Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      World Bank set to back South Africa’s big energy grid roll-out

      20 June 2025

      The algorithm will sing now: why musicians should be worried about AI

      20 June 2025

      Sita hits back at critics, promises faster, automated procurement

      20 June 2025

      The transatlantic race to create the first television

      20 June 2025

      Listed: All the MVNOs in South Africa – 2025 edition

      19 June 2025
    • World

      Watch | Starship rocket explodes in setback to Musk’s Mars mission

      19 June 2025

      Trump Mobile dials into politics, profit and patriarchy

      17 June 2025

      Samsung plots health data hub to link users and doctors in real time

      17 June 2025

      Beijing’s chip champions blacklisted by Taiwan

      16 June 2025

      China is behind in AI chips – but for how much longer?

      13 June 2025
    • In-depth

      Meta bets $72-billion on AI – and investors love it

      17 June 2025

      MultiChoice may unbundle SuperSport from DStv

      12 June 2025

      Grok promised bias-free chat. Then came the edits

      2 June 2025

      Digital fortress: We go inside JB5, Teraco’s giant new AI-ready data centre

      30 May 2025

      Sam Altman and Jony Ive’s big bet to out-Apple Apple

      22 May 2025
    • TCS

      TCS+ | AfriGIS’s Helen Hulett on how tech can help resolve South Africa’s water crisis

      18 June 2025

      TechCentral Nexus S0E2: South Africa’s digital battlefield

      16 June 2025

      TechCentral Nexus S0E1: Starlink, BEE and a new leader at Vodacom

      8 June 2025

      TCS+ | The future of mobile money, with MTN’s Kagiso Mothibi

      6 June 2025

      TCS+ | AI is more than hype: Workday execs unpack real human impact

      4 June 2025
    • Opinion

      South Africa pioneered drone laws a decade ago – now it must catch up

      17 June 2025

      AI and the future of ICT distribution

      16 June 2025

      Singapore soared – why can’t we? Lessons South Africa refuses to learn

      13 June 2025

      Beyond the box: why IT distribution depends on real partnerships

      2 June 2025

      South Africa’s next crisis? Being offline in an AI-driven world

      2 June 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Altron Group
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SevenC
      • SkyWire
      • Solid8 Technologies
      • Telit Cinterion
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • SMEs and start-ups
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Information security » Tactics, techniques, procedures: the cybercrime inside track

    Tactics, techniques, procedures: the cybercrime inside track

    Promoted | Rather than only focusing on the latest security tech, enterprise teams should take advantage of shared intelligence and understand TTPs, or tactics, techniques and procedures.
    By Digital Resilience Insight21 February 2023
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    Cybercrime numbers are alarming. According to data management firm Splunk, 65% of organisations reported an increase in cyberattack attempts during 2022, and 49% have suffered a data breach since 2020 — a 10% leap. Though it can seem as if we’re losing the war against online criminals, this isn’t a one-sided confrontation.

    Several reports note a reduction in successful breaches, and ransomware gangs took in less money during 2022 because companies are more reluctant to pay. It’s not enough to declare victory, but cybercrime stats no longer go in one direction, thanks to the industry educating people and businesses and adopting more sophisticated cybersecurity technologies.

    Yet if security, data and risk teams are not careful, they might lose this advantage. A new analysis by Splunk, delving into the findings of several respected threat reports, reveals that the most popular attacks are often still among the simplest. Rather than only focusing on the latest security tech, enterprise teams should take advantage of shared intelligence and understand TTPs, or tactics, techniques and procedures.

    This approach will help them thwart the most obvious attacks that tend to go under the radar, even in sophisticated cybersecurity estates, says Alan Browning, GM at Digital Resilience Insight, a Splunk partner:

    “The Splunk report is an opportune reminder that only a small group of cybercriminals use the latest and most sophisticated techniques. Most will go for tested techniques, especially when those might be ignored by security teams looking at newer threats. But the real benefit of using this information and the ATT&CK knowledge base is that teams can predict and preempt these attacks and put proactive safeguards in place.”

    Means of ATT&CK

    Browning refers to MITRE ATT&CK, a knowledge base of adversary tactics and techniques. Splunk used ATT&CK data as part of its analysis, identifying the most common attack types based on real-world observations.

    In Splunk’s analysis, four activities bubbled up as the most common:

    • PowerShell command and scripting interpreter: Criminals abuse the powerful Microsoft PowerShell command-line system for various tasks, such as discovery and executing code.
    • Obfuscated files or information: Criminals hide executables and other files from discovery by using encryption, compression and other methods.
    • Ingress tool transfer: Once they gain a foothold, criminals transfer tools and files from an external system into a compromised system.
    • System service execution: Criminals abuse system services or daemons to launch commands or programs, often at boot but also during other periods.

    These four are the most common, but Splunk lists several more important avenues of attack, including file and directory discovery, exploiting public-facing applications, and external remote services. Yet the overarching point is that these are known and obvious methods used by online criminals, and studying their TTPs will guide security teams to reinforce their environments.

    Know your TTPs

    Tactics, techniques and procedures are very important, not the least because it’s the criminals who tell us about them, says Browning.

    “You’d think the bad guys would be stealthy and the good guys would work together. But it’s almost the opposite. While security people don’t share as much intelligence and knowledge as they could, adversaries love to share new and reliable attack methods with others on forums and such places. Between collecting attack data and reading what those guys post, we have access to excellent shared intelligence on what attacks to look for.”

    The anatomy of an attack can split into TTPs:

    • Tactics are how online criminals carry out an attack, such as accessing data or moving around a network.
    • Techniques are their general methods, such as installing malware or running unauthorised database commands — tactics usually consist of several techniques.
    • Procedures are the granular steps of techniques. For example, crafting and deploying a phishing e-mail to deliver malicious software.

    Security teams gain a significant advantage when they focus on popular attack methods and study their TTPs. While adopting the latest security measures is imperative, the fundamentals of comprehensive security come from understanding and preempting common attacks.

    “Good security is about risk management,” says Browning. “Where are your risks and how do you mitigate against them? The downside is that the people who create those risks are very adversarial and constantly changing. But the upside is that they also want low risk and high reward, so they often go for proven tactics. Splunk’s analysis clearly shows this effect. I think it’s very important that security teams make TTP studies a part of their strategy, and that they use security providers that take the concept seriously.”

    For more information, connect with Digital Resilience Insight on LinkedIn, or contact GM Alan Browning.

    About Digital Resilience Insight
    Digital Resilience Insight is a leading provider of data security solutions for businesses and organisations of all sizes. With its cutting-edge technology and knowledgeable team, the company is committed to helping its customers protect their sensitive information.

    • This promoted content was paid for by the party concerned


    Alan Browning Atvance Atvance Intellect Digital Relience Insight Splunk
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleRicoh SA completes sustainable solar roll-out at new premises
    Next Article Tether tightens its grip on the wobbling world of stablecoins

    Related Posts

    Cisco to lay off thousands more employees: sources

    12 August 2024

    Get ready for a tidal wave of software M&A

    26 September 2023

    Cisco agrees to buy Splunk for $28-billion in cash

    21 September 2023
    Add A Comment

    Comments are closed.

    Company News

    Making IT happen: how Trade Link gears up to enable SA retail strategies

    20 June 2025

    Why parents choose CambriLearn for online education

    19 June 2025

    Disrupt first, ask questions later – the uncomfortable truth about incident response

    18 June 2025
    Opinion

    South Africa pioneered drone laws a decade ago – now it must catch up

    17 June 2025

    AI and the future of ICT distribution

    16 June 2025

    Singapore soared – why can’t we? Lessons South Africa refuses to learn

    13 June 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.