@DaveMWilburn@infosec.exchange
Post #4068449
2026-07-24 17:20 UTC
@mttaggart@infosec.exchange
Maybe we're talking cross purposes. At least from my experience, the spectrum of attribution can range from a cluster of similar activity on the one end, to specific named organization/agency/individuals on the other. Somewhere in the middle includes the goofy industry cover terms, often with nonspecific links to suspected countries of origin. I would agree that most defenders benefit from cluster-of-similar-activity level of attribution. Some larger organizations, especially ones that need to do more formal threat modelling, probably benefit from group names. I don't think anyone except governments benefit from attribution down to specific orgs/agencies/individuals.
Replies (1)
-
@mttaggart@infosec.exchange 2026-07-24 17:46
@DaveMWilburn@infosec.exchange Right so as I said, I believe "clustering" has value. To me, the strong form of "attribution" is "This is who did it and we're making a claim about it." And the reason I don't care is because that level of assignation does not impact my defensive choices. On the other hand, it eats up so much oxygen in threat intelligence reports.