Attackers Don't Execute Frameworks. They Execute Procedures.

Attackers Don't Execute Frameworks. They Execute Procedures.

Cybersecurity has never had more intelligence.  Threat intelligence tells us who is targeting organizations. ATT&CK helps us understand adversary behaviors.  CTEM helps us identify and prioritize exposures.  Validation technologies test controls.  Risk platforms quantify impact.  Security teams today have more visibility than at any point in history.

Yet a fundamental challenge remains.

Despite all this intelligence, many organizations still struggle to answer a deceptively simple question:

Can we defend against the attacks most likely to impact our organization?

The reason is surprisingly simple. Most security programs are built around understanding threats.  Attackers are built around executing them. And that gap is precisely where Threat-Led Defense emerges.

The Industry's Blind Spot

For years, the cybersecurity industry has invested heavily in understanding adversaries.

Who is targeting us? What sectors do they attack? Which techniques do they use? What vulnerabilities are they exploiting?

These are important questions. But they are incomplete.

Knowing that a threat actor uses PowerShell, credential dumping, or lateral movement does not tell a security team how an attack is actually executed.  Likewise, knowing an organization has a critical vulnerability or an exposed asset does not determine whether that weakness can realistically be leveraged to achieve an adversary objective.

Threat intelligence, exposure management, and validation technologies each provide valuable insight.  But they often operate independently.  What is frequently missing is the operational context that connects them together.

Threat-Led Defense was created to solve this problem.

The Missing Layer: Adversary Procedures

Attackers do not execute techniques.  They execute procedures.  A technique describes what an adversary is attempting to accomplish.  A procedure describes how they actually accomplish it.  It is the sequence of commands, actions, tools, configurations, and workflows used to execute an attack.

This distinction matters more than many organizations realize.  Because defenders do not stop attacks at the level of frameworks.  They stop attacks at the level of execution. 

A control does not prevent a technique. A control prevents a command from running.  A detection does not identify a tactic.  A detection identifies an action.  A response playbook does not disrupt a framework.  It disrupts a procedure.

This is why procedures represent the operational foundation of Threat-Led Defense.

Why CTEM Needs Threat-Led Defense

The rapid adoption of Continuous Threat Exposure Management reflects an important reality.  Organizations need a better way to identify, validate, and prioritize exposures.

CTEM provides a valuable framework for doing exactly that.  But identifying exposures is only part of the equation.  The more difficult question is determining which exposures matter in the context of adversary execution.

Not every vulnerability creates meaningful risk.  Not every exposed asset becomes a breach.  Not every security gap contributes to attacker success.

The determining factor is whether an adversary can leverage those conditions through procedures that align with their objectives.  This is where Threat-Led Defense becomes the missing operational layer.  Threat-Led Defense introduces adversary execution into the decision-making process.

Instead of asking:  "What exposures exist?"  Organizations begin asking:  "Which adversary procedures are most relevant to our environment, and can our defenses disrupt them?"

That shift changes everything.

Recommendations Are Easy. Relevance Is Hard.

Assessments are notorious for producing recommendations. Exposure management platforms produce recommendations. Frameworks produce recommendations. The CTEM produces framework recommendations. In many organizations, the challenge is no longer a lack of guidance, it is an overwhelming abundance of it.

The question is no longer, "What should we do next?" The question is, "How do we know what we do next will actually reduce attacker success?"

This is where many organizations encounter a critical gap. Recommendations are often prioritized based on severity, maturity, complexity, implementation effort, or compliance requirements. While these factors are important, they do not necessarily reflect how adversaries operate or whether a particular action will meaningfully improve defensive effectiveness.

A recommendation may improve a maturity score. It may close an exposure. It may satisfy a framework requirement. But none of those outcomes inherently reduce the likelihood of compromise.

Threat-Led Defense introduces a different lens for prioritization. Rather than asking which recommendation is easiest to implement or which gap appears most severe, organizations begin by understanding the adversary procedures most relevant to their environment. Only then can they determine which defensive actions will have the greatest impact on disrupting attacker execution.

This shifts the conversation from prioritizing activity to prioritizing outcomes. From managing recommendations to reducing attacker success. And from making informed decisions to making adversary-led decisions grounded in how attacks actually happen.

From Threat Intelligence to Procedure-Led Intelligence

Traditional threat intelligence helps organizations understand threats.  Threat-Led Defense helps organizations operationalize them.  The bridge between the two is procedures.

Procedures transform intelligence into something actionable. They create a direct connection between:

  • Threat actors
  • Campaigns
  • Techniques
  • Assets
  • Vulnerabilities
  • Controls
  • Detections
  • Defensive outcomes

Viewed independently, each of these domains provides only a partial picture.  Viewed through the lens of adversary procedures, they become operational.  Organizations can prioritize vulnerabilities based on how attackers actually exploit them.  Detection engineers can focus on attack execution rather than generalized behavior.  Purple teams can emulate realistic adversary workflows.  Security leaders can align investments to measurable defensive impact.

This is the essence of Threat-Led Defense.  Not understanding threats but operationalizing them.

The Future of Defensive Security

For decades, cybersecurity has focused on understanding adversaries.  The next decade will be defined by operationalizing adversary execution.  The organizations that succeed will not necessarily have the most intelligence.  They will have the intelligence the includes procedures and adversary execution-led intelligence.

Equipped with this type of intelligence, organizations will understand not only who may target them, but how those adversaries execute attacks and where those attacks can be disrupted.  They will move beyond exposure-centric security and toward defense-centric security.  Beyond understanding risk and toward reducing attacker success.  Beyond threat-informed decision making and toward Threat-Led Defense.

Because attackers do not execute frameworks.  They execute procedures.  And defenders must learn to do the same.

Learn more about Threat-Led Defense


To view or add a comment, sign in

More articles by Tidal Cyber

Others also viewed

Explore content categories