Tactics, techniques, and procedures describe how an adversary operates to achieve an objective. Tactics are the goal, techniques are the method, and procedures are the exact implementation. In hunting, they are more durable than artifacts because they reflect attacker tradecraft.
Expanded Definition
Tactics, techniques, and procedures, usually shortened to TTPs, are a structured way to describe attacker behaviour across intent, method, and execution. The tactic is the objective, such as persistence or credential access. The technique is the general approach used to pursue that objective. The procedure is the observed, actor-specific implementation. This distinction is central to threat intelligence because it helps defenders separate durable tradecraft from one-off indicators that change quickly.
In practice, TTPs are most useful when mapped to frameworks such as the MITRE ATT&CK Enterprise Matrix, which organises adversary behaviour into repeatable patterns. For AI-related threats, the same logic is increasingly applied through the MITRE ATLAS adversarial AI threat matrix, although usage in the industry is still evolving and not every team applies the term consistently across conventional and AI security operations.
The term is often misunderstood when teams treat techniques and procedures as the same thing, or when they focus only on malware hashes and IP addresses instead of the behaviour that enabled the intrusion. The most common misapplication is calling any observed attack detail a TTP, which occurs when analysts fail to distinguish the attacker’s objective from the specific steps used in that incident.
Examples and Use Cases
Implementing TTP analysis rigorously often introduces investigation overhead, requiring organisations to weigh faster incident triage against the cost of deeper behavioural analysis and better detection engineering.
- A phishing campaign may use the tactic of initial access, the technique of spearphishing attachment, and a procedure involving a uniquely crafted invoice lure sent from a compromised mailbox.
- A ransomware actor may pursue impact through encryption, using scheduled tasks for execution and a specific sequence of discovery commands before deployment.
- An AI-enabled threat may use prompt injection or tool abuse against an agentic workflow, with the procedure varying by model, connector, and access scope. In these cases, the MITRE ATLAS adversarial AI threat matrix is useful for grouping the behaviour.
- A cloud intrusion may rely on credential dumping followed by valid account use, where the tactic is persistence or privilege escalation and the procedure reflects the attacker’s exact commands and tooling.
- Threat hunters may map recurring behaviour to the MITRE ATT&CK Enterprise Matrix and then align response actions to NIST SP 800-53 Rev 5 Security and Privacy Controls for detection, logging, and incident response.
Security teams also use TTPs in tabletop exercises, red team reporting, and detections-as-code work, where the goal is to encode how an adversary behaves rather than merely what artefact was seen on one host.
Why It Matters for Security Teams
TTPs matter because they are more durable than single indicators and therefore better suited to detection engineering, hunt planning, and adversary emulation. If a team understands the tactic and technique but not the procedure, it may miss the exact execution path used in its own environment. If it focuses only on procedures, it risks overfitting to one incident and failing to recognise the same actor when the tooling changes.
This matters especially where identity and access are involved. Many intrusions now hinge on valid accounts, token abuse, session hijacking, or privilege escalation, so TTPs often reveal gaps in IAM, PAM, and NHI governance even when endpoint alerts are weak. Mapping these behaviours to control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls helps teams move from narrative threat reports to concrete defensive requirements.
Organisations typically encounter the limits of their detection strategy only after a real intrusion repeats a familiar behavioural pattern in a new way, at which point TTP analysis becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM | CSF monitoring and detection functions depend on recognising adversary behaviour patterns. |
| NIST SP 800-53 Rev 5 | RA-5 | Security assessment and vulnerability scanning benefit from mapping known attacker techniques. |
| MITRE ATLAS | ATLAS organizes adversarial AI tactics and techniques for AI-specific threat understanding. | |
| OWASP Agentic AI Top 10 | Agentic AI risks often emerge as repeatable attack behaviors against tools and workflows. | |
| NIST AI RMF | AI RMF supports structured risk analysis of adversarial behaviors affecting AI systems. |
Use observed TTPs to improve continuous monitoring and detect recurring hostile behaviour.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org