Action on objectives describes the goals adversaries pursue and the steps they take to achieve them, spanning data exfiltration and operational impact. The MITRE ATT&CK framework organizes these activities into tactics, techniques, and procedures that define how attacks unfold.
Action on Objectives
An adversary is going to have a goal, or what we call an objective. They're going to want to accomplish something, and they're going to take actions to accomplish it. We call this action on objectives.
At its simplest form, an objective just means a goal, something that you're trying to achieve — in soccer, or football depending on what country you're in. We know that the goal with a soccer ball, or a football, is to get it into the goal, and then you get points for that. So that would be the objective.
An adversary's objective is really going to be strongly influenced by their motivation. As an example of this, if they have a financial motivation, then their objective is money. If they are just after this for challenge, curiosity, or maybe some sort of notoriety, maybe they don't really care what their objective is. So maybe they have an objective of money, but that gives them that challenge or that notoriety. Or maybe it's just to cause disruption, cause some sort of impact, and maybe they're doing some sort of denial of service attack, or maybe something that causes just chaos. And so now that is their objective: let's cause chaos to this company. That's what they're thinking, that's what their objective is.
So let's say their objective is like a treasure map, and they are trying to go after this money to do it. Well, what we have now is action on objectives. The action that they're going to take to achieve that is the action. So action on objectives gives us both the objectives, where they're trying to go to, and the action that they're going to take to get to it.
There are lots of different models out there, but one of the primary ones that we're going to use throughout this course is going to be the MITRE ATT&CK. The MITRE ATT&CK categorizes objectives into two different categories. One of them would be data exfiltration, grabbing data, and the other one is some sort of impact to the business or organization.
Data exfiltration is a fairly simple concept, just the idea that the adversary is stealing data. There are a few terms that we can associate with this.
One of them is espionage. Espionage is the idea that there's a spy in a government and they're stealing maybe secrets to how a bomb is configured, how a missile is configured, and so they're stealing that information and they're bringing it back to another government. Maybe these two governments are at war. So that's creating espionage.
There is such a thing as corporate espionage, so it's not just governments. There's corporate espionage where somebody's maybe stealing trade secrets. Maybe there are secrets to the secret formula that makes — maybe it's KFC's secret formula to make their chicken taste amazing — and somebody steals those trade secrets. And so now a competing company has an advantage and can use that. We call that a competitive advantage, because now that competitive advantage maybe is lost from KFC and has been transferred to somebody else who can reproduce that same chicken.
There's also blackmail. Maybe this information is being used for blackmail, because now what happens is, if you don't do this then I'm going to release this information to the world. So it could be used for blackmail.
Impact can mean a lot of different things, but the impact could mean that you just go in there and you manipulate the data so then it's inaccurate, and so now somebody who's using that data doesn't realize that they're using bad data. Or maybe it's to just interrupt — maybe I launch a denial of service attack and bring that down, or even destroy that data. So now it's maybe over some sort of being vindictive and causing harm to another company or another organization, or maybe another person.
Some impact examples might be an attack on reputation. Maybe I launch a denial of service attack and their services go down, their customers get frustrated, and suddenly now they come to me, or they come to whatever organization is launching this attack.
Or maybe it's ransomware. What ransomware does is it encrypts data, and now you don't have access to your data until you pay money to get a code to decrypt that data, and then you get access to that data.
Here are a few other examples and other methods. Maybe there's some sort of service disruption, where we bring the service down. Or data destruction, data encryption, data manipulation. Maybe we launch that denial of service attack. Or defacement — an example of that would be tagging their business with spray paint. You go and spray paint it. Well, you could do the same thing digitally, to maybe a website.
If we apply this to the CIA triad, confidentiality would be equivalent to that data exfiltration, and integrity and availability — if somebody's launching an attack against those, it's an impact attack.
So how are they going to carry out this action on objectives? First of all, they're going to have a tactic, they're going to have a technique, and they're going to have a procedure. The tactic is going to be at a very high level, and tactics have several techniques that can be used, and each one of those techniques can have different procedures.
As an example, maybe an adversary is targeting a business and wants to steal data from them. So that's data exfiltration — their tactic in this case is going to be data exfiltration, so they're going to exfiltrate data. What is the technique that they're going to use? Well, maybe they're going to do it over an unencrypted protocol, and specifically they're going to do it over SMTP. So that's the technique that they're using. Now, to exfiltrate over SMTP there are going to be specific steps that they're going to follow that are going to carry out this type of attack.
So that is what tactics are: the upper level, essentially what they're trying to achieve, here in this case data exfiltration. Their techniques are how they're going about doing that, and there are also sub-techniques as well. And then the procedures are the actual steps that they follow to carry out this attack.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →