Markdown

TTP

TTP is the Acronym for Tactics, Techniques, and Procedures

A framework for identifying and analyzing the behavior of threat actors, Tactics, Techniques, and Procedures (TTPs) describe an adversary’s operational methodology. Unlike static indicators of compromise (such as IP addresses or file hashes), TTPs focus on the how and why of an attack, allowing security operations to implement behavioral detection.

Component Definitions

Each part of TTPs serves a specific role in understanding an adversary’s actions.

  • Tactics: The high-level strategic objectives of an attacker. Examples include Initial Access, Persistence, or Exfiltration.
  • Techniques: The specific methods used to achieve a tactical objective. Examples include Spearphishing or Brute-Force attacks.
  • Procedures: The granular, step-by-step sequences of actions and specific tools employed during an engagement.

Application in Cybersecurity

Analyzing TTPs helps organizations move toward behavioral detection.

  • Behavioral Detection: By understanding the how and why of an attack, organizations can implement defensive controls that remain effective even when an attacker changes their specific software or infrastructure.

Military Use Case

The United States Navy's Carrier Airborne Early Warning Weapons School (CAEWWS) develops and teaches TTPs for E-2D and E-2C Hawkeye aircraft. Originally part of VAW-110, CAEWWS became an independent command in 1988 and is now integrated into the Naval Aviation Warfighting Development Center (NAWDC). It operates alongside other specialized weapons schools, such as TOPGUN and HAVOC, to enhance naval aviation tactics.

Additional Acronyms for TTP

  • TTP - Time to Profitability
  • TTP - Time to Productive
  • TTP - Time To Purchase