CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Describing attacks with crime script analysis

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4711

As cited

Copy frozen at (site build).

threat intel

Describing attacks with crime script analysis

Crime script analysis (CSA) is a narrative-driven technique that breaks down cyberattacks into discrete, human-readable steps for broader audiences, complementing technical frameworks like MITRE ATT&CK. The article illustrates CSA applied to business email compromise (BEC), showing how AI is automating reconnaissance steps traditionally requiring manual research, enabling attackers to target lower-value victims at scale. Defense intervention points include seeding fake honeypot organizations, monitoring LLM usage patterns, rate-limiting anomalous email behavior, and improving victim awareness.

Why it matters: Security teams and business leaders need to understand where BEC attacks can be disrupted before automation scales the threat; CSA helps non-technical stakeholders grasp both the attack narrative and specific defensive actions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Describing attacks with crime script analysis

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Describing attacks with crime script analysis

Crime script analysis is a narrative-driven methodology that describes cyberattacks in accessible language for non-technical audiences, complementing technical frameworks like MITRE ATT&CK and Attack Flow diagrams. Applied to business email compromise (BEC), the approach decomposes attacks into discrete steps, revealing how artificial intelligence can automate reconnaissance and social engineering to scale attacks against previously unprofitable targets. Defenders can identify critical intervention points where defenses can disrupt the attack flow, from honeypot decoys and email provider blocks to victim awareness and payment verification processes.

Why it matters: Security leaders and defenders responsible for BEC prevention need this model to communicate threats to executives and non-technical stakeholders, and to recognize how AI-driven attackers are expanding targeting from high-value firms to commodity targets like small organizations.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary