Атрибуция кибератак по доказательной базе
★ 8.4 · research
analyzing-campaign-attribution-evidence is a Claude Code skill that systematically evaluates cyber-campaign evidence to attribute an operation to a specific threat actor. It applies the Diamond Model and Analysis of Competing Hypotheses (ACH), collecting and weighting indicators across six evidence categories — infrastructure overlap, TTP consistency, malware code similarity, operational timing patterns, language artifacts, and victimology — and produces confidence-weighted assessments rated HIGH, MODERATE, or LOW. The implementation uses Python classes backed by the attackcti, stix2, and networkx libraries, with integration into MISP and OpenCTI threat intelligence platforms and alignment to MITRE ATT&CK and NIST CSF controls. It is designed for SOC analysts and CTI practitioners who need a defensible, reproducible attribution conclusion during active incident investigations.
- #threat-intelligence
- #cti
- #mitre-attack
- #campaign-analysis
- #attribution
- #stix
- #ioc