logo

Threat-Led Defense Starts with Procedures, Not Techniques

ID: 4bade9d5-9a87-5c3b-ae56-6da2b181ec23

STIX ID: report--4bade9d5-9a87-5c3b-ae56-6da2b181ec23

Feed Name: Tidal Cyber Blog

Date Published: 2025-10-09

Date Updated: 2026-03-26

Author: Tidal Cyber

...
...

The document argues that aligning defenses solely to MITRE ATT&CK techniques can create false confidence and noisy detections, and advocates for procedure-level intelligence that captures specific commands, parameters, and methods adversaries use. It introduces Tidal Cyber’s Threat-Led Defense platform and Procedures Library, which map detections and controls to granular adversary behaviors, visualize coverage gaps, validate controls, and optimize configurations through a continuous feedback loop—enabling measurable, evidence-driven improvements across EDR, SIEM, and IAM stacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.