Every criminal endeavor has a con, a process, a workflow, or a «scheme» associated. For these schemes to be successful, they must have a certain, predictable outcome for the criminal. By examining cybercriminal adversary behavior, targets, and origins, we can build logical stories or use cases for what the adversary might be trying to accomplish — their desired outcomes. Once we understand what adversaries expect to see, receive, and monetize (or operationalize), we can work to de-incentivize the scheme, remove or delay feedback loops, and build in deception. These actions work together to cause as much pain to adversaries as possible. At the end of this discussion you will have a solid understanding of the TITO Threat Intelligence Framework, know how to apply TITO concepts to your existing Threat Intelligence program to improve operational workflows, and be able to add new friction to adversaries.