Pre-Attack Prevention
Attackers register domains, build capabilities, and stage infrastructure before they touch your environment. Pre-Attack Intelligence turns that preparation into evidence your team can act on first.
Pre-Attack Intelligence is the discipline of observing, validating, and acting on adversary preparation before execution.
It focuses on MITRE ATT&CK TA0042, Resource Development, where adversaries acquire domains, provision servers, obtain certificates, develop capabilities, and prepare delivery infrastructure. Pre-Attack Intelligence provides the intelligence foundation for Pre-Attack Prevention, the operational category focused on stopping attacks during setup and measuring performance through MTTP, Mean Time to Preempt.
The attack timeline
Not at initial access. Every campaign moves through preparation, execution, and response. Security investment concentrates on the last two. The defender's earliest opportunity exists in the first.
Adversaries acquire domains, develop capabilities, and stage infrastructure. MITRE ATT&CK catalogs this phase as TA0042, Resource Development. It unfolds outside the victim environment, across observable systems such as domain registries, certificate logs, DNS, and hosting infrastructure.
Phishing pages go live, exploits fire, payloads move, and command channels open. Average eCrime breakout time fell to 29 minutes in 2025, according to the CrowdStrike 2026 Global Threat Report published February 24, 2026.
Defenders investigate, contain, recover, and document Indicators of Compromise. Organizations took an average of 181 days to identify a breach, according to IBM's 2025 Cost of a Data Breach Report published July 30, 2025.
The overlooked phase
Adversaries cannot attack with nothing. They need infrastructure: domains that impersonate targets, servers that host payloads, certificates that establish trust, accounts that support access, and command channels that maintain control.
This work is mandatory. It also leaves evidence.
Anthropic analyzed 832 observed threat actors and found that 69 percent used T1587, Develop Capabilities, a technique within Resource Development. The report also found that three of the five highest-risk techniques were Pre-Attack Resource Development techniques. Both findings appear in Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator, published June 3, 2026.
Interisle Consulting Group estimated that bad actors purchased 16.8 million gTLD domains in 2025, approximately 20 percent of registrations, in its June 2026 study. In separate research published in October 2025, Interisle reported malicious domain registrations increased 149 percent year over year.
Adversaries operate a preparation supply chain. Registrations, certificates, hosting decisions, and capability development make that supply chain observable.
The time advantage
CrowdStrike measured average eCrime breakout time at 29 minutes during 2025 in its 2026 Global Threat Report, published February 24, 2026. Mandiant reported a mean time to exploit of negative seven days in M-Trends 2026, published in March 2026. On average, exploitation preceded patch availability by one week.
Detection and response programs are being asked to win races that may already be underway when the first alert arrives.
Preparation runs on a different clock. Infrastructure acquisition and capability development can begin days, weeks, or months before execution. Observing this work creates lead time that detection after execution cannot recover.
That changes the metric. Pre-Attack Prevention measures MTTP, Mean Time to Preempt: the interval between observing adversary preparation and taking action against it. Shorter MTTP means the defender claimed more of the setup window.
The evidence
Average eCrime breakout time during 2025.
Source: CrowdStrike 2026 Global Threat Report, February 24, 2026.
Increase in AI-enabled adversary operations year over year.
Source: CrowdStrike 2026 Global Threat Report, February 24, 2026.
Estimated gTLD domains purchased by bad actors during 2025, representing approximately 20 percent of registrations.
Source: Interisle Consulting Group, June 2026.
Three of the five highest-risk techniques were Pre-Attack Resource Development techniques. In the same dataset, 69 percent of 832 observed actors used T1587, Develop Capabilities.
Source: Anthropic, Mapping AI-enabled cyber threats, June 3, 2026.
Mean time to exploit relative to patch availability.
Source: Mandiant M-Trends 2026, March 2026.
Average time required to identify a breach.
Source: IBM Cost of a Data Breach Report 2025, July 30, 2025.
The timing gap
Those figures come from the SANS 2026 Cyber Threat Intelligence Survey, published May 19, 2026. The gap is not simply about data quality. It is about when the intelligence becomes available.
Traditional CTI largely depends on Indicators of Compromise. These indicators document malicious activity already observed in a victim environment. They help teams investigate, contain, and find related activity. Yet they begin after execution.
Censys measured a median lifespan of 5.0 days for observed Cobalt Strike services in its 2025 State of the Internet Report. An indicator may describe infrastructure that has already disappeared by the time it reaches an operational control.
Reactive CTI asks what happened and where else to look. Pre-Attack Intelligence asks what is being prepared and what defenders can do before it is used.
From observation to action
Observe domain registration, certificate issuance, DNS, hosting, and infrastructure configuration during Resource Development.
Connect artifacts through shared patterns and common identity attributes to determine whether separate assets belong to the same preparation activity.
Test relationships against available evidence. Validation distinguishes adversary setup from coincidence, novelty, or routine infrastructure activity.
Deliver the validated result as an IoPA, Indicator of Pre-Attack, with enough context to support blocking, monitoring, investigation, or disruption.
Read the Indicators of Pre-Attack referenceOwnership
Can the organization observe infrastructure being staged before it reaches the victim environment?
Which team validates the evidence and initiates blocking, monitoring, investigation, or takedown?
Does leadership track MTTP alongside existing detection and response measures?
TA0042 in practice
Lookalike, homoglyph, and combination domains registered against an organization, executive, supplier, or industry.
Hosting infrastructure acquired and configured to support phishing, payload delivery, redirects, or command and control.
TLS certificates obtained for staged domains before those domains become active in a campaign.
Name servers, records, and resolution patterns connecting staged domains to delivery infrastructure.
Malware, phishing kits, tooling, or supporting resources developed or acquired before deployment.
Market direction
Gartner projects that preemptive cybersecurity solutions will account for 50 percent of IT security spending by 2030, up from less than 5 percent in 2024. Gartner published the projection September 19, 2025.
Spending projections do not prove every preemptive approach will work. They indicate a change in the question security leaders are asking. Detection and response remain necessary. Yet organizations increasingly want controls that can act before impact.
A useful validation brief explains what was observed, why it indicates preparation, how strong the evidence is, and what action the evidence supports. That is where a signal becomes operational intelligence.
The industry has spent two decades getting faster at responding to attacks. The next advantage comes from asking an earlier question: what can you see before execution begins?
The setup phase is observable. TA0042 gives it structure. IoPAs turn its signals into evidence. MTTP measures whether defenders act while prevention remains possible.
Pre-Attack Intelligence moves security from describing attacks to owning the window before them.
What is Pre-Attack Intelligence?
Pre-Attack Intelligence is the discipline of observing, validating, and acting on adversary preparation before execution. It focuses on infrastructure and capabilities developed during MITRE ATT&CK TA0042, Resource Development.
What is Pre-Attack Prevention?
Pre-Attack Prevention is the operational category built on Pre-Attack Intelligence. It uses validated evidence to block, disrupt, or neutralize adversary infrastructure during preparation.
How is Pre-Attack Intelligence different from traditional CTI?
Traditional CTI largely describes known malicious activity through Indicators of Compromise. Pre-Attack Intelligence examines present preparation and produces IoPAs before that infrastructure is used.
What is an IoPA?
An IoPA, Indicator of Pre-Attack, is a validated signal that adversary infrastructure is being prepared before use. It answers a different question at an earlier point in the attack timeline.
What is MTTP?
MTTP means Mean Time to Preempt. It measures the interval between observing adversary preparation and taking defensive action against it.
How does Pre-Attack Intelligence relate to MITRE ATT&CK?
It anchors to TA0042, Resource Development. This tactic catalogs how adversaries acquire infrastructure, develop capabilities, establish accounts, and prepare other resources before attacking a target.
Framework
The authoritative framework for adversary infrastructure acquisition and capability development before execution.
Platform
See how Pre-Attack Intelligence becomes an operational Pre-Attack Prevention workflow.
E-book
Why defenders need to extend visibility earlier across the attack timeline.
Blog
The strategic advantage of acting during preparation instead of racing execution.
Blog
A practical examination of accountability before an attack reaches the victim environment.
Blog
What mature security programs can add between raw data and operational decisions.
Blog
Why attacker preparation creates a gap between what organizations monitor and what adversaries build.
Guide
Practical guidance for assigning ownership, integrating earlier intelligence, and measuring MTTP.

