Post #4068239
2026-07-24 17:09 UTC
Replies (2)
-
@cR0w@infosec.exchange 2026-07-24 17:18
@mttaggart@infosec.exchange @DaveMWilburn@infosec.exchange I agree with an asterisk. If your threat hunt and / or threat intel analysts are scooped for external hunts and information collection, the who matters to them. But I agree that it almost never matters to the customer / blue team.
-
@DaveMWilburn@infosec.exchange 2026-07-24 17:20
@mttaggart@infosec.exchange Maybe we're talking cross purposes. At least from my experience, the spectrum of attribution can range from a cluster of similar activity on the one end, to specific named organization/agency/individuals on the other. Somewhere in the middle includes the goofy industry cover terms, often with nonspecific links to suspected countries of origin. I would agree that most defenders benefit from cluster-of-similar-activity level of attribution. Some larger organizations, especially ones that need to do more formal threat modelling, probably benefit from group names. I don't think anyone except governments benefit from attribution down to specific orgs/agencies/individuals.