Skip to main content
Category: Threat Intelligence & Simulation

Tactics, Techniques, and Procedures

Also known as: TTPs, TTP, Tactics Techniques and Procedures
Simply put

Tactics, techniques, and procedures (TTPs) is a cybersecurity term that describes how threat actors behave when they plan and carry out attacks. It breaks that behavior into three levels: tactics are the broad goals or approach, techniques are the more specific methods used to achieve them, and procedures are the detailed steps an attacker follows. Security teams study TTPs to recognize patterns of malicious activity and better anticipate how attackers operate.

Formal definition

TTPs is a threat intelligence construct that characterizes adversary behavior across three levels of abstraction. A tactic is the highest-level description of behavior, often representing the adversary's objective; a technique provides a more detailed description of behavior within the context of a tactic; and a procedure describes the specific, concrete implementation an actor uses to execute a technique. Analysts use TTPs to identify and correlate patterns of behavior attributable to particular threat actors, supporting detection, attribution, and defensive planning. Because TTPs focus on behavior rather than on transient indicators such as file hashes or IP addresses, they are typically more durable for tracking adversaries over time.

Why it matters

TTPs matter because they shift defensive attention away from fragile, easily changed signals and toward the more durable patterns of how adversaries actually behave. Indicators such as file hashes, domains, and IP addresses can be swapped out by an attacker in minutes, but the underlying tactics, techniques, and procedures reflect deliberate choices, tooling, and habits that tend to persist across campaigns. By characterizing adversary behavior across the three levels of abstraction, security teams can recognize malicious activity even when surface-level indicators change, and can correlate activity to particular threat actors to support detection, attribution, and defensive planning.

Who it's relevant to

Virtual and Fractional CISOs
A vCISO or fractional CISO uses an understanding of TTPs at the strategy and governance level rather than as a hands-on analyst. In many engagements, they help a client prioritize defensive investments against the kinds of adversary behavior most relevant to that organization, and translate behavioral threat intelligence into risk-informed decisions for leadership. It is worth noting that the vCISO typically advises and directs; the operational work of building detections and hunting for TTPs generally sits with the client's internal team or contracted providers, and accountability for those decisions usually remains with the client organization.
Threat Intelligence and Detection Teams
Analysts and detection engineers work directly with TTPs to identify and correlate patterns of behavior attributable to particular threat actors. Because TTPs focus on behavior rather than transient indicators, they support detection and attribution that remains useful over time, even as an adversary changes infrastructure or tooling.
Security Leaders and Buyers Evaluating Engagements
Organizations considering a virtual security leadership engagement benefit from understanding that TTP-informed defense is a program and governance function, not solely a technical exercise. The value of any TTP-based defensive planning depends on organizational maturity, the availability of relevant telemetry, and stakeholder cooperation. Buyers should also avoid conflating a vCISO who advises on threat-informed strategy with a managed security service provider that performs continuous monitoring and hands-on detection work.

Inside TTPs

Tactics
The highest-level description of an adversary's objectives or the 'why' behind an action, such as gaining initial access, establishing persistence, escalating privileges, or exfiltrating data. Tactics represent goals rather than specific methods.
Techniques
The general methods or 'how' an adversary uses to achieve a tactical objective, for example phishing to gain initial access or credential dumping to obtain privileged accounts. Techniques are more specific than tactics but still describe an approach rather than a single tool.
Procedures
The specific, detailed implementations of a technique, including the exact sequence of steps, tools, or commands an adversary uses. Procedures are the most granular layer and often reveal patterns associated with a particular threat actor or campaign.
Behavioral focus
TTPs describe adversary behavior and intent rather than static indicators such as file hashes or IP addresses. Because behavior is harder for an attacker to change than infrastructure, TTPs tend to be more durable for detection and threat modeling.
Relationship to threat intelligence and frameworks
TTPs are commonly organized and communicated using structured knowledge bases and frameworks that catalog adversary tactics and techniques, supporting consistent analysis, detection engineering, and threat-informed defense. A virtual CISO typically uses TTP awareness to inform strategy and program priorities rather than to perform hands-on threat hunting, which is often out of scope unless explicitly contracted.

Common questions

Answers to the questions practitioners most commonly ask about TTPs.

Is a TTP just another word for a specific piece of malware or a single technical indicator?
No, and this is a common conflation worth correcting. Tactics, Techniques, and Procedures describe the behavioral patterns and operational approaches an adversary uses to achieve objectives, not a single artifact. Indicators such as file hashes, IP addresses, or domain names are atomic and often short-lived, whereas TTPs describe how an attacker operates and tend to be more durable. A virtual CISO typically emphasizes understanding TTPs precisely because they are harder for an adversary to change than swapping out an IP address, though the two concepts are complementary rather than interchangeable.
Does analyzing an adversary's TTPs mean my organization can prevent breaches?
No. Understanding TTPs supports better detection and defensive prioritization, but it does not guarantee breach prevention, and a virtual CISO should not frame it as doing so. TTP analysis helps a security program align controls and monitoring against how attackers are likely to behave, which can improve resilience. However, the value depends on organizational maturity, the quality of available intelligence, and the client's ability to act on findings. A vCISO advises and directs this work at a governance and risk level; accountability for security outcomes typically remains with the client organization and its officers.
How does a virtual CISO typically help an organization use TTP analysis without running a security operations center?
In many engagements, a virtual CISO operates at the strategy and governance level rather than performing hands-on monitoring or threat hunting. They may help the organization identify which adversary behaviors are most relevant to its industry and risk profile, prioritize where detection and control investments should go, and ensure that any internal team or managed provider is tasked appropriately. Operational execution such as SOC monitoring or incident response is generally out of scope unless explicitly contracted, so the vCISO often coordinates rather than performs that work.
How can TTPs be mapped to a framework the organization already uses?
A virtual CISO can often help align TTP analysis with frameworks the organization already relies on, such as mapping observed or relevant adversary behaviors to control categories within NIST CSF or to controls being assessed under ISO 27001 or SOC 2. The purpose is to translate threat behavior into governance and control decisions, not to assert certification. It is worth noting that supporting this mapping helps readiness and prioritization; it does not by itself demonstrate compliance or produce a certification, which remain separate processes.
What organizational conditions make TTP-informed defense effective?
The value of TTP-informed work depends heavily on organizational maturity, client cooperation, defined scope, and access to relevant stakeholders. An organization with limited logging, visibility, or internal ownership may struggle to act on TTP insights regardless of their quality. In practice, a virtual CISO often first assesses whether the foundational capabilities exist to consume and respond to this analysis, then advises on closing gaps before expecting meaningful defensive improvement.
Who is accountable for acting on TTP findings surfaced during a vCISO engagement?
A virtual CISO typically advises on and directs how TTP findings should inform strategy, priorities, and control decisions, but legal and organizational accountability for acting on those findings usually remains with the client organization and its officers. Responsibility for execution may sit with an internal team, a managed provider, or specific business owners as defined in the engagement scope. Unless a contract specifies otherwise, the vCISO does not assume liability or regulatory accountability for the outcomes of security decisions.

Common misconceptions

TTPs are the same as indicators of compromise (IOCs) such as malicious IPs, domains, or file hashes.
TTPs describe adversary behavior and methods, while IOCs are discrete artifacts left behind by activity. IOCs change frequently and are easy for attackers to rotate, whereas TTPs reflect underlying behavior that is generally more stable and therefore more valuable for durable detection and defense planning.
Understanding TTPs guarantees an organization can prevent breaches.
Awareness of adversary TTPs informs risk prioritization and defensive strategy, but it does not guarantee prevention. Effectiveness depends on organizational maturity, detection and response capabilities, defined scope, and the resources available to act on the intelligence. A virtual CISO can help align priorities to relevant TTPs but advises and directs rather than assuming accountability for outcomes.
The three levels, tactics, techniques, and procedures, are interchangeable terms for the same thing.
They are distinct layers of abstraction. Tactics are objectives, techniques are the general methods used to meet those objectives, and procedures are the specific implementations. Conflating them undermines precise analysis and communication among security stakeholders.

Best practices

Prioritize TTP-based analysis over reliance on transient indicators, since adversary behavior is typically more durable and harder to change than infrastructure artifacts like IPs or hashes.
Map identified TTPs to a structured framework so that tactics, techniques, and procedures are described consistently and can be communicated clearly to both technical teams and business stakeholders.
Use TTP awareness to inform governance and risk prioritization decisions, recognizing that a virtual CISO generally directs strategy while hands-on detection, threat hunting, and incident response execution are separate functions unless explicitly contracted.
Distinguish clearly among the three abstraction levels, objectives (tactics), methods (techniques), and detailed implementations (procedures), when documenting or discussing adversary activity to avoid analytical confusion.
Set realistic expectations with the organization that understanding TTPs supports defensive readiness and prioritization but does not guarantee breach prevention, and that value depends on maturity, scope, and stakeholder cooperation.
Confirm access to relevant stakeholders and data sources so that TTP-informed recommendations can be validated against the organization's actual environment rather than treated as generic guidance.