What to know
- Separate what investigators observed from the conclusions they drew.
- Assess independent evidence and credible alternative explanations.
- Use confidence language to describe the basis of a judgment.
Begin with the claim being made
Attribution can refer to several different claims: two incidents share activity, a particular operator conducted them, or a government directed that operator. These claims require different evidence. A report becomes easier to assess when it states which conclusion it is offering. Readers should not have to infer a claim of sponsorship from a technical observation about infrastructure.
MITRE ATT&CK describes groups as activity clusters tracked under common names and warns that reporting definitions can overlap. A group label is therefore useful shorthand for a body of observations, not automatically proof of a single known organization. Before comparing reports, check whether their authors are using a name to mean the same collection of activity.
An artifact supports more than one explanation
Consider a hypothetical investigation in which two intrusions contacted the same rented server. That observation may justify investigating a connection. It does not, by itself, establish a common operator. The investigators should consider whether the server changed hands, hosted multiple users, or formed part of a service used by unrelated actors. The relevant dates and usage context matter.
Now suppose the intrusions also share a distinctive sequence of actions. The combined evidence may make a relationship more plausible, but the analyst still needs to explain why that sequence is informative. Widely copied procedures offer different support from an unusual, consistently observed behavior. The value comes from the reasoning connecting evidence to a claim, not from the number of matching indicators alone.
Source: Office of the Director of National Intelligence: ICD 203 Analytic Standards
Count independent evidence, not repeated citations
Five reports can repeat one underlying observation. That repetition may increase public awareness without adding five independent reasons to believe the claim. Trace consequential assertions back to the evidence available to each author. A vendor report, a government statement, and a news article might contain separate collection, or they might all depend on the same original disclosure.
In the hypothetical server example, ask whether a second source independently observed the same activity or merely quoted the first report’s infrastructure list. Then describe the difference. Independent evidence can still be wrong, and shared sourcing does not make a claim false. The purpose is to avoid treating the appearance of agreement as stronger support than the underlying information provides.
Source: Office of the Director of National Intelligence: ICD 203 Analytic Standards
Separate confidence from likelihood
The U.S. intelligence community’s analytic standards distinguish a judgment’s likelihood from confidence in its evidentiary basis. FIRST’s threat-intelligence guidance also addresses communicating uncertainty. This distinction helps readers understand two different questions: how an analyst assesses an outcome or explanation, and how strong the available basis is for making that assessment.
A report might assess one explanation as the most plausible while acknowledging that important evidence is missing. That is different from claiming the explanation is established. State the limitations near the conclusion, including gaps in visibility, uncertainty about timing, or dependence on a single source. Confidence language becomes useful when the report explains what would strengthen or weaken the judgment.
Source: Office of the Director of National Intelligence: ICD 203 Analytic Standards · FIRST: Communicating Uncertainties in Cyber Threat Intelligence Reporting
Treat sponsorship and intent as additional judgments
Even a well-supported link between technical activity and an operator does not automatically resolve who directed the work or why it occurred. Those are further claims. A careful report should distinguish observed behavior from an assessment of its purpose. It should also identify whether a public conclusion depends on information that readers cannot independently examine.
Return to the two hypothetical intrusions. Access to similar targets may support an inquiry into shared objectives, but it cannot alone prove a government instruction. Several explanations may fit the same target selection. Present the strongest alternatives and explain why the preferred judgment fits better. This gives readers a way to assess the argument without pretending that every intelligence question has a publicly available answer.
Source: Office of the Director of National Intelligence: ICD 203 Analytic Standards
Match the decision to the evidence available
A defender often needs to contain suspicious access before the sponsor is known. The threshold for disabling a confirmed unauthorized account is different from the threshold for publicly assigning responsibility to a state. Separate those decisions. Useful technical evidence can support protective action while broader attribution remains provisional, disputed, or outside the organization’s ability to assess.
Good attribution writing makes its reasoning inspectable. It identifies the claim, describes the supporting observations, considers credible alternatives, and states its limits. It also leaves room for revision as evidence changes. A memorable group name can help readers follow a campaign, but the quality of the conclusion ultimately depends on the chain of judgments behind that name.
Source: FIRST: Communicating Uncertainties in Cyber Threat Intelligence Reporting · MITRE ATT&CK: Groups and Activity Clusters
Sources & further reading
- MITRE ATT&CK: Groups and Activity Clusters
- Office of the Director of National Intelligence: ICD 203 Analytic Standards
- FIRST: Communicating Uncertainties in Cyber Threat Intelligence Reporting
Factual statements are grounded in the linked material. Interpretation and illustrative examples are Byte Watchr analysis. Vendor claims are identified as claims, rather than independent testing.
This article belongs to Byte Watchr’s launch collection. The edition date organizes evergreen coverage and does not imply historical publication. Actual publication is recorded above.
Corrections policy · About this byline



