Thriving Defense

Home

❯

methodology

❯

systematically disrupt attacker behavior

systematically disrupt attacker behavior

Mar 24, 20261 min read

  • author/Jordan_Anderson
  • type/stub

The long-term vision of the Pyramid of Pain was to force attackers to change their TTPs. We need more of that (though it’s quite hard to pick winners).

Here are some examples where this has actually happened historically:

  • attackers are avoiding EDR
  • Macros are no longer the primary email malware attack vector (due to Macros from the internet are blocked by default in Office - Microsoft 365 Apps | Microsoft Learn)

Graph View

Backlinks

  • Selecting Advantageous Terrain

Created with Quartz v4.5.2 © 2026

  • GitHub