Skip to main content

CNiC Solutions

Security analysts studying network activity patterns in a cybersecurity operations center to detect attacker behavior

For years, defending a network meant blocking known bad things: a malicious file, a flagged IP address, a suspicious email attachment. That approach is now failing, because attackers have stopped relying on obvious malware. In 2024, 79% of the intrusions CrowdStrike observed used no malware at all, and instead mimicked legitimate user activity. When the tools look normal, the only thing that gives an attacker away is their behavior. That behavior is what TTPs capture, and understanding them is the difference between detecting a breach in minutes and discovering it months later.

  • TTPs are behavior, in three layers. A tactic is the goal, a technique is the general method, and a procedure is the specific step-by-step execution. Together they answer what, how, and how exactly.
  • Behavior is now the only reliable signal. With 79% of intrusions running malware-free, defenses that only match files and known indicators miss most modern attacks.
  • MITRE ATT&CK is the shared TTP dictionary. Its Enterprise matrix catalogs 14 tactics, 211 techniques, and 468 sub-techniques seen in real-world attacks.
  • TTPs beat IOCs on durability. An attacker can swap a file hash or IP in seconds, but changing how they operate is slow and costly, which is why TTP-level detection hurts them most.
  • Speed makes it urgent. The average adversary breakout time is now 48 minutes and the fastest is under a minute, so recognizing malicious behavior early is what limits the damage.

What’s in This Guide

 

 

Infographic showing the TTP hierarchy narrowing from tactic to technique to procedure, from goal to exact steps
TTPs move from the broad goal (tactic) through the general method (technique) down to the exact steps a specific attacker uses (procedure).

 

 

What Do Tactics, Techniques, and Procedures Mean?

The term comes from military doctrine and was adopted into cybersecurity to describe adversary behavior in a structured way. The U.S. National Institute of Standards and Technology defines it cleanly in NIST’s glossary of TTPs: a tactic is the highest-level description of behavior, a technique gives a more detailed description within that tactic, and a procedure is an even lower-level, highly detailed description within a technique. The three layers move from broad intent down to precise execution.

Think of a bank robbery. The goal is to steal the money. The general method might be tunneling in through the vault floor. The exact steps are how one specific crew does it: which street they access the sewer from, the drill they use, the night they pick, how they disable the alarm. A different crew with the same goal and the same general method would still have its own recognizable habits. Cyber attackers work the same way.

Tactics: the “what” (the goal)

A tactic is the adversary’s objective at a given stage of an attack. It answers the question of what they are trying to achieve right now. Gaining initial access, escalating privileges, moving laterally across the network, and stealing data are all tactics. They describe intent, not method, and they stay remarkably consistent across attackers because the goals of an intrusion rarely change.

Techniques: the “how” (the general method)

A technique is the general way an attacker accomplishes a tactic. If the tactic is initial access, the technique might be phishing, exploiting a public-facing application, or abusing valid stolen credentials. Techniques are more numerous than tactics but still describe a category of behavior rather than a single implementation.

Procedures: the “how exactly” (the precise steps)

A procedure is the specific, observed sequence a particular attacker uses to carry out a technique. Two groups may both use phishing, but one sends a fake invoice with a macro-enabled attachment while another sends a fake login page hosted on a lookalike domain. Procedures are the fingerprint. They are the most detailed and the most revealing, because they reflect the habits, tooling, and tradecraft of a specific adversary.

Source: NIST Computer Security Resource Center, TTP glossary (SP 800-150)

A Worked Example: One Attack Across All Three Layers

The layers are easiest to grasp when you follow a single, realistic attack from top to bottom. Imagine a business email compromise that ends in ransomware. Here is how the same event reads at each level of detail.

Layer Question it answers In this attack
Tactic What is the goal? Initial access to the network
Technique How, in general? Phishing with a malicious attachment
Procedure How, exactly? A finance employee receives a fake invoice; the attached document runs a hidden macro that launches a PowerShell command to download a loader, which then quietly installs remote-access tooling

Notice how the value shifts as you move down. The tactic (initial access) is shared by almost every attacker on earth, so it tells a defender little on its own. The technique (phishing) narrows things but is still extremely common. The procedure, the specific chain of a macro launching PowerShell to pull down a loader, is concrete enough to write a detection rule against and to link to a known threat actor. This is why mature security teams care most about procedures: they turn a vague category into an identifiable, catchable behavior.

TTPs vs Indicators of Compromise (IOCs)

The single most common point of confusion is the difference between TTPs and indicators of compromise. Both are used in threat intelligence, but they describe very different things, and treating them as interchangeable leaves dangerous gaps.

An indicator of compromise is a static artifact left behind by an attack: a malicious file hash, a specific IP address or domain, a registry key, a filename. IOCs are concrete and easy to act on, which is exactly why they are also easy for an attacker to discard. Recompiling a file changes its hash. Renting a new server changes the IP. A blocklist built on IOCs is always one step behind.

A TTP describes behavior instead of an artifact, and behavior is far harder to change. An attacker can swap infrastructure in minutes, but abandoning a proven method (their phishing style, their use of living-off-the-land tools, their lateral-movement habits) means retraining, retooling, and rebuilding a workflow that works. That cost is the whole point.

Attribute Indicators of Compromise (IOCs) Tactics, Techniques & Procedures (TTPs)
Describes Static artifacts an attack leaves behind How the attacker behaves
Examples File hash, IP address, domain, filename Phishing for access, abusing PowerShell, lateral movement patterns
How hard to change Trivial, often seconds Difficult, slow, and expensive
Detection value Fast but short-lived Durable and disruptive to the attacker
Best used for Quick blocking of known-bad artifacts Recognizing and stopping the adversary’s playbook

This trade-off is captured in a well-known model called the Pyramid of Pain, introduced by security researcher David Bianco in 2013 and expanded by the MITRE Center for Threat-Informed Defense. It ranks indicator types by how much “pain” detecting them causes the attacker. At the bottom sit file hashes and IP addresses, trivial to change. At the very top sit TTPs, labeled the toughest to alter. The higher up the pyramid a defender can detect, the more it forces the adversary to fundamentally rebuild their operation, and the more often they give up and move to an easier target.

 

 

Pyramid of Pain infographic ranking indicator types from easy-to-change hash values up to hard-to-change TTPs at the top
In the Pyramid of Pain, TTPs sit at the apex because they are the hardest for an attacker to change, making them the most valuable to detect.

 

 

Myth: strong antivirus and a good blocklist are enough. Both work only against things you have already seen, meaning known files and known indicators. But the majority of modern intrusions run no malware and use legitimate tools, so there is no bad file to catch and the “known-bad” list never triggers. Relying on IOCs alone means you are defending against last month’s attacks. Detecting TTPs is what catches the ones designed to slip past those tools.

TTPs and the MITRE ATT&CK Framework

Knowing that TTPs matter is one thing. Having a shared, standardized way to name and track thousands of them is another, and that is what the MITRE ATT&CK knowledge base provides. ATT&CK (short for Adversarial Tactics, Techniques, and Common Knowledge) is a free, continuously updated catalog of adversary behavior observed in real-world attacks. It has become the common language security teams, vendors, and threat researchers use to describe TTPs so that everyone means the same thing.

The Enterprise matrix, the version most businesses reference, is organized exactly along the TTP model. As of version 17, released in April 2025, it contains:

14
Tactics, the adversary goals, from reconnaissance and initial access through to data exfiltration and impact.Source: MITRE ATT&CK v17
211
Techniques, the general methods used to accomplish those tactics.Source: MITRE ATT&CK v17
468
Sub-techniques, the more specific variations that sit under the techniques.Source: MITRE ATT&CK v17

The 14 Enterprise tactics run roughly in the order an attack unfolds: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, and Impact. When a security team says an alert “maps to T1566, Phishing,” they are pointing to a specific technique in this catalog. That shared reference lets a defender in Houston and a researcher in another country compare notes on the same adversary behavior without ambiguity.

For a business, the practical value is that ATT&CK turns an abstract idea into a checklist. You can ask which techniques your industry’s most active threat actors use, then confirm your defenses actually detect those specific behaviors, rather than hoping your tools cover something.

Source: MITRE ATT&CK Enterprise Matrix

 

CNiC Solutions — Cybersecurity

 

Why TTPs Matter for Your Business

The shift toward behavior-based thinking is not academic. It is a direct response to how attacks have changed, and the data makes the case plainly.

First, attackers have largely abandoned malware. According to CrowdStrike’s 2025 Global Threat Report, 79% of detections in 2024 were malware-free, up from 40% in 2019. Instead of dropping a virus, intruders log in with stolen credentials and use the same administrative tools your own IT team uses. There is no malicious file for antivirus to catch. The only thing that separates the attacker from a legitimate admin is the pattern of what they do, which is their TTPs.

Share of Detections That Were Malware-Free

2024
79%
2019
40%

Nearly four in five intrusions now use no malware, relying on legitimate tools and stolen access instead. Source: CrowdStrike 2025 Global Threat Report.

Second, attacks move fast. CrowdStrike puts the average adversary breakout time, the window before an intruder begins spreading from their first foothold to the rest of your network, at 48 minutes, with the fastest recorded at 51 seconds. You do not have days to spot an intrusion. Recognizing malicious behavior in the first hour is what contains it.

48 min
Average adversary breakout time before an intruder moves laterally across the network, with the fastest observed at under a minute.Source: CrowdStrike 2025 Global Threat Report

Third, the entry point is usually a person, not a machine. The Verizon 2025 Data Breach Investigations Report, which analyzed more than 12,000 confirmed breaches, found the human element involved in 60% of them, and ransomware present in 44% of all breaches, rising to 88% of breaches at small and midsize businesses. Phishing, stolen credentials, and social engineering are TTPs, and they are how most breaches begin. A small business is not too small to be targeted. It is the most common target.

88%
Share of small and midsize business breaches that involved ransomware, versus 44% across organizations of all sizes.Source: Verizon 2025 DBIR

Put together, the message is clear. The attacks most likely to hit your business use no malware, exploit your people, and move within the hour. None of that is caught by a static list of bad files. It is caught by watching for the behaviors, the TTPs, that reveal an attacker in progress.

Source: CrowdStrike 2025 Global Threat Report | Verizon 2025 Data Breach Investigations Report

See How Managed Cybersecurity Detects Threats Like These

How to Use TTPs to Strengthen Your Defenses

You do not need an in-house threat-intelligence team to benefit from a TTP mindset. The goal is to shift your defenses from matching known-bad artifacts to recognizing malicious behavior. In practice, that means a few concrete moves.

  1. Deploy behavior-based detection, not just antivirus. Endpoint detection and response tools watch what processes actually do, so they can flag a legitimate tool being used in an illegitimate way. See how endpoint detection and response differs from traditional antivirus.
  2. Map your alerts to a shared framework. Tying detections to MITRE ATT&CK techniques shows you exactly which adversary behaviors you can see and, more importantly, which you are blind to.
  3. Prioritize the TTPs that target you. Most breaches start with phishing and stolen credentials, so hardening against the social engineering methods attackers rely on and the different forms phishing takes removes the most-used techniques first.
  4. Have a plan for when detection fires. Detecting a TTP only helps if someone acts on it quickly. A documented incident response plan turns an alert into a contained event instead of a full breach.

For most small and midsize businesses, running this around the clock is not realistic with internal staff alone. This is where a managed security partner earns its keep: a provider watches for adversary behavior on your behalf, maps it to known TTPs, and responds before breakout time runs out. If you are weighing whether to build this internally or outsource it, a virtual CIO can help you scope the right level of protection for your size and risk.

Get Strategic Security Guidance From a Virtual CIO

Common Questions About TTPs

What does TTP stand for in cybersecurity?

TTP stands for tactics, techniques, and procedures. Together they describe how a cyber attacker behaves: the goal they pursue, the general method they use, and the exact steps they carry out to reach it.

What is the difference between a tactic, a technique, and a procedure?

A tactic is the attacker’s goal, such as gaining initial access. A technique is the general method used to reach it, such as phishing. A procedure is the exact, step-by-step way a specific attacker carries that technique out.

What is the difference between TTPs and IOCs?

IOCs are static clues left behind by an attack, like a malicious file hash or IP address, which are easy to change. TTPs describe attacker behavior, which is far harder to change, so detecting TTPs imposes more cost on the adversary.

What is the MITRE ATT&CK framework?

MITRE ATT&CK is a free, globally used knowledge base that catalogs adversary TTPs observed in real attacks. Its Enterprise matrix organizes them into 14 tactics, 211 techniques, and 468 sub-techniques that defenders use to map and detect threats.

Why are TTPs important for threat detection?

Most attacks now use legitimate tools instead of malware, so file-based defenses miss them. Detecting behavior, or TTPs, catches an attacker by what they do rather than what file they carry, which is the most durable form of detection.

About This Guide

The definition of tactics, techniques, and procedures follows the U.S. National Institute of Standards and Technology (NIST SP 800-150). Framework counts are drawn from MITRE ATT&CK Enterprise version 17 (April 2025). Malware-free detection and adversary breakout-time figures come from the CrowdStrike 2025 Global Threat Report. Breach, human-element, and ransomware figures come from the Verizon 2025 Data Breach Investigations Report, which analyzed more than 12,000 confirmed breaches. The Pyramid of Pain model is credited to David Bianco (2013) and the MITRE Center for Threat-Informed Defense. Figures are cited to their original sources and used to illustrate attacker behavior, not as guaranteed outcomes for any specific business.

Sources: NIST CSRC, TTP glossary | MITRE ATT&CK Enterprise Matrix | CrowdStrike 2025 Global Threat Report | Verizon 2025 DBIR | MITRE Center for Threat-Informed Defense, Pyramid of Pain

Get a Free Security Consultation for Your Business

 

author avatar
David McFarlene Founder & CEO
David McFarlene is the owner and founder of CNiC Solutions, a trusted IT services and cybersecurity company serving the Houston, TX area. With over 20 years of experience in managed IT, infrastructure design, cloud solutions, and data security, David helps businesses and homeowners stay protected and productive through dependable, personalized technology support. He leads the CNiC Solutions team with a focus on reliability, transparency, and long-term relationships, ensuring clients always have a knowledgeable expert they can trust.
back to blog