Security1 distinct publisher3 min readUpdated
Cisco Talos revives a 1990s criminology method to describe intrusions as narratives, then uses a business email compromise to show which steps AI makes cheap and where defenders can push back.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Cisco Talos has made the case for describing intrusions as crime scripts, a narrative technique developed in the mid-1990s as a criminology tool, used alongside or instead of tactics, techniques and procedures [1] [7]. The argument is not about presentation. Writing an attacker's workflow out as a sequence of actions, decisions and situational requirements is what exposes which steps artificial intelligence lets an attacker industrialize, and therefore which defensive interventions actually change the attacker's arithmetic [2] [3].
Talos positions the technique against the existing models rather than over them. Lockheed Martin's Cyber Kill Chain, one of the earliest attempts to describe the steps in an attack, has a seven-step linear sequence that is too rigid for many real intrusions [4]. The Attack Flow model of MITRE ATT&CK fixes the rigidity by chaining TTPs with branches and loops, producing comprehensive graphs that Talos concedes can be daunting to a non-technical audience [5]. With threats evolving and budgets shrinking, Talos argues defenders need ways to communicate threats to a wider audience [6]. Its own framing: TTPs are the building blocks, Attack Flow is the structural engineering blueprint, and crime script analysis is the architect's artistic impression of the finished building [8].
The case study is business email compromise: someone with financial authority receives a message purporting to come from a superior in the same organization, asking for an urgent payment, and if the victim is fooled the money is released and laundered quickly to disguise its origin before the scam surfaces [9]. The Talos author writes that in April he covered such an attack on a small community sports club of which he is a member [10]. The requested sum was not large, so the stated reason was plausible; what failed was the tone of the email, which raised the treasurer's suspicions and exposed the attempted fraud [11].
That small scale is the whole point. The research that BEC requires, identifying the target victim, the person to spoof and the nature of the lure, has historically limited scalability, because doing it by hand takes time and has meant the fraud is typically aimed at larger businesses [12]. Talos says AI automates that preparative work [13]. In its script, steps 1 to 4 are the manual, time-consuming part, and automating them shifts execution from higher-value fraud against a few targets to lower-value fraud against many [14]. Step 5, the personalization, can also be generated: urgent payment requests relevant to the target organization that may look credible to the recipient [15]. If analyst time was the binding constraint on target selection, removing it lowers the minimum victim size that pays [18].
The intervention argument is where the published text available to us runs out. It begins to say steps 1 to 4 can be disrupted by seeding AI with fake data, and breaks off mid-sentence [16]. The excerpt also refers to steps 1 through 5 without reproducing the step list itself [17].
Watch for the full script and the seeding detail, because that is the operational content. Note also that the control which saved the sports club was a human reading tone [11], the exact attribute step 5 automation is aimed at [19].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Crime script analysis is a narrative-driven technique that can be used alongside, or as an alternative to, tactics, techniques and procedures, creating human-readable stories that describe attacks in a way non-technical audiences can understand.
Deconstructing an attack into discrete steps allows defenders to pinpoint intervention points where defenses can be deployed, or where strategic disruption can break the script and thwart the threat actor's operation.
Lockheed Martin's Cyber Kill Chain was one of the earliest models to describe the steps required to conduct a cyber attack, but its seven-step linear sequence is too rigid to apply to many attacks.
The Attack Flow model of the MITRE ATT&CK framework allows TTPs to be chained together, including branches and loops, producing comprehensive graphs that can be daunting to a non-technical audience.
Crime script analysis was originally developed in the mid-1990s as a criminology tool to understand how crimes are committed, and decomposes an attack into a sequence of actions, decisions and situational requirements, helping identify choke points where the crime can be disrupted.
Talos's analogy: MITRE ATT&CK TTPs are the building blocks of an attack, Attack Flow diagrams are the structural engineering blueprints showing how the blocks fit together, and crime script analysis is the architect's artistic impression of the finished building.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor essay, one anecdote, no data
All content comes from one self-published vendor blog post. The verifiable parts are descriptive and definitional (what CSA is, how it relates to the Cyber Kill Chain and Attack Flow, how BEC works, the proposed intervention points). The load-bearing forward claims — AI automating reconnaissance, credible AI-generated lures, and the resulting shift to low-value fraud at scale — carry no telemetry, case data or demonstration. The supplied text is also incomplete: the enumerated crime script it discusses is absent and the conclusion is cut off mid-word.
No adoption signal supplied
The supplied material contains no release, deployment, benchmark, pricing, licensing, usage disclosure or incident-volume evidence. Crime script analysis is presented as a technique to consider and the canary-organization idea as a proposal; nothing indicates any team, product or provider has adopted either. Adoption cannot be scored without inventing facts.
Mildly overstated: escalation asserted, framing hedged
The post is unusually restrained in places — it explicitly says CSA does not replace ATT&CK and hedges with 'may scale' and 'may appear credible' — which limits the gap. The overstatement is that a methodology essay's headline conclusion is an economic claim about attacker behaviour ('previously unprofitable victims' now in reach) supported only by one small-club anecdote and a missing step list, with the proposed countermeasure offered without any effectiveness evidence.
Vendor research blog promoting its own analytic frame
The single source is the research blog of a commercial security vendor, publishing a method it advocates and cross-referencing its own earlier post on the same incident. The recommended interventions land on email service providers and AI providers — adjacent markets to the publisher's own — and the framing of evolving threats plus shrinking budgets is standard demand-side positioning. Mitigating factors kept the score mid-range: the supplied text names no product, price or proprietary tool and credits third-party frameworks (ATT&CK, Attack Flow) rather than displacing them.
Confident on framing, weak on consequences
Confidence is moderate. What the post says, and how it positions CSA relative to the Cyber Kill Chain and Attack Flow, is unambiguous and directly quotable. Confidence in the story's substantive consequence — that AI is moving BEC downmarket — is low: one publisher, one anecdote, no measurement, no adoption signal, and a body that omits the crime script and ends mid-sentence.
security
Talos finds a commodity crew running agentic AI, and a target list of 170,000 URLs1 distinct publisher
invest
L3Harris shows what forfeiture can reach, and what it cannot1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
security
Akira advisory update: $244m taken, one SonicWall CVE, three controls to audit now1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026