Chapter 4. The Adversary’s Modus Operandi
Modus operandi (MO) is a term widely used in law enforcement work to analyze and understand the methods criminals employ in committing an offense, including the steps they take to execute, conceal, and escape. In criminal profiling, studying MO helps to shed light on thought processes and habits by giving a deeper understanding of psychology and behavior patterns. Just like understanding MO is important in understanding the behavior patterns and thought processes of criminals in traditional law enforcement, understanding tactics are essential in cybersecurity to understanding the methods used by cybercriminals in executing attacks. Think of tactics like a sports team’s playbook: just as a football team needs to know the different plays their opponents might use, cybersecurity teams need to understand the various methods that hackers could use to attack their systems.
The primary purpose of the ATT&CK framework is to provide a helpful tool for understanding the common tactics used by cybercriminals, while also serving as a useful resource for incident response, penetration testing, and enhancing security operations. However, it’s important to remember that not every attacker will follow all the tactics listed in the framework. Cyberattacks can take many forms, and the methods used by attackers can vary greatly depending on what they’re trying to accomplish and whom they’re targeting. This means it would be hard to order the tactics in a ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access