TechKnowSurge
VideoSecurityFree

Attack Methodologies

Cyber attackers follow structured processes that vary by motivation, resources, and sophistication, and security professionals use established frameworks to analyze and defend against those methods. This content covers TTPs, MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model of Intrusion Analysis.

Complete this video to capture a CTF flag worth 1 point.

About this video

Attackers rarely operate randomly. When targeting an organization, adversaries follow deliberate processes shaped by their motivations, available resources, sponsorship, and technical sophistication. Two attackers pursuing the same objective may take entirely different paths to reach it, and the nature of the attack itself — whether a denial-of-service, ransomware deployment, or data exfiltration — further defines what that process looks like. By studying these varied approaches, cybersecurity professionals can identify common patterns and organize them into analytical frameworks that support both defense and investigation. Tactics, Techniques, and Procedures — commonly referred to as TTPs — provide a structured way to describe attacker behavior. Tactics represent the high-level goal of each phase in an attack, techniques describe how those goals are executed, and procedures capture the specific step-by-step actions taken. The MITRE ATT&CK framework builds directly on this concept, offering a continuously updated, comprehensive knowledge base of adversarial tactics and techniques documented from real-world intrusions. It serves as a practical reference for identifying what an attacker may be doing at any given stage of a campaign. The Cyber Kill Chain models the sequential flow of a cyberattack from reconnaissance through final objective completion, giving defenders a way to anticipate attacker progression and identify opportunities to interrupt it. Complementing this, the Diamond Model of Intrusion Analysis focuses on post-incident examination, helping security teams reconstruct attacker activity within a network by analyzing the relationships between adversaries, capabilities, infrastructure, and victims. Used together, these four frameworks — TTPs, MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model — represent some of the most recognized and widely applied tools in the cybersecurity profession for understanding, analyzing, and responding to network-based threats.

What you'll learn

What's covered

Attack Methodologies

Key terms

Tactics, Techniques, and Procedures
TTP
Tactics, Techniques, and Procedures describe the behavior and methods used by threat actors during cyberattacks, with TTPs forming the basis for frameworks such as MITRE ATT&CK and enabling defenders to develop detection and response strategies.
Threat Actor
An individual or group responsible for a security incident or attack.
Threat Intelligence
Information about existing or emerging threats that helps organizations make informed security decisions.
MITRE ATT&CK
A globally accessible knowledge base that categorizes adversary tactics and techniques based on real-world observations, used to understand and defend against cyber threats.
Cyber Kill Chain
The Cyber Kill Chain is a Lockheed Martin threat model describing the seven stages of a targeted cyberattack — reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives — used to structure defensive strategies.
Diamond Model of Intrusion Analysis
A framework used by cybersecurity professionals to analyze intrusions by examining the relationships between an adversary, their capabilities, infrastructure, and the victim.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
Exploit
A piece of software or technique that takes advantage of a vulnerability to gain unauthorized access or cause harm.

Topics

Attack Methodologies Mitre Attack Cyber Kill Chain Diamond Model Ttps Threat Intelligence Cybersecurity

Transcript

Typically, when an attacker targets an organization, they're going to have some sort of process in mind that they're going to go through in order to carry out this attack. An attacker is going to have some sort of objective, and there's going to be a flow, a procedure, a step by step, some sort of method that they're going to use to get to that objective.

The attack is going to look different depending on what motivation they have, what relationship to the organization they have, how much resources they have, if they're sponsored or not, and the level of sophistication that they have in approaching this attack. That's going to vary up what this process looks like. If they're carrying out a denial of service attack, that looks much different than a data deletion or a ransomware or data exfiltration. And even two adversaries that have the same target and the same objective are going to approach things in a different way.

But what we can do is start analyzing all the different attacks that happen and all the different methods that are used, and start putting it into a methodology, a single methodology that we can start evaluating all of these different attacks with. By understanding a general methodology of how an attacker is going to attack a network, we can better defend our network against these types of attacks. Methodology just means a system of methods used in a particular area study. So in this case we're talking about attack methodologies, ways an attacker would attack our network, and then we can start studying what those attacks look like.

Tactics, Techniques and Procedures

The first model that we can look at is the tactics, techniques and procedures, or TTPs. Tactics, techniques, and procedures is a way to analyze what an attacker is doing and see the different methods that they have in order to attack a network.

The tactics is the overall goal for each step. As an attacker goes through and systematically attacks a network, they're going to go through steps, and this is the goal of each of those steps. Then you get into the techniques. The techniques are how they execute those tactics, and there are subtechniques to that as well. Then there are procedures, the actual step-by-step process that they're going to use to carry out their techniques, to reach the goal of that step, to reach the overall objective that they're trying to accomplish.

MITRE ATT&CK

One of the things that can really help us understand what these tactics and techniques are that adversaries use is MITRE ATT&CK. It's a very comprehensive database full of these different tactics and techniques. ATT&CK stands for adversarial tactics, techniques, and common knowledge. As I mentioned, we can think of it as a database of these tactics and techniques, and it's very comprehensive.

The Cyber Kill Chain and the Diamond Model

Another model that's very common to use when we're understanding attacks and the flow of attacks is the cyber kill chain. The cyber kill chain gives us an idea of what an attacker is going to use, a flow that the attacker is going to use to execute an attack and meet their objectives.

We can also take that cyber kill chain and apply it to the diamond model of intrusion analysis. Where the cyber kill chain is the idea of the flow of an attacker and how they would attack a network, the diamond model of intrusion analysis is what we can use as cyber security professionals to analyze where an attacker has been within our network and figure out what has happened in our network.

So the tactics, techniques and procedures, MITRE ATT&CK, the cyber kill chain and the diamond model of intrusion analysis are some of the most popular and well-recognized models that we can use as cyber security professionals to be able to understand what an attacker is going to do to attack our network.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →