Tactics, techniques, and procedures (TTPs) are a core framework cybersecurity professionals use to understand and analyze adversary behavior across every stage of an attack. The MITRE ATT&CK framework catalogs 14 tactics, 203 techniques, and 453 sub-techniques that map out how attackers operate inside real-world networks.
Tactics, Techniques, and Procedures (TTPs)
One of the models that we use as cyber professionals to analyze what an attacker is doing is the tactics, techniques, and procedures.
An adversary is going to use many different tactics to get into your network. The tactics is a goal for each step along the way as they make their way through your network. Each one of those tactics has many different techniques to carry out that tactic, to carry out that goal. And also each one of those techniques has many procedures to carry out those techniques.
Let's take a look at an example of tactic, techniques, and procedures that's unrelated to technology. First of all, I have an objective. Maybe that objective is to get into better shape. So I want to get into better shape. And what is my tactics to do that? There's several to choose from. I can choose many different tactics. Maybe I'm going to exercise more. Maybe I'm going to eat better. Maybe I'm going to have better habits throughout my day. Maybe I'm going to do a combination of these. Maybe I'm going to do all of them.
So what is the techniques that I'm going to use for each one of these? For exercise, I could do push-ups. I could do sit-ups. I could do pull-ups. All of which would count as exercise. For food, I could have eggs for breakfast, salads for lunch, fish for dinner, or I could use a combination of any of these techniques as well. And then for habits, I could do hourly walks. I could do a standing desk. These are the different techniques that I can use to carry out that tactic.
What are the procedures? For each one of those techniques, I could possibly have many different procedures. So, for instance, for push-ups, I could have a procedure that says, "Lay on your stomach on the floor, and then put your arms under your shoulders, and then push up." This is describing the procedure or the process that I'd use, the step by step, to carry out those push-ups. And then I'd have the same thing for sit-ups, the same thing for pull-ups, the same thing for eating, when I would eat these different meals. So we have an overall objective. We have tactics to meet those objectives, techniques to carry out those tactics, and procedures to carry out the techniques.
Now let's take a look at an example of somebody trying to break into a network. Let's say they're trying to break into this network right here. We call it initial access, so the tactic is initial access: they initially gain access to that network. How are they going to do that? They could try getting through the firewall, so that might be one technique there. Or maybe they can leverage somebody inside and do some social engineering.
Let's say this adversary chooses to go that route. The technique here that they're going to use is spear phishing. They're going to identify somebody in this network right here and then figure out what they're going to do, which in this case is choose a virus and then send an email with the virus to this user right here. So these are the procedures to carry out this technique, which is spear phishing, to carry out this tactic, which is trying to get into this network right here.
Do realize that once this person is in this network right here, they've carried out the tactic, technique and procedure to gain initial access into the network. Their job isn't done. They have not executed any kind of action on objective. So at this point in time, once they're inside this network, they need to carry out a different tactic, technique, and procedure to make it to the next step during this attack.
I'm not going to go in depth into what MITRE ATT&CK is at this point, that's not part of this lesson, but what I did do is I jumped on this website so we get a glimpse into what these different tactics and techniques are, because essentially this is a database of those tactics and techniques.
If we look across the top here, we see reconnaissance, resource development, initial access, execution, persistence. Each one of those is a tactic that you can use, a tactic that an adversary will use to break into your network. So we can take a look at reconnaissance here, and then under there there are different techniques. All of the ones listed under here are techniques to carry out this reconnaissance, reconnaissance which is pretty much doing research into a target. We can see active scanning, gather victim host information, gather victim identity information. These are specific techniques to do that. And then I can actually open these up, and under active scanning we can see scanning IP blocks, vulnerability scanning, wordlist scanning. These are sub-techniques to this active scanning technique.
In total, there are 14 different tactics that are outlined by that MITRE ATT&CK. And at the end here is our action on objectives. We see here data exfiltration and impact. That's what we're trying to accomplish out of all of this, the end result of this. But we could be using many different tactics and techniques to get to that.
Of the 14 tactics, there are a total of 203 different techniques. And there are 453 sub-techniques. These are just a few of them that you may recognize: adversary in the middle, or supply chain compromise, or phishing, active scanning. These are different techniques that an attacker could use in order to get into and break into your organization and into your network. For each one of those techniques, there could be many different procedures that an adversary would follow to break into that network.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →