Threat actor attribution
Threat actor attribution is a commonly discussed concept that's often misunderstood. Inherently difficult, threat actor attribution is the process of identifying the actors behind an attack, in addition to understanding their motivations. Attempts by advanced threat groups to obscure their identities have generated countless discussions about attribution and its nuance. But ultimately, attribution often boils down to a combination of technical indicators, attacker mistakes, activity overlaps, and sometimes, luck.
Attribution rarely ends up in any material action against the individual performing the attack but understanding the who behind an attack can help inform defenders to make better defensive choices. Attribution often leads to one of two outcomes – either an unknown threat actor group or a known threat actor group.
When you're attempting to perform attribution, it's often best to look at historical campaigns that have been...