🤓 I've built the ultimate threat actor attribution tool!!
Okay, okay… not quite ultimate, but still pretty useful. 😅
Let me explain. 👇
When you investigate an attack, sometimes you know what you are looking at—maybe you are an experienced analyst or have tracked a threat actor long enough to recognize their patterns.
But sometimes, you don’t! Or maybe your biases are too strong. 🫠
So, I wanted a system where I could describe an attack, add IOCs, TTPs, or a target sector, and get an automatic threat actor suggestion with confidence level and justification, based on my data and public knowledge.
I used the following metric: direct evidence (IOCs matching, tools/malware ID, TTP correlation), confidence scoring (0-100%), attribution factors (target, geography, infrastructure, timeline, tools, code patterns), and validation through public sources like ORKL.
I threw everything into an AI model with some similarity calculation, prevalidation and evaluation, and tada!