My contribution to the threat actor naming discourse
@mttaggart agreed. I think this every time I catch myself down a rabbit hole of "oh they reused this github username on another site, wonder what other threads I can pull at"
that guy doesn't deserve to be a meme
something like a bargain basement Charlie Kirk
@mttaggart knowing the motivation of your threat group is important. Like knowing that you got creds stolen from a group that is going to sell them versus use them is important.
Also knowing if something is targeted or not is important.
@Xavier How does it matter at all? Once you know you have your creds stolen, is there any reason to assume they won't be sold/abused? Why would your defensive posture/response differ?
@mttaggart Yes, if its a cred reseller, we can expect our normal controls to remain effective. For example, we find creds on the dark web. Just reset creds and run reports, but likelihood is that they never successfully connected due to other controls.
If the actor is like Scattered Spider, then they already have automated process that is learning your controls and are actively adding capabilities to their attack. This is a all hands on deck, including security engineering, and will probably be a extended engagement.
Not knowing anything your actor means responding like SS every time, which is not fun.
@Xavier To be frank, that sounds like missing telemetry in both cases. You shouldn't be guessing about follow-on behavior. And again, with that telemetry, you're focused on behavior and not who might have done it.
Hmm...
I suppose with the commoditization and separation of initial access and post-initial access crews, that's probably true for most criminal activity. But I don't know if I'd say that's universally true. There are still some criminal shops out there that, while not as monolithic as state actors, tend to maintain stable TTPs for long enough and for enough of the attack lifecycle that attribution can help defenders and responders.
@DaveMWilburn That puts the value on identifying relevant TTPs, where it should be. The who does not matter; you are aligning defenses against observed behavior.
At best clustering can be useful, but that isn't attribution.
@mttaggart my personal experience has been that, at least during incident response, narrowing down the universe of possible TTPs down to the ones most commonly used by a specific, attributed threat actor helps focus and speed up incident scoping and response in critical ways. It's less helpful in general defense, but absolutely critical in time-sensitive breach response.
@DaveMWilburn I have a similar experience but if I examine it closely, the who does not matter. I find relevant threat intelligence that describes a similar campaign. Great. I then hunt for those TTPs. At no point does attribution impact my defensive posture.