Skip to main content

Describing attacks with crime script analysis

0
Medium
Analysis
Published: 08/19/2026 (08/19/2026, 10:00:52 UTC)
Source: Cisco Talos

Description

This content describes crime script analysis (CSA), a narrative-driven technique to decompose cyber attacks into sequential steps using everyday language. It uses business email compromise (BEC) as a case study to illustrate how AI can automate preparatory steps, enabling attackers to scale attacks to previously unprofitable targets. The narrative approach helps defenders identify intervention points to disrupt attacks effectively. CSA complements existing models like MITRE ATT&CK by providing accessible descriptions for non-technical audiences and highlighting where AI may assist attackers and where defenses can be applied.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 09:33:53 UTC

Technical Analysis

Crime script analysis (CSA) is a technique that breaks down cyber attacks into a sequence of actions, decisions, and situational requirements, making attack narratives accessible to non-technical audiences. Using BEC as an example, the analysis shows that AI can automate time-consuming preparatory steps (such as target identification and social engineering message generation), allowing attackers to scale attacks from high-value few to low-value many. The CSA narrative identifies key intervention points, including seeding AI with fake honeypot organizations to disrupt reconnaissance, detecting malicious AI prompts, blocking delivery mechanisms via email service providers, and increasing victim awareness and procedural controls. CSA does not replace frameworks like MITRE ATT&CK but complements them by providing a human-readable narrative that aids understanding and defense strategy formulation.

Potential Impact

The impact described is the potential industrialization and scaling of business email compromise attacks through AI automation, increasing the volume of attacks against a broader range of targets, including smaller organizations previously less targeted. This scaling could increase financial losses and operational disruption. However, the analysis also identifies multiple intervention points where defenses can disrupt or detect the attack, potentially limiting impact if effectively implemented.

Defensive Guidance

No official patch or fix applies as this is an attack methodology analysis rather than a software vulnerability. Mitigation recommendations include deploying honeypot organizations to mislead AI reconnaissance, monitoring for suspicious AI-generated social engineering messages, enforcing rate-limiting and reputation-based blocking on email sending to disrupt delivery, and increasing user awareness and procedural controls such as verifying payment requests and implementing payment delays. These targeted mitigations align with the narrative's identified choke points and do not contradict any vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.55,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://blog.talosintelligence.com/describing-attacks-with-crime-script-analysis/","fetched":true,"fetchedAt":"2026-08-19T10:15:54.619Z","wordCount":1129}

Threat ID: 6a85825ac6e8be0332871b42

Added to database: 08/19/2026, 10:15:54 UTC

Last enriched: 09/11/2026, 09:33:53 UTC

Last updated: 10/02/2026, 13:50:45 UTC

Views: 82

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses