Elektrine lite

← Feed

@DaveMWilburn@infosec.exchange

Post #4068449

2026-07-24 17:20 UTC

@mttaggart@infosec.exchange Maybe we're talking cross purposes. At least from my experience, the spectrum of attribution can range from a cluster of similar activity on the one end, to specific named organization/agency/individuals on the other. Somewhere in the middle includes the goofy industry cover terms, often with nonspecific links to suspected countries of origin. I would agree that most defenders benefit from cluster-of-similar-activity level of attribution. Some larger organizations, especially ones that need to do more formal threat modelling, probably benefit from group names. I don't think anyone except governments benefit from attribution down to specific orgs/agencies/individuals.

Replies (1)

  • @mttaggart@infosec.exchange 2026-07-24 17:46

    @DaveMWilburn@infosec.exchange Right so as I said, I believe "clustering" has value. To me, the strong form of "attribution" is "This is who did it and we're making a claim about it." And the reason I don't care is because that level of assignation does not impact my defensive choices. On the other hand, it eats up so much oxygen in threat intelligence reports.

    Open ##4068931