Post #4068205
2026-07-24 17:03 UTC
@DaveMWilburn@infosec.exchange That puts the value on identifying relevant TTPs, where it should be. The who does not matter; you are aligning defenses against observed behavior.
At best clustering can be useful, but that isn't attribution.
Replies (1)
-
@DaveMWilburn@infosec.exchange 2026-07-24 17:08
@mttaggart@infosec.exchange my personal experience has been that, at least during incident response, narrowing down the universe of possible TTPs down to the ones most commonly used by a specific, attributed threat actor helps focus and speed up incident scoping and response in critical ways. It's less helpful in general defense, but absolutely critical in time-sensitive breach response.