What are Tactics, Techniques, and Procedures (TTPs)? Why do CTI analysts talk about them all the time?

6.20.2022TeamT5 Media Center
Tactics, Techniques, and Procedures (TTPs) is a comprehensive description of a cyber actor's behavior.
  • Tactic: the highest-level description of the cyber actor’s behavior.
  • Technique: gives a more detailed description of behavior in the context of a tactic.
  • Procedure: an even lower-level, highly detailed description in the context of a technique.
A good threat intelligence will provide TTPs, so the reader has a detailed understanding of the cyber attack. Then, the reader will be able to take right defensive measures.

*Reference: tactics, techniques, and procedures (TTP) -
*Image courtsey of Pixabay
