Analyzing Campaign Attribution Evidence

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-campaign-attribution-evidence

by mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0Listed Oct 9, 2026Updated Oct 9, 2026

Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
assets/template.md1003 Btext/markdown
LICENSE11 KBtext/plain
references/api-reference.md3.1 KBtext/markdown
references/standards.md1.1 KBtext/markdown
references/workflows.md1.4 KBtext/markdown
scripts/agent.py9.9 KBtext/plain
scripts/process.py5.9 KBtext/plain
SKILL.md9 KBtext/markdown

Source and attribution

Source:mukul975/Anthropic-Cybersecurity-Skillsinskills/analyzing-campaign-attribution-evidenceat commit54a7988

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal