Describing attacks with crime script analysis
This content describes crime script analysis (CSA), a narrative-driven technique to decompose cyber attacks into sequential steps using everyday language. It uses business email compromise (BEC) as a case study to illustrate how AI can automate preparatory steps, enabling attackers to scale attacks to previously unprofitable targets. The narrative approach helps defenders identify intervention points to disrupt attacks effectively. CSA complements existing models like MITRE ATT&CK by providing accessible descriptions for non-technical audiences and highlighting where AI may assist attackers and where defenses can be applied.
AI Analysis
Technical Summary
Crime script analysis (CSA) is a technique that breaks down cyber attacks into a sequence of actions, decisions, and situational requirements, making attack narratives accessible to non-technical audiences. Using BEC as an example, the analysis shows that AI can automate time-consuming preparatory steps (such as target identification and social engineering message generation), allowing attackers to scale attacks from high-value few to low-value many. The CSA narrative identifies key intervention points, including seeding AI with fake honeypot organizations to disrupt reconnaissance, detecting malicious AI prompts, blocking delivery mechanisms via email service providers, and increasing victim awareness and procedural controls. CSA does not replace frameworks like MITRE ATT&CK but complements them by providing a human-readable narrative that aids understanding and defense strategy formulation.
Potential Impact
The impact described is the potential industrialization and scaling of business email compromise attacks through AI automation, increasing the volume of attacks against a broader range of targets, including smaller organizations previously less targeted. This scaling could increase financial losses and operational disruption. However, the analysis also identifies multiple intervention points where defenses can disrupt or detect the attack, potentially limiting impact if effectively implemented.
Mitigation Recommendations
No official patch or fix applies as this is an attack methodology analysis rather than a software vulnerability. Mitigation recommendations include deploying honeypot organizations to mislead AI reconnaissance, monitoring for suspicious AI-generated social engineering messages, enforcing rate-limiting and reputation-based blocking on email sending to disrupt delivery, and increasing user awareness and procedural controls such as verifying payment requests and implementing payment delays. These targeted mitigations align with the narrative's identified choke points and do not contradict any vendor advisory.
Describing attacks with crime script analysis
Description
This content describes crime script analysis (CSA), a narrative-driven technique to decompose cyber attacks into sequential steps using everyday language. It uses business email compromise (BEC) as a case study to illustrate how AI can automate preparatory steps, enabling attackers to scale attacks to previously unprofitable targets. The narrative approach helps defenders identify intervention points to disrupt attacks effectively. CSA complements existing models like MITRE ATT&CK by providing accessible descriptions for non-technical audiences and highlighting where AI may assist attackers and where defenses can be applied.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Crime script analysis (CSA) is a technique that breaks down cyber attacks into a sequence of actions, decisions, and situational requirements, making attack narratives accessible to non-technical audiences. Using BEC as an example, the analysis shows that AI can automate time-consuming preparatory steps (such as target identification and social engineering message generation), allowing attackers to scale attacks from high-value few to low-value many. The CSA narrative identifies key intervention points, including seeding AI with fake honeypot organizations to disrupt reconnaissance, detecting malicious AI prompts, blocking delivery mechanisms via email service providers, and increasing victim awareness and procedural controls. CSA does not replace frameworks like MITRE ATT&CK but complements them by providing a human-readable narrative that aids understanding and defense strategy formulation.
Potential Impact
The impact described is the potential industrialization and scaling of business email compromise attacks through AI automation, increasing the volume of attacks against a broader range of targets, including smaller organizations previously less targeted. This scaling could increase financial losses and operational disruption. However, the analysis also identifies multiple intervention points where defenses can disrupt or detect the attack, potentially limiting impact if effectively implemented.
Defensive Guidance
No official patch or fix applies as this is an attack methodology analysis rather than a software vulnerability. Mitigation recommendations include deploying honeypot organizations to mislead AI reconnaissance, monitoring for suspicious AI-generated social engineering messages, enforcing rate-limiting and reputation-based blocking on email sending to disrupt delivery, and increasing user awareness and procedural controls such as verifying payment requests and implementing payment delays. These targeted mitigations align with the narrative's identified choke points and do not contradict any vendor advisory.
Technical Details
- Classification
- {"confidence":0.55,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/","fetched":true,"fetchedAt":"2026-08-19T10:15:54.619Z","wordCount":1129}
Threat ID: 6a85825ac6e8be0332871b42
Added to database: 08/19/2026, 10:15:54 UTC
Last enriched: 09/11/2026, 09:33:53 UTC
Last updated: 10/02/2026, 13:50:45 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.