Analyzing Campaign Attribution Evidence

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-campaign-attribution-evidence

by mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.0Listed Oct 9, 2026Updated Oct 9, 2026

Systematically evaluate cyber-campaign evidence to attribute an operation to a threat actor, using the Diamond Model and Analysis of Competing Hypotheses (ACH) to weigh infrastructure overlaps, TTP consistency, malware code similarity, and timing/language artifacts into confidence-weighted attribution assessments. Use when an incident investigation needs a defensible attribution confidence level.

  1. 54a798831d2266a3ca61ce68a7acb80b81160d57Currentcommit 54a7988Published Oct 9, 2026

Source and attribution

Source:mukul975/Anthropic-Cybersecurity-Skillsinskills/analyzing-campaign-attribution-evidenceat commit54a7988

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal