{"id":"https://openalex.org/W4385692141","doi":"https://doi.org/10.1145/3600160.3605013","title":"Tactics, Techniques and Procedures of Cybercrime: A Methodology and Tool for Cybercrime Investigation Process","display_name":"Tactics, Techniques and Procedures of Cybercrime: A Methodology and Tool for Cybercrime Investigation Process","publication_year":2023,"publication_date":"2023-08-09","ids":{"openalex":"https://openalex.org/W4385692141","doi":"https://doi.org/10.1145/3600160.3605013"},"language":"en","primary_location":{"id":"doi:10.1145/3600160.3605013","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3600160.3605013","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5067655368","display_name":"G. Sarkar","orcid":"https://orcid.org/0000-0002-2421-0083"},"institutions":[{"id":"https://openalex.org/I94234084","display_name":"Indian Institute of Technology Kanpur","ror":"https://ror.org/05pjsgx75","country_code":"IN","type":"education","lineage":["https://openalex.org/I94234084"]}],"countries":["IN"],"is_corresponding":true,"raw_author_name":"Gargi Sarkar","raw_affiliation_strings":["Department of Computer Science and Engineering, Indian Institute of Technology Kanpur, India"],"raw_orcid":"https://orcid.org/0000-0002-2421-0083","affiliations":[{"raw_affiliation_string":"Department of Computer Science and Engineering, Indian Institute of Technology Kanpur, India","institution_ids":["https://openalex.org/I94234084"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101793292","display_name":"Hardeep Singh","orcid":"https://orcid.org/0009-0003-0029-8775"},"institutions":[{"id":"https://openalex.org/I94234084","display_name":"Indian Institute of Technology Kanpur","ror":"https://ror.org/05pjsgx75","country_code":"IN","type":"education","lineage":["https://openalex.org/I94234084"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Hardeep Singh","raw_affiliation_strings":["C3I Hub, Indian Institute of Technology Kanpur, India"],"raw_orcid":"https://orcid.org/0009-0003-0029-8775","affiliations":[{"raw_affiliation_string":"C3I Hub, Indian Institute of Technology Kanpur, India","institution_ids":["https://openalex.org/I94234084"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087802345","display_name":"Subodh Kumar","orcid":"https://orcid.org/0009-0006-0108-2433"},"institutions":[{"id":"https://openalex.org/I4210162141","display_name":"Microsoft (India)","ror":"https://ror.org/04ww0w091","country_code":"IN","type":"company","lineage":["https://openalex.org/I1290206253","https://openalex.org/I4210162141"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Subodh Kumar","raw_affiliation_strings":["Microsoft India, India"],"raw_orcid":"https://orcid.org/0009-0006-0108-2433","affiliations":[{"raw_affiliation_string":"Microsoft India, India","institution_ids":["https://openalex.org/I4210162141"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5021517996","display_name":"Sandeep K. Shukla","orcid":"https://orcid.org/0000-0001-5525-7426"},"institutions":[{"id":"https://openalex.org/I94234084","display_name":"Indian Institute of Technology Kanpur","ror":"https://ror.org/05pjsgx75","country_code":"IN","type":"education","lineage":["https://openalex.org/I94234084"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Sandeep K. Shukla","raw_affiliation_strings":["Department of Computer Science and Engineering, Indian Institute of Technology Kanpur, India"],"raw_orcid":"https://orcid.org/0000-0001-5525-7426","affiliations":[{"raw_affiliation_string":"Department of Computer Science and Engineering, Indian Institute of Technology Kanpur, India","institution_ids":["https://openalex.org/I94234084"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5067655368"],"corresponding_institution_ids":["https://openalex.org/I94234084"],"apc_list":null,"apc_paid":null,"fwci":6.6759,"has_fulltext":false,"cited_by_count":15,"citation_normalized_percentile":{"value":0.96813786,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"10"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10574","display_name":"Crime Patterns and Interventions","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cybercrime","display_name":"Cybercrime","score":0.9842242002487183},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.621211051940918},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5798879265785217},{"id":"https://openalex.org/keywords/law-enforcement","display_name":"Law enforcement","score":0.5096123218536377},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.49622660875320435},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.46507856249809265},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.3423587381839752},{"id":"https://openalex.org/keywords/criminology","display_name":"Criminology","score":0.32596272230148315},{"id":"https://openalex.org/keywords/law","display_name":"Law","score":0.2492007613182068},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.20146381855010986},{"id":"https://openalex.org/keywords/political-science","display_name":"Political science","score":0.165567547082901},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.13643023371696472},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.11835956573486328}],"concepts":[{"id":"https://openalex.org/C2779390178","wikidata":"https://www.wikidata.org/wiki/Q29137","display_name":"Cybercrime","level":3,"score":0.9842242002487183},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.621211051940918},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5798879265785217},{"id":"https://openalex.org/C2780262971","wikidata":"https://www.wikidata.org/wiki/Q44554","display_name":"Law enforcement","level":2,"score":0.5096123218536377},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.49622660875320435},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.46507856249809265},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.3423587381839752},{"id":"https://openalex.org/C73484699","wikidata":"https://www.wikidata.org/wiki/Q161733","display_name":"Criminology","level":1,"score":0.32596272230148315},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.2492007613182068},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.20146381855010986},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.165567547082901},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.13643023371696472},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.11835956573486328},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3600160.3605013","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3600160.3605013","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 18th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.8100000023841858,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320307764","display_name":"Microsoft","ror":"https://ror.org/00d0nc645"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W159069299","https://openalex.org/W404074782","https://openalex.org/W562195940","https://openalex.org/W1585702935","https://openalex.org/W1598791898","https://openalex.org/W1985594089","https://openalex.org/W2023265233","https://openalex.org/W2071360859","https://openalex.org/W2073198389","https://openalex.org/W2095786751","https://openalex.org/W2159347668","https://openalex.org/W2329840676","https://openalex.org/W2508426536","https://openalex.org/W2591594469","https://openalex.org/W2621190648","https://openalex.org/W2888352404","https://openalex.org/W2940449415","https://openalex.org/W3009068656","https://openalex.org/W3096595385","https://openalex.org/W3124351849","https://openalex.org/W4213136755","https://openalex.org/W4214590541","https://openalex.org/W4223958541","https://openalex.org/W4321599946"],"related_works":["https://openalex.org/W2338899373","https://openalex.org/W4252285266","https://openalex.org/W199254545","https://openalex.org/W3025546445","https://openalex.org/W3031409616","https://openalex.org/W3164984769","https://openalex.org/W1983112135","https://openalex.org/W2049886938","https://openalex.org/W4200166010","https://openalex.org/W3012403896"],"abstract_inverted_index":{"Individuals,":[0],"organizations":[1],"and":[2,32,77,154,229,249],"nation-states":[3],"are":[4,81,87,161],"increasingly":[5],"falling":[6],"victim":[7],"to":[8,16,104,134,144,150,170,173,182,192,205,221,244],"cyberattacks.":[9],"A":[10],"lot":[11],"of":[12,21,56,69,120,137,202,208],"research":[13],"on":[14,60],"how":[15],"understand":[17],"the":[18,26,57,61,95,110,113,118,125,135,146,151,162,180],"modus":[19,177],"operandi":[20,178],"a":[22,65,106,175,184,193,200,206,215,223,241],"cyber":[23,34,42,92],"attacker":[24],"through":[25],"MITRE":[27],"ATT&CK":[28],"framework,":[29],"CAPEC":[30],"enumeration":[31],"various":[33,98],"kill":[35],"chain":[36],"frameworks":[37],"has":[38,64],"been":[39],"available":[40],"for":[41,45,179,218,226,232,253],"incident":[43,148,250],"responders":[44],"both":[46],"pre-attack":[47],"defensive":[48],"posture":[49],"preparation":[50],"as":[51,53,190,240],"well":[52],"post-attack":[54],"mapping":[55],"indicators.":[58],"Cybercrime,":[59],"other":[62],"hand,":[63],"very":[66],"different":[67],"set":[68,201],"motives,":[70],"majorly":[71],"financial,":[72],"but":[73],"also":[74],"impersonation,":[75],"harassment":[76],"hate":[78],"crimes,":[79],"which":[80,236],"targeted":[82,246],"mostly":[83],"towards":[84],"individuals":[85],"who":[86],"vulnerable.":[88],"Investigative":[89],"officers":[90,168],"in":[91,101,129],"cells":[93],"around":[94],"world":[96],"use":[97],"investigative":[99],"processes":[100,163],"their":[102],"attempt":[103],"solve":[105,183],"cybercrime":[107,131,147,166,195,227,254],"incident,":[108],"detect":[109],"criminal(s),":[111],"recover":[112],"lost":[114],"money,":[115],"shut":[116],"down":[117,124],"accounts":[119],"perpetrators,":[121],"or":[122,197],"bring":[123],"cyber-criminal":[126],"gangs":[127],"involved":[128],"reported":[130],"incidents.":[132],"However,":[133],"best":[136],"our":[138],"knowledge,":[139],"there":[140],"is":[141],"no":[142],"framework":[143,217],"map":[145,199],"narratives":[149],"tactics,":[152],"techniques":[153],"procedures":[155],"(TTPs)":[156],"used":[157,164,239],"by":[158,165],"cybercriminals,":[159],"nor":[160],"investigating":[167],"mapped":[169],"such":[171],"TTPs":[172],"create":[174],"systematic":[176],"investigators":[181],"cybercrime,":[185],"cluster":[186],"multiple":[187],"crime":[188],"incidents":[189],"attributable":[191],"specific":[194],"operator,":[196],"systematically":[198],"evidence":[203],"collected":[204],"pattern":[207],"TTPs.":[209],"In":[210],"this":[211],"paper,":[212],"we":[213],"present":[214],"TTP-based":[216],"classified":[219],"cybercrimes":[220],"formulate":[222],"comprehensive":[224],"strategy":[225],"interpretation":[228],"action":[230],"recommendations":[231],"law":[233],"enforcement":[234],"officers,":[235],"can":[237],"be":[238],"reference":[242],"point":[243],"establish":[245],"threat":[247],"models":[248],"response":[251],"methodologies":[252],"investigations.":[255]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":1}],"updated_date":"2026-05-05T08:41:31.759640","created_date":"2025-10-10T00:00:00"}
