Analyzing Campaign Attribution Evidence

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-campaign-attribution-evidence

by mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0Listed Oct 9, 2026Updated Oct 9, 2026

Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.

AI-generated overview

Evaluates cyber-campaign evidence to attribute attacks to threat actors using the Diamond Model and competing-hypotheses analysis.

What it does
This skill guides a structured attribution analysis of a cyber campaign, collecting evidence across six categories: infrastructure overlap, TTP consistency, malware code similarity, operational patterns, language artifacts, and victimology. It scores evidence as consistent, inconsistent, or neutral against competing threat-actor hypotheses, compares infrastructure and ATT&CK technique sets, and ranks hypotheses into high, moderate, or low confidence. It produces a structured attribution assessment report with rankings, a primary attribution, and an evidence summary.
When to use it
Use it when an incident investigation needs a defensible attribution confidence level for a cyber operation. It suits SOC analysts and threat-intelligence teams who must weigh competing actor hypotheses and document false-flag considerations.
Requirements
Python 3.9+ with the attackcti, stix2, and networkx libraries; access to threat-intelligence platforms such as MISP or OpenCTI; familiarity with the Diamond Model, MITRE ATT&CK group profiles, and malware/infrastructure tracking. The skill ships executable scripts.

Analyzing Campaign Attribution Evidence

Overview

Campaign attribution analysis involves systematically evaluating evidence to determine which threat actor or group is responsible for a cyber operation. This skill covers collecting and weighting attribution indicators using the Diamond Model and ACH (Analysis of Competing Hypotheses), analyzing infrastructure overlaps, TTP consistency, malware code similarities, operational timing patterns, and language artifacts to build confidence-weighted attribution assessments.

When to Use

  • When investigating security incidents that require analyzing campaign attribution evidence
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Python 3.9+ with attackcti, stix2, networkx libraries
  • Access to threat intelligence platforms (MISP, OpenCTI)
  • Understanding of Diamond Model of Intrusion Analysis
  • Familiarity with MITRE ATT&CK threat group profiles
  • Knowledge of malware analysis and infrastructure tracking techniques

Key Concepts

Attribution Evidence Categories

  1. Infrastructure Overlap: Shared C2 servers, domains, IP ranges, hosting providers
  2. TTP Consistency: Matching ATT&CK techniques and sub-techniques across campaigns
  3. Malware Code Similarity: Shared code bases, compilers, PDB paths, encryption routines
  4. Operational Patterns: Timing (working hours, time zones), targeting patterns, operational tempo
  5. Language Artifacts: Embedded strings, variable names, error messages in specific languages
  6. Victimology: Target sector, geography, and organizational profile consistency

Confidence Levels

  • High Confidence: Multiple independent evidence categories converge on same actor
  • Moderate Confidence: Several evidence categories match, some ambiguity remains
  • Low Confidence: Limited evidence, possible false flags or shared tooling

Analysis of Competing Hypotheses (ACH)

Structured analytical method that evaluates evidence against multiple competing hypotheses. Each piece of evidence is scored as consistent, inconsistent, or neutral with respect to each hypothesis. The hypothesis with the least inconsistent evidence is favored.

Workflow

Step 1: Collect Attribution Evidence

python
from stix2 import MemoryStore, Filterfrom collections import defaultdict
class AttributionAnalyzer:    def __init__(self):        self.evidence = []        self.hypotheses = {}
    def add_evidence(self, category, description, value, confidence):        self.evidence.append({            "category": category,            "description": description,            "value": value,            "confidence": confidence,            "timestamp": None,        })
    def add_hypothesis(self, actor_name, actor_id=""):        self.hypotheses[actor_name] = {            "actor_id": actor_id,            "consistent_evidence": [],            "inconsistent_evidence": [],            "neutral_evidence": [],            "score": 0,        }
    def evaluate_evidence(self, evidence_idx, actor_name, assessment):        """Assess evidence against a hypothesis: consistent/inconsistent/neutral."""        if assessment == "consistent":            self.hypotheses[actor_name]["consistent_evidence"].append(evidence_idx)            self.hypotheses[actor_name]["score"] += self.evidence[evidence_idx]["confidence"]        elif assessment == "inconsistent":            self.hypotheses[actor_name]["inconsistent_evidence"].append(evidence_idx)            self.hypotheses[actor_name]["score"] -= self.evidence[evidence_idx]["confidence"] * 2        else:            self.hypotheses[actor_name]["neutral_evidence"].append(evidence_idx)
    def rank_hypotheses(self):        """Rank hypotheses by attribution score."""        ranked = sorted(            self.hypotheses.items(),            key=lambda x: x[1]["score"],            reverse=True,        )        return [            {                "actor": name,                "score": data["score"],                "consistent": len(data["consistent_evidence"]),                "inconsistent": len(data["inconsistent_evidence"]),                "confidence": self._score_to_confidence(data["score"]),            }            for name, data in ranked        ]
    def _score_to_confidence(self, score):        if score >= 80:            return "HIGH"        elif score >= 40:            return "MODERATE"        else:            return "LOW"

Step 2: Infrastructure Overlap Analysis

python
def analyze_infrastructure_overlap(campaign_a_infra, campaign_b_infra):    """Compare infrastructure between two campaigns for attribution."""    overlap = {        "shared_ips": set(campaign_a_infra.get("ips", [])).intersection(            campaign_b_infra.get("ips", [])        ),        "shared_domains": set(campaign_a_infra.get("domains", [])).intersection(            campaign_b_infra.get("domains", [])        ),        "shared_asns": set(campaign_a_infra.get("asns", [])).intersection(            campaign_b_infra.get("asns", [])        ),        "shared_registrars": set(campaign_a_infra.get("registrars", [])).intersection(            campaign_b_infra.get("registrars", [])        ),    }
    overlap_score = 0    if overlap["shared_ips"]:        overlap_score += 30    if overlap["shared_domains"]:        overlap_score += 25    if overlap["shared_asns"]:        overlap_score += 15    if overlap["shared_registrars"]:        overlap_score += 10
    return {        "overlap": {k: list(v) for k, v in overlap.items()},        "overlap_score": overlap_score,        "assessment": "STRONG" if overlap_score >= 40 else "MODERATE" if overlap_score >= 20 else "WEAK",    }

Step 3: TTP Comparison Across Campaigns

python
from attackcti import attack_client
def compare_campaign_ttps(campaign_techniques, known_actor_techniques):    """Compare campaign TTPs against known threat actor profiles."""    campaign_set = set(campaign_techniques)    actor_set = set(known_actor_techniques)
    common = campaign_set.intersection(actor_set)    unique_campaign = campaign_set - actor_set    unique_actor = actor_set - campaign_set
    jaccard = len(common) / len(campaign_set.union(actor_set)) if campaign_set.union(actor_set) else 0
    return {        "common_techniques": sorted(common),        "common_count": len(common),        "unique_to_campaign": sorted(unique_campaign),        "unique_to_actor": sorted(unique_actor),        "jaccard_similarity": round(jaccard, 3),        "overlap_percentage": round(len(common) / len(campaign_set) * 100, 1) if campaign_set else 0,    }

Step 4: Generate Attribution Report

python
def generate_attribution_report(analyzer):    """Generate structured attribution assessment report."""    rankings = analyzer.rank_hypotheses()
    report = {        "assessment_date": "2026-02-23",        "total_evidence_items": len(analyzer.evidence),        "hypotheses_evaluated": len(analyzer.hypotheses),        "rankings": rankings,        "primary_attribution": rankings[0] if rankings else None,        "evidence_summary": [            {                "index": i,                "category": e["category"],                "description": e["description"],                "confidence": e["confidence"],            }            for i, e in enumerate(analyzer.evidence)        ],    }
    return report

Validation Criteria

  • Evidence collection covers all six attribution categories
  • ACH matrix properly evaluates evidence against competing hypotheses
  • Infrastructure overlap analysis identifies shared indicators
  • TTP comparison uses ATT&CK technique IDs for precision
  • Attribution confidence levels are properly justified
  • Report includes alternative hypotheses and false flag considerations

References

Source and attribution

Source:mukul975/Anthropic-Cybersecurity-Skillsinskills/analyzing-campaign-attribution-evidenceat commit54a7988

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from mukul975/Anthropic-Cybersecurity-Skills

Exploiting Sql Injection Vulnerabilities

mukul975

Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testing, SQLi exploitation, database security assessment, or injection vulnerability verification.

Includes scripts
Awaiting classificationOct 9, 2026

Analyzing Network Traffic With Wireshark

mukul975

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

Includes scripts
Awaiting classificationOct 9, 2026

Analyzing Dns Logs For Exfiltration

mukul975

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.

Includes scripts
Awaiting classificationOct 9, 2026

Analyzing Cloud Storage Access Patterns

mukul975

Detects abnormal cloud storage access in AWS S3, GCS and Azure Blob logs using statistical baselines and anomaly detection.

Includes scripts
SecurityOct 9, 2026

Analyzing Certificate Transparency For Phishing

mukul975

Monitors Certificate Transparency logs via crt.sh and Certstream to detect phishing domains and lookalike certificates.

Includes scripts
SecurityOct 9, 2026

Analyzing Browser Forensics With Hindsight

mukul975

Parses Chromium-based browser profile databases with Hindsight to reconstruct web activity timelines for investigations.

Includes scripts
SecurityOct 9, 2026