skip to content

In the Pyramid of Pain, what does a rung's height actually measure?

level: juniorimportance: must knowfreq 68%

answer

  1. cost to them, not harm to you
  2. six rungs, one axis
  3. trivial through tough: the operator's pain
  4. a recompile versus retraining humans
  5. no severity field anywhere on it

basics

~20 s

Height measures the adversary's replacement cost: how much money and operator time it costs them to swap that thing once it stops working. It says nothing about how dangerous the thing is or how confident you are.

solid answer

~40 s

The Pyramid of Pain stacks six kinds of thing an adversary leaves behind - hash values, IP addresses, domain names, network and host artefacts, tools, and TTPs - and the vertical axis carries exactly one quantity: what it costs the crew to replace that thing after it stops working for them. Bianco's own rung labels run trivial, easy, simple, annoying, challenging, tough, and they describe the operator's pain, not the victim's damage. A hash changes with a recompile; a fresh address is a card payment; retiring a tool means writing or buying replacement capability and re-learning it; changing TTPs means the humans change how they work. Nothing on the pyramid encodes severity, likelihood, or certainty that a value is malicious - those judgements come from somewhere else entirely.

go deeper

for a junior

Be ready to state the axis in one sentence - the adversary's cost to replace - and to name the six rungs bottom to top without reaching for severity language.

for a middle

An interviewer expects you to price two adjacent rungs concretely: what a crew actually spends, in money and hours, to get a new address versus new capability.

for a senior

Show that you re-price the rungs for the crew being discussed rather than reciting the order, and can name one case where the ordering does not hold.

for a principal

Own the model's limit: it is a rhetorical device for arguing about where effort pays, has no data behind any rung, and should never be quoted as a measured cost curve.

## The model in one sentence The Pyramid of Pain is a diagram David Bianco published in 2013. It stacks six kinds of thing an adversary leaves behind and orders them by a single quantity: **how much it costs that adversary to replace the thing once it has stopped working for them**. Bottom to top, with Bianco's own difficulty labels: ``` TTPs tough Tools challenging Network / host artefacts annoying Domain names simple IP addresses easy Hash values trivial ``` The labels are the giveaway. *Trivial*, *easy*, *annoying*, *tough* are all descriptions of one person's inconvenience, and that person is the operator on the other side. ## Pricing the six rungs - **Hash values.** Any change to a file changes its hash - a recompile, a different build timestamp, one padded byte. Crews often get a new hash by accident. Cost: seconds. - **IP addresses.** Rent another host somewhere else. Cost: a card payment and a few minutes of provisioning. - **Domain names.** Register a name, point it at hosting, sometimes let it sit so it is not obviously new, then update whatever build refers to it. Cost: tens of dollars and a little patience - which is why it sits one rung above an address rather than several. - **Network and host artefacts.** The names and strings the tooling emits: a mutex it creates so it does not run twice, a named pipe, the service or scheduled-task name it installs under, an install path, a URI pattern, a user-agent string. Cost: an edit to a literal and a rebuild. - **Tools.** The capability itself. Replacing it means writing something new, buying something, or falling back on something the crew knows less well - then re-testing it against a target-like machine. Cost: weeks of development, or money plus a drop in effectiveness. - **TTPs.** How the crew works: that they get code running through a trusted system binary, that they harvest credentials out of memory, that they move data out over a channel the target already allows. Changing this means humans change their habits. Cost: retraining, sometimes rehiring, and a stretch of being worse at the job. The gradient across those six is roughly seconds, minutes, hours, hours, weeks, months. That is the whole claim. ## What the axis is not This is where the question is usually failed, and the wrong answers are all plausible: - **Not severity.** The pyramid has no field for impact. A hash belonging to a wiper and a hash belonging to adware sit on the same rung, because the rung is about the crew's cost of swapping it, not what the code does. - **Not confidence.** How sure you are that a value belongs to an adversary is a judgement about where the value came from. The pyramid never asks. - **Not longevity.** How long a value stays useful is a consequence of the crew's habits and how widely the value has spread, not the axis the model orders on. - **Not effort on your side.** Two rungs can cost you the same to act on and cost the adversary wildly different amounts. The asymmetry is the point. ## The one empirical claim Stated plainly, the model asserts: *taking away something higher up costs the adversary more than taking away something lower down, so effort spent higher up buys more.* That is a claim about the economics of running an intrusion campaign, and it is worth stating out loud in an interview because it is falsifiable. A crew that can regenerate a build per target has already paid the bottom rung down to zero. A crew whose entire delivery rests on one stolen signing key holds a bottom-rung-looking value it cannot replace at any price it likes. ## Where the model stops The pyramid has no data behind it. It is an experienced practitioner's generalisation, offered as a way to argue about where effort pays, and it holds for a median crew. Replacement cost is a property of a specific adversary's supply chain - what they can automate, what they must buy, what they had to steal - and not a property of the value's data type. The mature use of the model is to take its ordering as a *default* and then re-price the rungs against the crew actually in front of you. In an interview, the answer that scores is short: the axis is the adversary's replacement cost; the labels describe their pain; nothing on the diagram is a severity scale.

  • Why is a domain name placed above an IP address if both are just network values?
    Because replacing them costs differently. A fresh address is a card payment and a few minutes of provisioning. A domain has to be registered, pointed at hosting, sometimes left to sit so it is not obviously brand new, and then bedded into whatever build refers to it. Neither is expensive in absolute terms - the model only claims the second is dearer than the first, and for most crews it is.
  • Does the pyramid say that acting on a hash is worthless?
    No. It says the hash is cheap to replace, not that removing it achieves nothing. It still stops re-use of a build the crew has not bothered to regenerate, and forces a rebuild if they have. The claim is about the price imposed on them, and at the bottom rung that price rounds to minutes.
  • Is the ordering measured, or is it an opinion?
    It is an experienced generalisation published in 2013, not a measurement. There is no cost data behind any rung. That is precisely why you are expected to treat the order as a default and re-price it for the specific crew you are discussing, rather than quoting it as if it were a curve someone fitted.

It prices a burglar's inconvenience, not the value of what was taken: changing gloves is trivial, changing the way you pick locks is not.

saying these in an interview costs you the question

  • Says higher rungs mean more dangerous or higher severity
  • Reads the height as confidence that a value is malicious
  • Thinks the pyramid ranks how much damage an intrusion does
  • Cannot say what the vertical axis measures at all
  • Assumes the ordering holds identically for every crew

context