Skip to content
CIM-025 Cyber Incidents & Offender Methods

Does a threat-intelligence match identify an offender?

A threat-intelligence match may link activity to infrastructure, malware or techniques seen elsewhere. It does not automatically identify the offender.

Avoid the dangerous assumption

The dangerous assumption is that matching one indicator or method to a named group proves that group carried out the incident.

Infrastructure can be shared, rented, compromised or reassigned.

Malware can be sold, leaked, copied or modified.

Phishing kits can be used by many offenders.

Techniques such as password spraying, remote desktop access or archive creation are not unique to one group.

Even distinctive combinations of activity may reflect imitation, shared tooling or inaccurate prior reporting.

Ask what exactly matched.

Was it an IP address, a domain, a file hash, a malware family, a certificate, a command pattern, a ransom note, a sequence of techniques or a victim profile?

Then assess the strength of the link. An exact file hash may be more specific than a general technique. A dedicated server may be more informative than a shared cloud address. A current indicator may be more useful than one observed years earlier.

Also identify the intelligence confidence and whether the source distinguishes between infrastructure attribution, campaign attribution and personal attribution.

A match can support a hypothesis and guide requests for related records. It may help show that the incident is consistent with a known campaign.

It should not be converted into a categorical statement about offender identity without corroboration from the incident itself and other independent evidence.

Report the position cautiously: “The activity shared indicators with…” or “The infrastructure had previously been associated with…” may be justified where “Group X carried out the attack” is not.

Operational takeaway

Treat a threat-intelligence match as evidence of similarity or association, and require independent corroboration before attributing the incident to an offender or group.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.