Tactics, Techniques, and Procedures (TTPs) describe how an adversary operates. The MITRE ATT&CK framework standardizes these descriptions.
Instead of hunting for an ever-changing file hash (Tactical), hunting for the *behavior* of credential dumping (Operational) is much more robust against adversary evasion.