This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Overview
Why does attacker infrastructure so often stay live until the moment it is used? Not because defenders cannot see it. Domains, certificates, scans, and access probes surface well before an attack launches. The gap is operational: early signals arrive fragmented across tools, with no shared thresholds and no ownership for deciding when to act.
This ebook introduces Operational Pre-Attack Playbooks, a practical, SOC-native model for turning early attacker signals, called Indicators of Pre-Attack (IoPAs), into enforceable action during the setup phase. It defines a four-stage workflow, analyst decision points, response runbooks, and KPIs such as Mean Time to Preempt (MTTP) that let teams disrupt adversary infrastructure before first contact.
The approach aligns with the Resource Development (TA0042) phase of MITRE ATT&CK and runs alongside detection and response rather than replacing them. Malanta provides the platform layer that enables these playbooks to run at scale inside existing SOC workflows and controls.
Key findings
- AI-assisted adversary operations compress infrastructure setup from weeks into minutes, making post-execution reaction an insufficient control model.
- The problem is not visibility. Early signals lack a defined operational path, shared thresholds, and clear ownership, so attacker infrastructure often remains live until actively used.
- IoPAs become actionable when they meet three criteria: they represent setup activity that has preceded real attacks, they align with known attacker tradecraft or reuse patterns, and they show relevance to the organization.
- Core IoPA signal families include brand and impersonation setup, staged social engineering infrastructure, and C2 and tooling staging.
- A four-stage SOC workflow, from ingest and normalize through validate, assess imminence, and decide action path, feeds three standardized runbooks: internal block and harden, external disruption, and campaign-level clustering.
- Pre-attack prevention requires new metrics, led by Mean Time to Preempt (MTTP), campaign-level disruption rate, and reduction in downstream phishing and credential abuse incidents.
What is inside
- Executive Summary
- The Operational Shift: From IOC Response to IoPA Prevention
- What Qualifies as a Pre-Attack Signal
- Core IoPA Signal Families
- SOC Pre-Attack Workflow (S0-S3)
- Response Runbooks
- Measuring Success
- 30-60-90 Day Adoption Plan
Frequently asked questions
What are Operational Pre-Attack Playbooks?
Operational Pre-Attack Playbooks are a practical, SOC-native model for turning early attacker signals into enforceable action during the setup phase. They define workflows, analyst decision points, response paths, and KPIs that let teams disrupt adversary infrastructure before first contact.
What is an IoPA?
An IoPA, Indicator of Pre-Attack, is a validated signal that adversary infrastructure is being prepared before use. It is not a lower-confidence IOC. It answers a different question at an earlier point in the attack timeline.
How is an IoPA different from an IOC?
An IOC documents malicious activity that already occurred. An IoPA identifies validated evidence of infrastructure preparation before execution. They describe different phases and support different actions.
What is MTTP?
MTTP means Mean Time to Preempt. It measures the interval between observing adversary preparation and taking defensive action against it.
Does pre-attack prevention replace detection and response?
No. The pre-attack workflow runs alongside detection and response as a dedicated SOC lane anchored to TA0042, Resource Development. It is limited to defensive actions such as internal control changes, blocking, and lawful external coordination, all fully auditable and governed.
How do teams adopt these playbooks?
Adoption follows a 30-60-90 day plan. Teams define IoPA signal families, ownership, and governance in the first 30 days, operationalize the S0-S3 workflow and begin tracking MTTP within 60 days, and automate low-risk actions with human oversight within 90 days.









