Knowledge / detection IR threat-intel

Tactics, techniques, and procedures

How they work, not just which IP they used today. ATT&CK is the common catalogue.

TTPs describe adversary behaviour: the tactic (why), the technique (how in general), the procedure (how this group, this month). An IOC is a fingerprint. A TTP is the method.

MITRE ATT&CK is the shared language so detections can be mapped and gaps seen. Hunt the behaviour even when the hash is new: living off the land, token theft, unusual mail forwarding.

See also: MITRE ATT&CK, Indicator of compromise, Threat hunting, Living off the land.