Nemstar Insights
By Sean Hanna, Founder & Director of Nemstar
January 14, 2025
According to Google and TechTarget.com, it is: anyone attempting to gain unauthorized access to a computer computing system or network with the intent of disabling, disrupting or destroying it.
Or using hacking techniques on computer systems to alter, block, delete, manipulate or steal the data held within these systems.
A cyber attack can be launched from anywhere by any individual or group.
It sounds boring when I look at the definition. I think:
“Geez, if I had read that, I don’t know if I would’ve actually started a career in this. It must be more interesting than that!”.
There are many different types of hackers using threat intelligence to get past network security. White hat or ethical hackers are computer security experts or programmers who use technical skills to find cybersecurity vulnerabilities in order to fix them. And there are also black hat hackers who use methods like social engineering to find vulnerabilities and take advantage of them.
You see the definition of what a hacker is, is not actually that interesting. But how they accomplish a hack, the steps they take and the modus operandi of the hacker is incredibly interesting. As a security architect and security consultant, I am interested in two really important things: Tactics, techniques and procedures (TTPs) and Indicators of Compromise (IOCs).
The TTP of a hacker is their modus operandi. The tactics, the techniques, and the procedures they use even if it is for ethical hacking. Hackers deploy different ways of attacking networks. They all follow the same general principles, but each group of hackers, or APTs (Advanced Persistent Threat Groups) has a different modus operandi.
They’ve got signatures. Tell-tale things that one crew do that the other crew doesn’t. And if we understand the TTP: the tactics, the techniques, and the procedures that hackers deploy, we’re in a better position to defend ourselves.
The other thing I’m interested in is the IOCs, the indicators of compromise. We need to watch out. We need to check. We need to continuously be vigilant to find out if someone’s attacking the network. And if they’ve been successful or not. Think of it as a burglar alarm for your network and your systems. If you were going to install a burglar alarm, a detective control, what would you look for?
If you understand TTPs, you already have a head start. You’re looking for the tactics, techniques, and procedures that are commonly deployed. When you deploy anti-virus, a firewall, IDS, IPS and XDR, these detective controls work on IOCs.
TTPs are what the hacker does. IOCs are little tell-tale signs that someone’s trying to get in or has successfully got into your network.

Sean Hanna
Founder & Director
Sean Hanna founded Nemstar in 2009, leveraging 20+ years of cybersecurity expertise to deliver business-focused technical training. As EC Council’s Global Security Trainer of the Year, he has trained thousands globally, including at Microsoft, GCHQ, and the U.S. Navy. Sean led Microsoft Exchange 2000’s technical training launch and helps organizations strengthen their cybersecurity defenses.
If you are keen to progress your skills as an ethical hacker, check out our courses