Threat campaigns
Understanding what defines a threat campaign is paramount in CTI. Threat campaigns help define a specific cluster of related activity conducted by a singular or several threat actors or groups acting in unison. Ultimately, campaigns are groups of threat activity that are carried out by threat actors using specific tactics, techniques, and procedures operating for a specific purpose. A good example of this would be a threat actor group targeting a retail outlet during December.
A threat campaign is a set of incidents performed by a threat actor using specific techniques over a specific timeframe with a particular motivation and target. Most often, when campaigns are being identified, the actor behind the campaign cannot be defined. In this case, it's best to assign a temporary or unknown actor indicator for further clustering and analysis. Defining the activity that correlates with a specific campaign is a largely subjective decision. This is often the case...