@DaveMWilburn@infosec.exchange
Post #4068206
2026-07-24 16:59 UTC
@mttaggart@infosec.exchange
Hmm...
I suppose with the commoditization and separation of initial access and post-initial access crews, that's probably true for most criminal activity. But I don't know if I'd say that's universally true. There are still some criminal shops out there that, while not as monolithic as state actors, tend to maintain stable TTPs for long enough and for enough of the attack lifecycle that attribution can help defenders and responders.
Replies (1)
-
@mttaggart@infosec.exchange 2026-07-24 17:03
@DaveMWilburn@infosec.exchange That puts the value on identifying relevant TTPs, where it should be. The who does not matter; you are aligning defenses against observed behavior. At best clustering can be useful, but that isn't attribution.