TTP
Tactics, Techniques and Procedures (TTPs) describe how an attacker operates, from their goals to the concrete implementation.
Tactics, Techniques, and Procedures (TTPs) describe how an attacker operates. Tactics are the goals, techniques the methods, and procedures the specific implementation by a particular group.
How it works
A tactic could be 'stealing credentials'. A corresponding technique is reading credentials from memory (OS Credential Dumping, T1003). The procedure describes the specific tool and parameters used by a particular group. The MITRE ATT&CK knowledge base systematically catalogues these levels. It assigns an identifier to each technique.
For example, a ransomware group gains access via a VPN without MFA. They then use a legitimate remote administration tool. They delete shadow copies before encrypting data. Knowing these steps allows you to build a specific detection for each one. The attack can then be stopped early in the kill chain.
What to look out for
- Coverage: Check which relevant techniques are covered by your detection rules.
- Prioritisation: Not all techniques are equally important for your environment. Start by addressing the most common ones.
- Testing: Purple team exercises show whether rules trigger against real procedures.
- Context: Many techniques use legitimate system tools. The rule therefore needs knowledge of normal behaviour.
Why TTPs are important
Attackers can change their tools and IP addresses very quickly. Their overall methods, however, change much more slowly. Detection based on TTPs therefore remains effective for longer than pure IOC lists.
A second example
Many attackers create a scheduled task after gaining initial access. This allows them to maintain persistence after a system restart. The specific tool used for this often changes, but the technique does not. A rule for new scheduled tasks with unusual paths can detect many attackers. To avoid excessive noise, it needs exceptions for known software. These exceptions should be reviewed on a regular basis.
How we implement it
Our detection rules are mapped to the MITRE ATT&CK framework.