TechKnowSurge
VideoSecurityFree

Tactic, Techniques, and Procedures (TTPs)

Tactics, techniques, and procedures (TTPs) are a core framework cybersecurity professionals use to understand and analyze adversary behavior across every stage of an attack. The MITRE ATT&CK framework catalogs 14 tactics, 203 techniques, and 453 sub-techniques that map out how attackers operate inside real-world networks.

Complete this video to capture a CTF flag worth 1 point.

About this video

Tactics, techniques, and procedures (TTPs) are a foundational framework for understanding adversary behavior in cybersecurity. A tactic defines the goal an attacker is trying to accomplish at a specific stage of an intrusion, a technique describes one method for achieving that goal, and a procedure is the detailed, step-by-step process used to execute that technique. Attackers rarely stop after completing a single tactic — gaining initial access, for example, is just one step, and the attacker must continue executing new TTPs to move deeper into the network and ultimately achieve their objective. The MITRE ATT&CK framework is the industry-standard reference for mapping these adversary behaviors. It organizes 14 distinct tactics that span the full attack lifecycle, from reconnaissance and resource development through execution, persistence, and final actions on objectives such as data exfiltration and impact. Across those 14 tactics, the framework documents 203 techniques and 453 sub-techniques, providing a granular, searchable catalog of the specific methods attackers use against real-world environments. Familiar techniques such as spear phishing, adversary-in-the-middle, supply chain compromise, and active scanning all appear within the framework, each tied to the broader tactic it supports. Understanding the relationship between tactics, techniques, and procedures allows security professionals to analyze incidents more precisely, anticipate attacker behavior at each stage, and align defensive controls to the specific methods most likely to be used against their organization.

What you'll learn

What's covered

Tactics, Techniques, and Procedures (TTPs)

Key terms

Tactics, Techniques, and Procedures
TTP
Tactics, Techniques, and Procedures describe the behavior and methods used by threat actors during cyberattacks, with TTPs forming the basis for frameworks such as MITRE ATT&CK and enabling defenders to develop detection and response strategies.
Threat Actor
An individual or group responsible for a security incident or attack.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Data Exfiltration
The unauthorized transfer of data from a system to an external destination.
MITRE ATT&CK
A globally accessible knowledge base that categorizes adversary tactics and techniques based on real-world observations, used to understand and defend against cyber threats.

Topics

Ttps Mitre Attack Threat Intelligence Adversary Behavior Cybersecurity Attack Techniques

Transcript

One of the models that we use as cyber professionals to analyze what an attacker is doing is the tactics, techniques, and procedures.

An adversary is going to use many different tactics to get into your network. The tactics is a goal for each step along the way as they make their way through your network. Each one of those tactics has many different techniques to carry out that tactic, to carry out that goal. And also each one of those techniques has many procedures to carry out those techniques.

An example outside technology

Let's take a look at an example of tactic, techniques, and procedures that's unrelated to technology. First of all, I have an objective. Maybe that objective is to get into better shape. So I want to get into better shape. And what is my tactics to do that? There's several to choose from. I can choose many different tactics. Maybe I'm going to exercise more. Maybe I'm going to eat better. Maybe I'm going to have better habits throughout my day. Maybe I'm going to do a combination of these. Maybe I'm going to do all of them.

So what is the techniques that I'm going to use for each one of these? For exercise, I could do push-ups. I could do sit-ups. I could do pull-ups. All of which would count as exercise. For food, I could have eggs for breakfast, salads for lunch, fish for dinner, or I could use a combination of any of these techniques as well. And then for habits, I could do hourly walks. I could do a standing desk. These are the different techniques that I can use to carry out that tactic.

What are the procedures? For each one of those techniques, I could possibly have many different procedures. So, for instance, for push-ups, I could have a procedure that says, "Lay on your stomach on the floor, and then put your arms under your shoulders, and then push up." This is describing the procedure or the process that I'd use, the step by step, to carry out those push-ups. And then I'd have the same thing for sit-ups, the same thing for pull-ups, the same thing for eating, when I would eat these different meals. So we have an overall objective. We have tactics to meet those objectives, techniques to carry out those tactics, and procedures to carry out the techniques.

Breaking into a network

Now let's take a look at an example of somebody trying to break into a network. Let's say they're trying to break into this network right here. We call it initial access, so the tactic is initial access: they initially gain access to that network. How are they going to do that? They could try getting through the firewall, so that might be one technique there. Or maybe they can leverage somebody inside and do some social engineering.

Let's say this adversary chooses to go that route. The technique here that they're going to use is spear phishing. They're going to identify somebody in this network right here and then figure out what they're going to do, which in this case is choose a virus and then send an email with the virus to this user right here. So these are the procedures to carry out this technique, which is spear phishing, to carry out this tactic, which is trying to get into this network right here.

Do realize that once this person is in this network right here, they've carried out the tactic, technique and procedure to gain initial access into the network. Their job isn't done. They have not executed any kind of action on objective. So at this point in time, once they're inside this network, they need to carry out a different tactic, technique, and procedure to make it to the next step during this attack.

The MITRE ATT&CK database

I'm not going to go in depth into what MITRE ATT&CK is at this point, that's not part of this lesson, but what I did do is I jumped on this website so we get a glimpse into what these different tactics and techniques are, because essentially this is a database of those tactics and techniques.

If we look across the top here, we see reconnaissance, resource development, initial access, execution, persistence. Each one of those is a tactic that you can use, a tactic that an adversary will use to break into your network. So we can take a look at reconnaissance here, and then under there there are different techniques. All of the ones listed under here are techniques to carry out this reconnaissance, reconnaissance which is pretty much doing research into a target. We can see active scanning, gather victim host information, gather victim identity information. These are specific techniques to do that. And then I can actually open these up, and under active scanning we can see scanning IP blocks, vulnerability scanning, wordlist scanning. These are sub-techniques to this active scanning technique.

In total, there are 14 different tactics that are outlined by that MITRE ATT&CK. And at the end here is our action on objectives. We see here data exfiltration and impact. That's what we're trying to accomplish out of all of this, the end result of this. But we could be using many different tactics and techniques to get to that.

Of the 14 tactics, there are a total of 203 different techniques. And there are 453 sub-techniques. These are just a few of them that you may recognize: adversary in the middle, or supply chain compromise, or phishing, active scanning. These are different techniques that an attacker could use in order to get into and break into your organization and into your network. For each one of those techniques, there could be many different procedures that an adversary would follow to break into that network.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →