Describing attacks with crime script analysis

Source: Cisco Talos Blog

Author: Martin Lee

URL: https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/

https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/

ONE SENTENCE SUMMARY:

Crime script analysis narratively models attacks to expose AI-enabled scaling opportunities and highlight practical disruption points for defenders and stakeholders.

MAIN POINTS:

  1. Crime script analysis (CSA) creates human-readable attack stories for non-technical audiences.
  2. Modeling attacker workflows reveals where AI can industrialize previously manual attack preparation.
  3. Breaking attacks into discrete steps helps defenders locate effective intervention “choke points.”
  4. Cyber Kill Chain’s rigid linear sequence often fails to represent real-world attack variability.
  5. MITRE ATT&CK Attack Flow chains TTPs with branches and loops but can overwhelm stakeholders.
  6. CSA originated in 1990s criminology to map actions, decisions, and situational requirements.
  7. CSA complements ATT&CK and Attack Flow at different abstraction levels for different audiences.
  8. BEC scams exploit authority impersonation to trigger urgent payments and rapid money laundering.
  9. AI can automate target research and personalize lures, enabling many lower-value BEC attempts.
  10. Key disruptions include honeypot canary organizations, LLM trace detection, mail rate-limits, and victim controls.

TAKEAWAYS:

  1. Use CSA to communicate threats clearly when budgets shrink and audiences broaden.
  2. Expect AI to expand BEC targeting beyond large enterprises to smaller, historically unprofitable victims.
  3. Deploy deception (fake public personas) to poison recon and identify malicious senders early.
  4. Partner with AI and email providers for pattern-based detection and delivery-channel blocking.
  5. Strengthen payment governance—verification, purchase orders, and delays—to reduce successful fraud.