The correct order of the examples listed corresponds toTactic, Technique, Procedurein the TTP framework:
Tactic:The high-level goal or objective an adversary tries to accomplish. "Extend movement" (likely meant as "Lateral movement") or "Exploiting a remote service" are tactics that describewhatthe adversary wants to do.
Technique:The general method or approach used to achieve the tactic. "Exploiting a remote service" is a technique, detailing the type of action used in pursuit of the tactic.
Procedure:The specific implementation or instance of a technique. "Use EternalBlue to exploit a remote SMB server" is a concrete procedure, an exact exploit tool or method used.
This hierarchy is fundamental to frameworks likeMITRE ATT&CK, which guides how analysts categorize and investigate adversary behaviors.
[Reference:, Splunk Cybersecurity Defense Analyst Study Guide, Chapter 3: Tactics, Techniques, and Procedures Explained, MITRE ATT&CK Framework Documentation, Splunk Enterprise Security: Threat Intelligence and TTP Mapping, , ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit