Module 3: Analyze, Report, and Improve

Describe Adversary Behavior Without Overclaiming

Use behavior, capability, and context to explain threats without treating attribution as certainty.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Describe adversary behavior using observable evidence while separating capability, intent, opportunity, and attribution confidence.

Describe Adversary Behavior Without Overclaiming

This lesson teaches a careful way to discuss actors and campaigns. You will distinguish observed behavior from inferred intent and learn why technique overlap, shared infrastructure, and false flags make attribution a separate analytic claim.

Describe What the Adversary Can Do

A useful behavior description answers four questions: What capability is visible? What opportunity does the adversary have? What target or objective appears relevant? What evidence supports the assessment? This is more durable than starting with a dramatic actor label.

Suppose a campaign uses valid cloud accounts, sends convincing invoices, and creates mailbox forwarding rules. You can describe those observable behaviors, the access they require, and the defensive telemetry that could reveal them. You may assess that the activity is consistent with financially motivated credential theft. You should not state that a named group definitely conducted it unless the evidence supports that separate claim.

Use ATT&CK or another shared vocabulary to make behavior searchable, but do not confuse a technique mapping with attribution. Many actors can use the same technique. A technique says what happened or could happen; it does not, by itself, prove who acted, why they acted, or whether the activity belongs to one campaign.

Treat Attribution as a Hypothesis

Attribution can be useful, but it is often the least certain part of an assessment. Shared tools, copied procedures, compromised infrastructure, contractors, malware-as-a-service, and deliberate false flags reduce the uniqueness of many indicators. Government attribution may also rely on evidence unavailable to a private analyst.

Use a confidence statement that names the basis and the limits: “We assess with low confidence that the activity may be associated with Group A because of infrastructure overlap and targeting similarities; shared hosting and reused tools prevent a firm attribution.” This gives the reader a useful hypothesis without turning it into a fact.

Defensive action should usually depend on the behavior and exposure, not on winning the attribution debate. If the activity suggests credential theft, improve identity telemetry and protect accounts even while actor identity remains uncertain. If a domain is malicious-looking but evidence is weak, preserve it for investigation rather than blocking a broad provider range without context.

Resources

  • MITRE ATT&CK Groups — Compare group descriptions and techniques while practicing the distinction between documented behavior and attribution certainty.