Tactic, Technique, Procedure, or TTP, is a way of describing attack behavior at three levels of detail. Tactics are the adversary’s goals, techniques are the methods used to reach those goals, and procedures are the specific implementations seen in a campaign or test.
What TTP Means in Cybersecurity
TTP is shorthand for tactic, technique, and procedure, a three-level way of describing adversary behavior. It helps analysts move from broad intent to specific actions and repeatable implementation details.
Why TTPs Matter for Threat Analysis
TTPs are useful because they give defenders a stable vocabulary for describing how an adversary operates, even when tooling, infrastructure, or target environments change. A tactic captures the objective, a technique captures the method, and a procedure captures the observed execution pattern. That structure makes it easier to compare incidents, map campaigns, and separate a one-off artifact from a recurring attacker pattern.
At the technique level, defenders can generalize across many incidents that use the same method. At the procedure level, they can preserve campaign-specific detail, such as the exact commands, payload sequence, or operator behavior seen in a case.
How TTPs Support Detection and Hunting
TTPs are especially valuable in detection engineering and threat hunting because they anchor analysis to behavior rather than to static indicators. A hash, domain, or IP can disappear quickly; a technique such as credential dumping or phishing-enabled initial access tends to remain recognizable across campaigns. That is why behavior-based frameworks such as MITRE ATT&CK Enterprise Matrix are often used to structure detections, hunt hypotheses, and incident reporting.
When teams document procedures, they can also measure how an adversary executed a technique in their environment, which improves triage and response. The same technique may be performed differently in different systems, so procedures provide the operational context needed to avoid overgeneralizing from a single alert.
TTPs in Practice, Across Incidents and Frameworks
TTPs are a bridge between raw telemetry and a durable threat model. They are often used to connect observed activity to known adversary playbooks, red-team outcomes, and mitigations. For AI-related attack behavior, analysts may use MITRE ATLAS adversarial AI threat matrix to describe tactics and techniques in systems where prompts, tools, memory, or agents become part of the attack surface.
That same concept also helps during control design. If a procedure shows that an attacker repeatedly abuses a specific workflow, defenders can map the behavior to defensive countermeasures and then evaluate whether prevention, detection, or recovery controls address the actual method rather than the symptom.
Risk and Threat Considerations
TTPs matter because attackers often reuse the same techniques and procedures across different campaigns, while changing only their infrastructure or payloads. That creates a risk of false confidence if defenders focus on indicators alone instead of the behavior that actually enabled the compromise.
Failure mechanism: Detection misses, weak attribution, and incomplete incident reconstruction occur when organizations track only visible artifacts and fail to normalize the underlying tactic, technique, and procedure.
Impact: The result is slower containment, weaker hunting coverage, and a reduced ability to recognize repeatable attack patterns across separate incidents.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and MITRE ATLAS define the specific risk controls and attack patterns relevant to this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1059 — Command and Scripting Interpreter | ATT&CK organizes adversary behavior into tactics, techniques, and procedures. |
| Recommendation — Map observed activity to ATT&CK techniques and use them to drive detections and hunts. | ||
| MITRE ATLAS | T0001 — Prompt Injection | ATLAS applies the TTP model to adversarial AI behavior and attack techniques. |
| Recommendation — Map AI incidents to ATLAS techniques and monitor for repeated adversary behaviors. | ||
Practitioner Guidance
Why practitioners should care: TTPs are most useful when they are treated as an operating model for analysis, not just as terminology in a report. If an incident write-up stops at “malicious activity” or a list of indicators, it usually leaves too much ambiguity for future detections and response lessons.
Common misunderstanding: Teams sometimes use “TTP” to mean any threat detail. In practice, the three levels are different, and keeping tactic, technique, and procedure distinct improves consistency when analysts compare cases or hand findings to hunters, engineers, or response teams.
Practitioner takeaway: Good TTP documentation should preserve both the repeatable behavior and the exact way it was carried out, because both are needed for durable detection and response learning.
Related resources from NHI Mgmt Group
- Why do MITRE ATT&CK detections that reach Technique or Tactic level matter more than generic alerts?
- How can organisations measure whether technique-level detection is working?
- Why do technique-based controls work better than payload filters for modern exploits?
- Why do technique-level detection scores often overstate real coverage?