Elektrine lite

← Feed

@mttaggart@infosec.exchange

Post #4068239

2026-07-24 17:09 UTC

@DaveMWilburn@infosec.exchange I have a similar experience but if I examine it closely, the who does not matter. I find relevant threat intelligence that describes a similar campaign. Great. I then hunt for those TTPs. At no point does attribution impact my defensive posture.

Replies (2)

  • @cR0w@infosec.exchange 2026-07-24 17:18

    @mttaggart@infosec.exchange @DaveMWilburn@infosec.exchange I agree with an asterisk. If your threat hunt and / or threat intel analysts are scooped for external hunts and information collection, the who matters to them. But I agree that it almost never matters to the customer / blue team.

    Open ##4068386

  • @mttaggart@infosec.exchange Maybe we're talking cross purposes. At least from my experience, the spectrum of attribution can range from a cluster of similar activity on the one end, to specific named organization/agency/individuals on the other. Somewhere in the middle includes the goofy industry cover terms, often with nonspecific links to suspected countries of origin. I would agree that most defenders benefit from cluster-of-similar-activity level of attribution. Some larger organizations, especially ones that need to do more formal threat modelling, probably benefit from group names. I don't think anyone except governments benefit from attribution down to specific orgs/agencies/individuals.

    Open ##4068449