# What are Tactics, Techniques, and Procedures (TTPs)?

> Tactics, techniques, and procedures (TTPs) describe how threat actors pursue objectives and carry out attacks.

- Canonical URL: https://yellowcube.eu/glossary/tactics-techniques-and-procedures/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

In the MITRE ATT&CK model, a **tactic** is the adversary’s goal or reason for an action, a **technique** is the method used to achieve that goal, and a **procedure** is a specific implementation observed in real activity.

For example, initial access is a tactic; phishing (T1566) is one technique for achieving it; and a particular campaign’s lure wording, attachment type, and follow-on commands are the procedure. Mapping observations to TTPs gives defenders a shared language for detections, threat reports, exercises, and control testing.

### Key points

- **Primary purpose:** Describe adversary behavior in a way that can be compared across incidents and tools.
- **Defensive use:** Detection engineering, threat hunting, purple teaming, gap analysis, and incident reporting.
- **Relative durability:** Behaviors are often more stable than individual domains, addresses, or file hashes, though actors do change them.
- **Important limitation:** A TTP match rarely identifies an actor by itself; unrelated groups can use the same tools and techniques.

### Related terms

[MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)](<https://yellowcube.eu/glossary/mitre-att-and-ck-adversarial-tactics-techniques-and-common-knowledge/>) · [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/>) · [Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Cyber kill chain](<https://yellowcube.eu/glossary/cyber-kill-chain/>) · [Threat actor](<https://yellowcube.eu/glossary/threat-actor/>)

### Sources

[MITRE ATT&CK FAQ](https://attack.mitre.org/resources/faq/) · [MITRE ATT&CK: Enterprise tactics](https://attack.mitre.org/tactics/enterprise/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

