Crime script analysis in cyber attacks is gaining traction as a practical way to demystify threat scenarios for both technical and non-technical audiences. In the context of business email compromise attacks, this technique offers a clear, step-by-step narrative of how incidents unfold and where defenders can intervene.
Understanding Crime Script Analysis in Cyber Attacks
Traditional models for describing cyber attacks, such as the Cyber Kill Chain or the MITRE ATT&CK framework, provide useful technical detail but often remain inaccessible to non-specialists. The Cyber Kill Chain breaks attacks into seven linear steps, but this rigid structure does not account for the complexity or variability of real-world threats. MITRE ATT&CK, with its branching attack flows and comprehensive technical mapping, offers much-needed detail but can overwhelm those without deep cybersecurity knowledge.
Crime script analysis (CSA) addresses this gap by adopting a narrative-driven approach. Originally developed in criminology during the mid-1990s, CSA decomposes an attack into a sequence of actions, decisions and situational requirements. It allows security professionals to tell the story of an attack in plain language, identifying not just the steps taken by attackers but also the moments where defenders can most effectively intervene.
- CSA translates complex technical scenarios into accessible narratives
- It highlights choke points where specific defences or interventions can disrupt the attacker’s workflow
- This approach supports communication with non-technical stakeholders, enabling informed decision-making
Business Email Compromise: A Crime Script Analysis Case Study
Business email compromise (BEC) is a persistent and costly form of cyber crime. In a typical scenario, an attacker sends a fraudulent message to someone with financial authority, impersonating a trusted superior and urgently requesting a payment. If successful, the scammer quickly launders the money, obscuring its origin before the fraud is discovered.
Historically, BEC attacks required significant manual research. Attackers had to identify suitable targets, understand organisational hierarchies, and craft convincing lures. This labour-intensive process meant BEC was usually directed at larger organisations where a bigger payoff justified the effort.
A recent real-world example highlighted the evolving threat landscape. A small community sports club was targeted in a BEC attack. The requested sum was modest, designed to fit the scale of the organisation and to arouse minimal suspicion. Although the attempt failed—the treasurer recognised inconsistencies in tone and raised the alarm—it demonstrated how attackers are now targeting smaller organisations once considered unprofitable.
This shift is driven by the automation of preparatory work using artificial intelligence. AI can rapidly scan public records, social media and company websites to build profiles of potential victims, their roles and internal relationships. It can even assist in drafting convincing email lures at scale, lowering the effort required per target and increasing the attack’s reach.
Deconstructing a BEC Attack with Crime Script Analysis
Using crime script analysis, the BEC attack can be broken down into the following key steps:
- Reconnaissance: Attacker identifies suitable organisations and staff with financial authority
- Preparation: AI tools gather information about internal hierarchies, communication styles and recent events
- Lure Creation: Attacker crafts an email impersonating a trusted figure, often with AI assistance
- Delivery: Fraudulent email is sent to the target
- Exploitation: If the target is deceived, payment instructions are followed
- Laundering: Illicit funds are rapidly moved through accounts to obscure their origin
By mapping each stage, defenders can pinpoint where interventions are likely to be most effective. For example, robust verification processes for payment requests, staff awareness training and technical controls to detect spoofed emails can all be mapped to specific steps in the script. This approach not only clarifies the attack process but also helps identify where resources should be focused.
Why Crime Script Analysis Matters for Cyber Defence
Crime script analysis is valuable because it puts actionable intelligence into the hands of decision-makers, not just technical staff. By translating technical threats into clear, accessible stories, it empowers non-specialists to recognise risks, support security investments and respond effectively to incidents.
As threat actors increasingly use automation and AI to industrialise attacks like BEC, defenders need equally agile methods to keep up. CSA helps bridge the gap between technical detail and organisational action, ensuring that even small organisations can understand and defend against evolving threats.
What Organisations Should Do Now
- Review your incident response plans to include crime script analysis alongside technical frameworks
- Use CSA to communicate risks and intervention points to non-technical stakeholders
- Monitor the role of AI in scaling previously low-yield attack types like BEC
Integrating crime script analysis into your cyber defence strategy can improve preparedness and help organisations of any size respond to the changing threat landscape.
Originally reported by blog.talosintelligence.com.






