The patterns of behaviour, methods, and tools that threat actors use to conduct attacks.
Tactics, Techniques, and Procedures (TTPs) describe how threat actors operate—their objectives (tactics), methods (techniques), and specific implementations (procedures). TTPs provide deeper understanding than IOCs alone, revealing attacker behaviour patterns that persist even when specific indicators change. The MITRE ATT&CK framework catalogues known TTPs, providing a common language for describing and defending against attacks. Understanding adversary TTPs enables proactive defence and threat hunting.
Why It Matters
The DSC Perspective:
TTPs reveal how attackers think and operate. While IOCs change frequently, TTPs are more stable—understanding adversary behaviour helps anticipate and prevent attacks. MITRE ATT&CK maps defences to known TTPs.
