Acronym for Tactics, Techniques, and Procedures—how threat actors conduct their attacks.
TTP stands for Tactics, Techniques, and Procedures. See 'Tactics, Techniques, and Procedures' for the full definition. TTPs are essential for understanding threat actors beyond simple indicators.
Why It Matters
The DSC Perspective:
TTP analysis helps security teams understand and anticipate attacker behaviour. When evaluating security tools, consider how well they detect known TTPs rather than just specific indicators.
