Open cardosec

Case 4B9537 · Malware & intel · L1 Foundations

IOCs vs TTPs

Practise as: Explain it · Interview

Interview questionWhat is the difference between an IOC and a TTP, and which is more valuable for detection?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. IOCs are artifacts of a past compromise: hashes, IPs, domains, file paths, registry keys
  2. TTPs are adversary behaviors: tactics, techniques and procedures, e.g. dumping LSASS with comsvcs.dll
  3. IOCs are cheap to share and match but short-lived; attackers rotate infrastructure and recompile in minutes
  4. TTP-based detections are harder to build but survive tool changes, so they last longer
  5. Use IOCs for fast sweeps and scoping; invest in TTP detections for durable coverage

If the interviewer pushes back

  • How would you turn a vendor IOC report into a behavioral detection?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.