Cyber attackers follow structured processes that vary by motivation, resources, and sophistication, and security professionals use established frameworks to analyze and defend against those methods. This content covers TTPs, MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model of Intrusion Analysis.
Attack Methodologies
Typically, when an attacker targets an organization, they're going to have some sort of process in mind that they're going to go through in order to carry out this attack. An attacker is going to have some sort of objective, and there's going to be a flow, a procedure, a step by step, some sort of method that they're going to use to get to that objective.
The attack is going to look different depending on what motivation they have, what relationship to the organization they have, how much resources they have, if they're sponsored or not, and the level of sophistication that they have in approaching this attack. That's going to vary up what this process looks like. If they're carrying out a denial of service attack, that looks much different than a data deletion or a ransomware or data exfiltration. And even two adversaries that have the same target and the same objective are going to approach things in a different way.
But what we can do is start analyzing all the different attacks that happen and all the different methods that are used, and start putting it into a methodology, a single methodology that we can start evaluating all of these different attacks with. By understanding a general methodology of how an attacker is going to attack a network, we can better defend our network against these types of attacks. Methodology just means a system of methods used in a particular area study. So in this case we're talking about attack methodologies, ways an attacker would attack our network, and then we can start studying what those attacks look like.
The first model that we can look at is the tactics, techniques and procedures, or TTPs. Tactics, techniques, and procedures is a way to analyze what an attacker is doing and see the different methods that they have in order to attack a network.
The tactics is the overall goal for each step. As an attacker goes through and systematically attacks a network, they're going to go through steps, and this is the goal of each of those steps. Then you get into the techniques. The techniques are how they execute those tactics, and there are subtechniques to that as well. Then there are procedures, the actual step-by-step process that they're going to use to carry out their techniques, to reach the goal of that step, to reach the overall objective that they're trying to accomplish.
One of the things that can really help us understand what these tactics and techniques are that adversaries use is MITRE ATT&CK. It's a very comprehensive database full of these different tactics and techniques. ATT&CK stands for adversarial tactics, techniques, and common knowledge. As I mentioned, we can think of it as a database of these tactics and techniques, and it's very comprehensive.
Another model that's very common to use when we're understanding attacks and the flow of attacks is the cyber kill chain. The cyber kill chain gives us an idea of what an attacker is going to use, a flow that the attacker is going to use to execute an attack and meet their objectives.
We can also take that cyber kill chain and apply it to the diamond model of intrusion analysis. Where the cyber kill chain is the idea of the flow of an attacker and how they would attack a network, the diamond model of intrusion analysis is what we can use as cyber security professionals to analyze where an attacker has been within our network and figure out what has happened in our network.
So the tactics, techniques and procedures, MITRE ATT&CK, the cyber kill chain and the diamond model of intrusion analysis are some of the most popular and well-recognized models that we can use as cyber security professionals to be able to understand what an attacker is going to do to attack our network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →