Post #4068207
2026-07-24 16:44 UTC
Replies (5)
-
@DaveMWilburn@infosec.exchange 2026-07-24 16:59
@mttaggart@infosec.exchange Hmm... I suppose with the commoditization and separation of initial access and post-initial access crews, that's probably true for most criminal activity. But I don't know if I'd say that's universally true. There are still some criminal shops out there that, while not as monolithic as state actors, tend to maintain stable TTPs for long enough and for enough of the attack lifecycle that attribution can help defenders and responders.
-
@joriki@infosec.exchange 2026-07-24 17:37
@mttaggart@infosec.exchange that guy doesn't deserve to be a meme
-
@Xavier@infosec.exchange 2026-07-24 17:24
@mttaggart@infosec.exchange knowing the motivation of your threat group is important. Like knowing that you got creds stolen from a group that is going to sell them versus use them is important. Also knowing if something is targeted or not is important.
-
@thief_of_fire@infosec.exchange 2026-07-24 18:31
@mttaggart@infosec.exchange agreed. I think this every time I catch myself down a rabbit hole of "oh they reused this github username on another site, wonder what other threads I can pull at"
-
@z_ack@infosec.exchange 2026-07-25 04:36
@mttaggart@infosec.exchange And while we’re doing attribution, can we stop being coy? If it’s Russia, and you have a code word for Russia, just call it Russia.