Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Attack modes and methods

Attack modes and methods, sometimes referred to as Tactics, Techniques, and Procedures (TTPs), are representations of how cyber adversaries behave. They characterize what these adversaries do and how they do it, in increasing levels of detail. Attack modes and methods apply for STIX 1.1.

For example, an attack mode/method might be to use malware to steal credit card credentials. Or another, related tactic (at a lower level of detail) might be to send targeted emails with attachments that contain malicious code, which executes upon opening, captures credit card information from keystrokes, and uses http to communicate with a command and control server to transfer information.

Attack modes and methods apply for STIX 1.1.

Parent Topic:IoC Repository

Related topics

Indicators of compromise

Observables

Attack patterns

Campaigns

Course of actions

Identities

Infrastructure

Intrusion set

Locations

Malware

Malware analysis

Observed data

Threat actors

Threat groupings

Marking definitions

Threat notes

Threat opinions

Threat reports

Sightings

Tools

Vulnerabilities

Relationships

STIX Visualizer