| Attribute | Indicators of Compromise (IOCs) | Tactics, Techniques & Procedures (TTPs) |
|---|---|---|
| Describes | Static artifacts an attack leaves behind | How the attacker behaves |
| Examples | File hash, IP address, domain, filename | Phishing for access, abusing PowerShell, lateral movement patterns |
| How hard to change | Trivial, often seconds | Difficult, slow, and expensive |
| Detection value | Fast but short-lived | Durable and disruptive to the attacker |
| Best used for | Quick blocking of known-bad artifacts | Recognizing and stopping the adversary’s playbook |
This trade-off is captured in a well-known model called the Pyramid of Pain, introduced by security researcher David Bianco in 2013 and expanded by the MITRE Center for Threat-Informed Defense. It ranks indicator types by how much “pain” detecting them causes the attacker. At the bottom sit file hashes and IP addresses, trivial to change. At the very top sit TTPs, labeled the toughest to alter. The higher up the pyramid a defender can detect, the more it forces the adversary to fundamentally rebuild their operation, and the more often they give up and move to an easier target.

Myth: strong antivirus and a good blocklist are enough. Both work only against things you have already seen, meaning known files and known indicators. But the majority of modern intrusions run no malware and use legitimate tools, so there is no bad file to catch and the “known-bad” list never triggers. Relying on IOCs alone means you are defending against last month’s attacks. Detecting TTPs is what catches the ones designed to slip past those tools.
Knowing that TTPs matter is one thing. Having a shared, standardized way to name and track thousands of them is another, and that is what the MITRE ATT&CK knowledge base provides. ATT&CK (short for Adversarial Tactics, Techniques, and Common Knowledge) is a free, continuously updated catalog of adversary behavior observed in real-world attacks. It has become the common language security teams, vendors, and threat researchers use to describe TTPs so that everyone means the same thing.
The Enterprise matrix, the version most businesses reference, is organized exactly along the TTP model. As of version 17, released in April 2025, it contains:
The 14 Enterprise tactics run roughly in the order an attack unfolds: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact. When a security team says an alert “maps to T1566, Phishing,” they are pointing to a specific technique in this catalog. That shared reference lets a defender in Houston and a researcher in another country compare notes on the same adversary behavior without ambiguity.
For a business, the practical value is that ATT&CK turns an abstract idea into a checklist. You can ask which techniques your industry’s most active threat actors use, then confirm your defenses actually detect those specific behaviors, rather than hoping your tools cover something.
Source: MITRE ATT&CK Enterprise Matrix
The shift toward behavior-based thinking is not academic. It is a direct response to how attacks have changed, and the data makes the case plainly.
First, attackers have largely abandoned malware. According to CrowdStrike’s 2025 Global Threat Report, 79% of detections in 2024 were malware-free, up from 40% in 2019. Instead of dropping a virus, intruders log in with stolen credentials and use the same administrative tools your own IT team uses. There is no malicious file for antivirus to catch. The only thing that separates the attacker from a legitimate admin is the pattern of what they do, which is their TTPs.
Share of Detections That Were Malware-Free
Nearly four in five intrusions now use no malware, relying on legitimate tools and stolen access instead. Source: CrowdStrike 2025 Global Threat Report.
Second, attacks move fast. CrowdStrike puts the average adversary breakout time, the window before an intruder begins spreading from their first foothold to the rest of your network, at 48 minutes, with the fastest recorded at 51 seconds. You do not have days to spot an intrusion. Recognizing malicious behavior in the first hour is what contains it.
Third, the entry point is usually a person, not a machine. The Verizon 2025 Data Breach Investigations Report, which analyzed more than 12,000 confirmed breaches, found the human element involved in 60% of them, and ransomware present in 44% of all breaches, rising to 88% of breaches at small and midsize businesses. Phishing, stolen credentials, and social engineering are TTPs, and they are how most breaches begin. A small business is not too small to be targeted. It is the most common target.
Put together, the message is clear. The attacks most likely to hit your business use no malware, exploit your people, and move within the hour. None of that is caught by a static list of bad files. It is caught by watching for the behaviors, the TTPs, that reveal an attacker in progress.
Source: CrowdStrike 2025 Global Threat Report | Verizon 2025 Data Breach Investigations Report
See How Managed Cybersecurity Detects Threats Like These
You do not need an in-house threat-intelligence team to benefit from a TTP mindset. The goal is to shift your defenses from matching known-bad artifacts to recognizing malicious behavior. In practice, that means a few concrete moves.
For most small and midsize businesses, running this around the clock is not realistic with internal staff alone. This is where a managed security partner earns its keep: a provider watches for adversary behavior on your behalf, maps it to known TTPs, and responds before breakout time runs out. If you are weighing whether to build this internally or outsource it, a virtual CIO can help you scope the right level of protection for your size and risk.
Get Strategic Security Guidance From a Virtual CIO
The definition of tactics, techniques, and procedures follows the U.S. National Institute of Standards and Technology (NIST SP 800-150). Framework counts are drawn from MITRE ATT&CK Enterprise version 17 (April 2025). Malware-free detection and adversary breakout-time figures come from the CrowdStrike 2025 Global Threat Report. Breach, human-element, and ransomware figures come from the Verizon 2025 Data Breach Investigations Report, which analyzed more than 12,000 confirmed breaches. The Pyramid of Pain model is credited to David Bianco (2013) and the MITRE Center for Threat-Informed Defense. Figures are cited to their original sources and used to illustrate attacker behavior, not as guaranteed outcomes for any specific business.
Sources: NIST CSRC, TTP glossary | MITRE ATT&CK Enterprise Matrix | CrowdStrike 2025 Global Threat Report | Verizon 2025 DBIR | MITRE Center for Threat-Informed Defense, Pyramid of Pain
Get a Free Security Consultation for Your Business
Cyber insurance is a business insurance policy that pays for the financial fallout of a cyberattack…
Passkey, defined: A passkey is a phishing-resistant login credential that replaces your password with a cryptographic…
An IT standard operating procedure (SOP) is a documented, step-by-step set of instructions for performing a…
Fake USPS delivery texts are not a minor nuisance, they are the single most-reported text scam…