← Back to News

Cyber Has ATT&CK. Physical Threats Had Nothing. So We Built a Common Language for How Armed Groups, Criminals and Activists Operate

20 September 2026

The Risk

If a ransomware group is targeting your sector, your security team can look up exactly how it operates — initial access, lateral movement, exfiltration — in a shared framework that every analyst, vendor and regulator recognises. The same team, asked how a particular armed group, criminal organisation or activist movement tends to act on the ground, has to fall back on a paragraph of prose in someone's briefing note.

That gap matters most to the people who have to plan around it: corporate security teams with staff overseas, close protection teams moving principals through unfamiliar cities, and duty-of-care leads deciding whether a site needs a different posture this month. "Elevated risk" doesn't tell an advance team whether to worry about kidnapping, vehicle attacks, drone surveillance or a blockade of the only road to the airport. Those are different problems with different mitigations, and every one of them is a technique that a specific actor either uses or doesn't.

The Structure

Fenestra MODUS, our physical TTP framework, version 0.1, is our first attempt to close that gap. The name stands for Model Of Deployment, Use-of-force & Signalling, and nods to the modus operandi it describes. It borrows the idea that made cyber threat intelligence comparable across teams (it is our own framework, independent of MITRE's) — separate what an actor is trying to achieve (tactics) from how it does it (techniques) — and applies it to physical and kinetic behaviour.

10 tactics, 86 techniques (78 techniques plus 8 sub-techniques), each with a permanent ID:

Fenestra MODUS, the physical TTP framework v0.1: ten tactics (PA0001 Reconnaissance & Targeting, PA0002 Resource Development, PA0003 Infiltration & Access, PA0004 Movement & Logistics, PA0005 Concealment & Evasion, PA0006 Inflict Casualties, PA0007 Coerce & Control, PA0008 Destroy & Disrupt, PA0009 Seize & Hold, PA0010 Influence & Signalling) and their 86 numbered techniques and sub-techniques

The full framework. Click the image to enlarge. PA#### identifies a tactic, P#### a technique and P####.### a sub-technique.

A few design choices are worth explaining, because they're what make it usable rather than merely tidy:

  • One tactic per technique. Every technique sits under the single objective it primarily serves, so a count of "what this group does" adds up cleanly and can't be inflated by one behaviour being filed in three places.
  • Never scoped to an actor type. A technique isn't "a terrorist technique" or "an activist technique". Kidnapping is kidnapping whether a cartel, an insurgent group or a criminal gang carries it out, which is what lets you compare very different actors on the same scale.
  • Permanent IDs. Once issued, an ID is never renumbered or reused, so reporting, alerts and analysts' notes stay valid as the framework grows.
  • Grown from evidence, not just assumption. The first draft was seeded from established analyst knowledge and the vocabulary our platform already used. Twelve further techniques — protest and demonstration, strike action, boycott, arrest and detention, state repression, armed robbery, human trafficking and others — were added because reading real reporting showed behaviour the first draft couldn't classify. The process is repeatable: we mine text that matches no technique, review what recurs, and add it, so gaps show up in the data before they show up in a client's incident.

In Practice

On each threat actor's profile, techniques are grouped under their tactic, so a security lead can open "Inflict Casualties" or "Coerce & Control", see which techniques that actor is associated with, and click through to the reporting behind each one.

For a close protection team, that changes the question from "is this region dangerous?" to "what does the group active here actually do, and which of those techniques apply to my principal's movements?" An actor that leans on roadside devices and ambushes calls for route planning; one that leans on kidnapping and threat calls for a different posture altogether; one whose signature is protest and obstruction calls for a third.

What v0.1 Is

This is version 0.1, a draft we expect to grow. We'll add techniques as the data shows behaviour it can't yet describe, and revise names and groupings after review.

The Fix

  • Describe physical threat the way you describe cyber threat. Techniques, not adjectives. "Kidnap and abduction, sustained, in this region" is something a team can plan against; "high risk" is not.
  • Compare actors on one scale. Put a cartel, an insurgent group and an activist campaign side by side on the same set of techniques to see where their behaviour overlaps and where the real differences are.
  • Keep the evidence one click away. A technique label you can't trace back to reporting is an assertion. Insist on the source text behind it.
  • Expect the framework to change. A physical-threat taxonomy that never changes is one that has stopped listening to the data.

This is what Fenestra TI's threat actor intelligence is built to provide, and it sits alongside our Itinerary Threat Monitoring, which checks every leg of a route against live data before anyone travels.

If your organisation has people, sites or principals in places where physical threat is part of the picture, get in touch to see how the framework applies to the actors that matter to you.

⚙