Source: Cisco Talos Blog
Author: Martin Lee
URL: https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/
https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/
ONE SENTENCE SUMMARY:
Crime script analysis narratively models attacks to expose AI-enabled scaling opportunities and highlight practical disruption points for defenders and stakeholders.
MAIN POINTS:
- Crime script analysis (CSA) creates human-readable attack stories for non-technical audiences.
- Modeling attacker workflows reveals where AI can industrialize previously manual attack preparation.
- Breaking attacks into discrete steps helps defenders locate effective intervention “choke points.”
- Cyber Kill Chain’s rigid linear sequence often fails to represent real-world attack variability.
- MITRE ATT&CK Attack Flow chains TTPs with branches and loops but can overwhelm stakeholders.
- CSA originated in 1990s criminology to map actions, decisions, and situational requirements.
- CSA complements ATT&CK and Attack Flow at different abstraction levels for different audiences.
- BEC scams exploit authority impersonation to trigger urgent payments and rapid money laundering.
- AI can automate target research and personalize lures, enabling many lower-value BEC attempts.
- Key disruptions include honeypot canary organizations, LLM trace detection, mail rate-limits, and victim controls.
TAKEAWAYS:
- Use CSA to communicate threats clearly when budgets shrink and audiences broaden.
- Expect AI to expand BEC targeting beyond large enterprises to smaller, historically unprofitable victims.
- Deploy deception (fake public personas) to poison recon and identify malicious senders early.
- Partner with AI and email providers for pattern-based detection and delivery-channel blocking.
- Strengthen payment governance—verification, purchase orders, and delays—to reduce successful fraud.