An enterprise SOC receives a threat report describing a campaign that uses signed binaries, scheduled tasks, and remote desktop. The report includes several file hashes and C2 IP addresses, but the analyst wants to pivot to other incidents by attacker behavior. Which element should the analyst prioritize?
Select an answer to reveal the explanation.
Short Explanation
Think of a burglar: footprints are artifacts, while climbing through a window is behavior. You're not chasing a single hash or IP here - you're mapping how the attacker moves and repeats. That's why TTPs, not indicators, describe behavior.
Full Explanation
Tactics, techniques, and procedures are threat-intelligence constructs used to describe how adversaries achieve objectives across a campaign. Tactics capture the goal, such as persistence or lateral movement, while techniques describe the implementation and procedures describe observable details within those techniques. In hunting, TTPs help analysts pivot from one incident to related activity because they focus on repeatable behavior rather than transient infrastructure. File hashes are observable artifacts that identify specific files; they can change through repacking or renaming and do not explain why an attacker used a file. IP addresses are network indicators that reveal communication endpoints but may be disposable, shared, or spoofed, so they are weaker for behavioral modeling. Registry keys are host-based artifacts that can indicate execution or persistence, yet they remain evidence of an action rather than the broader pattern of actions an attacker follows. Exam caveat: Do not confuse indicators of compromise with TTPs; indicators support detection, but TTPs support hunting and correlation. Operational check: When enriching an alert, record the observed artifact and map the associated technique to a framework such as MITRE ATT&CK before pivoting to other hosts.