Editorial
Procedures: The missing link
Between techniques & reality
If you’ve ever tried to move from knowing adversary behaviour to actually defending against it, you’ve probably hit the same wall we all have; abstraction.
MITRE ATT&CK® has been a game-changer for understanding how adversaries operate, but “Tactics” and “Techniques” only get us so far when you’re trying to write a detection rule, simulate an attack, or validate control coverage.
That’s why we thought the release of Procedures in Tidal Cyber’s Threat-Led Defense Platform is a big deal. It’s the first time anyone has delivered a structured, operationalised library of real-world adversary procedures and it’s built to make Threat-Led Defence actually work at the technical level.
So, as a defender, we've unpicked what we think are the highlights for you.
Why procedure matters
Every defender knows “TTPs”, Tactics, Techniques, and Procedures, but until now, the “P” has always been the missing link.- Tactics tell us why adversaries act
- Techniques tell us what they do
- Procedures finally show us how they do it — in the specific, technical detail we need to act
The challenge as we see it
What’s New: The Procedures Library
- 20,000+ real-world “Sightings” - each representing a specific, observed instance of threat activity.
- 2,300+ “Clusters” - grouping similar Sightings for a higher-level analytical view.
- Linked directly to ATT&CK tactics, techniques, sub-techniques, and technology platforms (Windows, Linux, macOS).
- Mapped to detection components, capabilities, and visibility requirements giving you an instant view of where you’re strong, and where you’re blind.
How they did it
The library was built using clearly-aligned definitions:
“A Procedure is a clearly defined, repeatable set of technical actions that an adversary, or simulated adversary, executes to achieve a specific objective.”
That definition became the foundation for a huge data engineering effort. Tidal’s proprietary AI, developed after its acquisition of Zero-Shot Security, processed over 1,500 technical threat reports, extracting procedure-level data points buried deep within them. This isn’t more threat intel. It’s operationalised threat intel that's structured, linked, and ready to use.
What you can do with it
This is about giving defenders precision not more noise. With Procedures integrated directly into Tidal Cyber’s platform, defenders can now:
- See real-world Procedures mapped to your stack’s capabilities: Understand which behaviours your current tools detect and which they don’t.
- Use Coverage Maps to visualise exposure: Move from “we think we’re covered” to “we know exactly which TTPs we can stop.”
- Build detections and simulations faster: Use structured Procedures as a foundation for new rules, tests, or red-team exercises.
- Prioritise your next move: Focus on the behaviors that matter most to your environment — not every technique in the book.
What it means for Threat-Led Defence
Threat-Led Defence only works when intelligence is usable. Tidal Cyber’s Procedures close the gap between intel and action. By structuring how adversaries actually execute behaviours and linking that directly to detection logic, visibility needs, and control mapping, it’s now possible to operationalise Threat-Led Defense at scale.
Whether you’re:
- writing detection,
- running purple team exercises,
- building your next hunt query, or
- reporting on coverage to leadership,
you’ll have the procedure-level intelligence you’ve been missing.
Why we think our Community should care
This release represents something bigger than a product update, it’s a shift in how the defender community can use threat intel. For years, we’ve been guessing and now we can prove it.
Procedures turn abstract TTP's into defensible actions. They let us measure what really matters, but are we ready for how attackers actually operate?
In Summary
This is the kind of progress that moves Threat-Led Defence from concept to capability. If you’re ready to close the gap between what you know and what you can do, it’s time to explore what these new Procedures can unlock for your team.
Unlock the value of Procedures
NARC gives you the "how" behind the attack, not just the headline tactics & techniques. NARC centers on procedures, automatically pulling them from unstructured data and reports to provide the fidelity customers need to defend against the threats that matter most.
dOWNLOad
About this Sponsor
Also in this section
Cyber Security
From IOC Chasing to Threat-Led Defence
Breaking out of the loop
Cyber Security
Tidal Cyber - Threat -Led Defence Video
When 'Good' looks THIS GOOD!
Cyber Security
Sleighing cybersecurity threats
How the North Pole is preparing for more AI mischief in 2026
Cyber Security
Get hands-on
from Tidal Cyber Community Edition to an Enterprise rollout
Cyber Security
Choose your path to Threat-Led Defence
Book your discovery call now
Cyber Security
Threat-Led Defence Whitepaper
Techniques, procedures, adversary change
Cyber Security
What “Good Coverage” Actually Means
(and why you probably don't have it yet)