Analytic Methods & Attribution
The reasoning between collection and reporting — what the Diamond Model is actually for, how activity clusters form, and why attribution past "same cluster" rarely changes a defensive decision.
This pillar covers where observations come from, the arithmetic that keeps them honest, and the formats they leave in. This page is the part in between: how a set of observations becomes a judgment, and how much of a judgment the evidence actually supports.
It is the step most often skipped, because it is the one with no tooling and no deliverable. The result is reporting that describes what was seen and then asserts what it means, with nothing connecting the two.
Models, and what each is for
Section titled “Models, and what each is for”- Cyber Kill Chain — linear and intrusion-centric. Useful shared vocabulary for “how far did they get.” Weak on intrusions that begin with valid credentials and never involve malware, which is most cloud and identity-first activity.
- Diamond Model — adversary, capability, infrastructure, victim, joined by relationships. Its value is the pivoting, not the diagram: any known vertex is a route to discovering another, and a chain of pivots is how tracking sustains itself over months. This is the model that actually supports clustering.
- ATT&CK — a taxonomy of observed behavior. Covered in MITRE ATT&CK.
The common error is treating ATT&CK as an analytic framework. It is a shared vocabulary, which is enormously valuable and a different thing. It tells you what to call what you observed; it does not tell you what to conclude from it. A report that maps twelve techniques and draws no inference has described an intrusion, not analyzed one.
Structured analytic techniques
Section titled “Structured analytic techniques”Analysts anchor on the first plausible explanation and then collect evidence that confirms it. The techniques exist to make that expensive:
- Analysis of Competing Hypotheses: enumerate hypotheses first, then score each piece of evidence by how inconsistent it is with each one. The discriminating power lives in the inconsistencies, because evidence consistent with everything tells you nothing. The output is the hypothesis with the least evidence against it — a different and more robust question than which has the most for it.
- Key assumptions check: write down what is being taken as given, then ask what changes if each is wrong. Assumptions inherited unexamined from an earlier report are the ones that bite, because they were load-bearing there and are invisible here.
- Devil’s advocacy: worth the cost only on high-consequence judgments.
Match the technique to the decision. A daily triage note does not need ACH. A judgment that prompts customer notification or a public statement does.
Clustering: what makes two intrusions the same thing
Section titled “Clustering: what makes two intrusions the same thing”Clustering is the operational core, and attribution is downstream of it. Evidence types, in roughly descending order of how much weight they can carry:
- Shared non-public infrastructure under common control
- Malware with shared code, build artifacts, or unique configuration values
- Distinctive tradecraft — the sequence and operational habits, not individual techniques
- Targeting and timing overlap
- Shared commodity tooling — the weakest, and the most consistently overweighted
Commodity tooling is where clusters get wrongly merged. Public offensive tools and widely sold RATs are used by unrelated actors, so their presence is close to evidence-free no matter how distinctive it looks in isolation. This is exactly the base rate problem: a feature common across the population has almost no discriminating power, however striking it is in the single case in front of you.
The mirror-image trap is attributing by victimology when your visibility covers one sector. The actor appears sector-focused because you cannot see anything else — sampling bias producing a finding about your own telemetry and reporting it as a finding about the adversary.
Attribution has levels, and most work needs only the first
Section titled “Attribution has levels, and most work needs only the first”Distinguish clearly between: an activity cluster, a named group, a real-world organization, a named individual, and national responsibility. Each step requires a different class of evidence, and the last two generally require collection a private defender does not have.
The honest position: past “same cluster,” attribution rarely changes a defensive decision. Whether the operator is a criminal crew or a state service, the patch, the detection and the control are identical. Its genuine uses are narrow — prioritization when an actor’s targeting pattern says you are plausibly next, legal and policy response, and executive communication.
It is also where the most confident-sounding and least falsifiable claims in the industry live, which is precisely why it deserves the strictest confidence language you have. “We assess with moderate confidence” is the finding here, not a hedge.
Actor naming is not a shared namespace
Section titled “Actor naming is not a shared namespace”Every vendor names independently, from its own visibility: APT numbers, animal pairs, weather names, UNC and TA identifiers. Two names are not two actors — and they are not reliably one actor either, because vendors cluster on different evidence and their groups have different boundaries. Recent cross-vendor mapping efforts help, but they publish mappings, not merges, and the distinction matters.
Practical discipline: track your own clusters against your own evidence, attach vendor names to them as aliases carrying their own confidence, and never let a vendor name enter your reporting as though it were an entity you observed directly.
What is worth tracking
Section titled “What is worth tracking”The Pyramid of Pain ranks indicators by what it costs the adversary when you burn them. Hashes and addresses are changed trivially; tooling and tradecraft are not. That ordering is why behavioral analysis outlives indicator collection, and why the durable output of analysis is a detection idea rather than a list — the handoff into the detection backlog.
How it looks in practice
Section titled “How it looks in practice”The discipline shows up as a small amount of standing infrastructure around the analysts:
- An internal cluster registry — the team’s own names, defined by its own evidence, with vendor names attached as aliases carrying their own confidence. The registry is the difference between tracking activity and tracking press coverage.
- ACH run in a worksheet, reserved for the judgments that trigger notification or a public statement. A simple matrix template makes the evidence-against-hypothesis scoring visible, reviewable, and inheritable by the next analyst on the case.
- A key-assumptions section in the report template, which costs a paragraph and catches the inherited load-bearing assumption before it ships.
- One confidence vocabulary — ICD 203’s estimative ladder or a house equivalent — used across every product, so “moderate confidence” means the same thing in an attribution judgment as in any other report.
Where this connects
Section titled “Where this connects”This sits directly downstream of collection and upstream of reporting, and it fails in the ways statistics predicts — base rates and sampling bias, wearing analytic clothes. ATT&CK supplies the vocabulary the analysis is written in. Investigation method is the same discipline under time pressure, with evidentiary obligations attached, and behavioral conclusions land as detection ideas rather than indicators.
Graph View
Spotted an error on this page? Report it.