Threat Actor Attribution
SkillSecurityAssess possible threat-actor or campaign links using the Diamond Model and ATT&CK group data, expressed with calibrated estimative language; use only when a case shows enough TTP or infrastructure overlap to justify attribution discussion.
Use Threat Actor Attribution in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Threat Actor Attribution and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Threat Actor Attribution skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by gensecaihq/wazuh-autopilot in backend/app/skills/threat-actor-attribution/SKILL.md and read by ahel’s review.
Attribution is rarely needed to respond, and wrong attribution causes real harm (misdirected response, bad executive decisions). Do it carefully or not at all.
When to attempt
Attempt only if at least two of these hold:
- Infrastructure (IP/domain) with a reliable (A/B) public link to a named cluster.
- Tooling or malware family with known actor associations.
- A distinctive TTP sequence matching an ATT&CK group profile.
- Targeting consistent with the actor's known sector/geography interest.
Otherwise record "attribution not assessed — insufficient evidence" and stop.
Diamond Model
Describe the intrusion on four vertices and the links between them:
| Vertex | Questions | Evidence sources |
|---|---|---|
| Adversary | Who operates it? (often unknown — that's fine) | intel reporting |
| Capability | Tools, malware, exploits, techniques | host forensics, ATT&CK mapping |
| Infrastructure | IPs, domains, C2, hosting | IOC enrichment |
| Victim | Which assets, users, sector | case entities, org context |
Meta-features: timestamp, phase (ATT&CK tactic), result, direction, methodology. Pivot vertex-to-vertex (e.g. infrastructure → other victims seen in intel) to test links.
Comparing to ATT&CK groups
- List the case's confirmed techniques (from
mitre-attack-mapping). - Compare with candidate groups' technique sets from public ATT&CK group pages
(via
search_external_contextfor the group name — public data only). - Overlap on common techniques (T1059, T1078, T1110) means little; weight distinctive techniques and tool names higher.
- Record competing hypotheses, including "unknown / commodity actor".
Estimative language (ICD 203 style)
Use consistent probability terms and state confidence separately:
| Term | Approx. probability |
|---|---|
| almost no chance / remote | 1–5% |
| very unlikely | 5–20% |
| unlikely | 20–45% |
| roughly even chance | 45–55% |
| likely | 55–80% |
| very likely | 80–95% |
| almost certainly | 95–99% |
Confidence (low / moderate / high) reflects evidence quality and source reliability, not probability. Example: "We assess it is unlikely (moderate confidence) that this activity is linked to group X; infrastructure overlap is limited to a shared hosting provider."
Rules
- Never name a nation-state sponsor on your own; at most reference public reporting and grade it.
- Distinguish commodity crimeware, opportunistic scanning, and targeted operations.
- Attribution never changes containment urgency by itself.
Output
add_findingtitledAttribution assessmentwith the Diamond Model table, competing hypotheses with estimative language and confidence, sources with Admiralty grades, and key gaps. standard_refs:MITRE-ATTACK.
Signals
- GitHub stars
- 57
- Forks
- 16
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
threat-actor-attribution- Source
- github.com/gensecaihq/wazuh-autopilot
github.com/gensecaihq/wazuh-autopilot
Related picks
Skill · mukul975
The pick for Vulnerabilitiespre-mortem-facilitator
Skill · codebygarv
The pick for Vulnerabilitiesgws-shared
Skill · googleworkspace
More in Securitybrandkit
Skill · leonxlnx
More in Securitydefi-amm-security
Skill · affaan-m
More in Securityfastapi-patterns
Skill · affaan-m
More in Security