A municipal SOC is documenting an LSASS dump on a finance workstation. How should the analyst label the three TTP layers?
Select an answer to reveal the explanation.
Short Explanation
Goal, method, recipe. Credential Access is why they showed up, OS Credential Dumping is how, and the exact malware-plus-LSASS command is the one-off recipe on that finance PC.
Full Explanation
Industry TTP language has three layers: a tactic is the adversary's goal (Credential Access), a technique is the method (OS Credential Dumping), and a procedure is the specific implementation in this environment—the malware family and dump command on the municipal finance host. Hashes, VLANs, sourcetypes, CIM models, and notable urgency are not those layers. Civic analysts should keep the three labels distinct and never collapse them into a single IoC.