Damus
Taggart :ifin: · 2w
My contribution to the threat actor naming discourse https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/975/957/486/476/308/original/801269bafab7e0f4.png
Dave Wilburn :donor: profile picture
@nprofile1q...

Hmm...

I suppose the commoditization and separation of initial access and post-initial access crews, that's probably true for most criminal activity. But I don't know if I'd say that's universally true. There are still some criminal shops out there that, while not as monolithic as state actors, tend to maintain stable TTPs for long enough and for enough of the attack lifecycle that attribution can help defenders and responders.
1
Taggart :ifin: · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq25ys6m6zxxdggtg8vtcycfv2pzmv44h6lsne9d0gy6hz6nd3epvsa3q2xw That puts the value on identifying relevant TTPs, where it should be. The who does not matter; you are aligning defenses against observed behavior. At best clustering can be useful, but...