Threat Actor Profiling & Attribution

Advanced

Learn threat actor profiling and attribution: grade evidence, weigh competing hypotheses, and state confidence you can defend. You work an unnamed activity cluster through infrastructure, behaviour and underground persona analysis, decide what the evidence actually supports about the operator, and write an actor intelligence product a decision maker can act on. The path teaches the refusal as well as the claim: when the evidence will not carry a name, saying so is the finding. Four sections, 38 lessons, 190 quizzes and seven hands-on missions on live investigation surfaces.

By CTI Academy Team45 steps4 sections~10 hoursCertificate

Curriculum

45 steps across 4 sections. Sections unlock in order as you complete them.

8 more steps behind a free account

Free account

Ready to start Threat Actor Profiling & Attribution?

Create a free account to open the remaining 8 steps, track every one you finish and earn your certificate.

  • Free to start
  • Progress saved on every step
  • Certificate on completion
Sign up with email

About this path

Attribution goes wrong in a specific way. It is rarely that the analyst had no evidence. It is that the evidence was counted rather than weighed, that four readings of one vendor's telemetry were treated as four sources, and that a name went on the page because the room wanted one. This path is about the discipline that stops that, and about the sentence most training never teaches you to write: the evidence does not support naming anybody, and here is exactly what it does support.

The spine of it is an evidence ladder with four rungs. An observation is weak when most operators could have produced it, because it is a default or a commodity. It is supporting when it narrows the field, because it reflects a preference rather than a default. It is strong when few operators could have produced it, because the choice is habitual or costly to change. It is exceptional when effectively one could, usually through a mistake that leaks an identity. The rung is set by how many operators could have produced the observation, never by how much you want the conclusion. Every judgement in the path is priced on that ladder.

The first section builds attribution discipline before any evidence arrives: what a cited claim is, why a shared ecosystem is not a shared actor, and how an activity cluster earns a designator without earning a name. The second section is technical correlation, where you price infrastructure honestly. A shared IP means nothing until you know the tenant count. A certificate serial that ties three hosts together is a different rung from a hosting provider they happen to share. The third section moves to behaviour and identity: working hours, language, underground personas, and the gap between a record about an account and a record about a person. The fourth section turns a graded assessment into a product, sixteen fields of it, with a confidence row that has to survive a reader who disagrees.

Seven missions run alongside the lessons, and they are not quizzes with a story on top. You work a case on live investigation surfaces, read a closed forum and a breach corpus, pull certificates and whois records off a lab range, and hand back a judgement with its confidence stated. Two of them end with you declining to name anybody, because that is what the evidence pays for, and writing the other sentence would be something you could not defend.

It assumes you already work with threat intelligence: that you can read a report, recognise MITRE ATT&CK technique ids, and know what an indicator is. If that is new, start with Cyber Threat Intelligence and come back. Nothing here needs a corporate telemetry stack. The investigation surfaces are part of the platform and the lab range is reachable over the VPN the path hands you.

What you will learn

  • Price evidence on a four-rung ladder. Place any observation on weak, supporting, strong or exceptional by asking how many operators could have produced it, and defend the rung when somebody pushes back.
  • Say what an activity cluster is, and is not. Track an operator as an unnamed cluster with a designator, and know exactly what has to change before that cluster earns a name.
  • State confidence in words that survive review. Write a confidence line that says how much weight the claim will take, and keep the grade separate from how strongly you happen to feel about it.
  • Refuse an attribution in writing. Recognise the cases where the evidence will not carry a name, and write the refusal so that it reads as a finding rather than as a gap.
  • Correlate infrastructure without overreading it. Price a shared address by its tenant count, tell a registrar handover from a takeover, and know when a certificate is a link and when it is a coincidence.
  • Read behaviour as evidence. Turn working hours, language and tooling habits into graded observations, and keep them apart from the build artifacts that describe a product rather than a person.
  • Work an underground persona. Read a closed board and a breach corpus for what a record actually establishes about an account, and resist the leap from account to person.
  • Separate a shared supplier from a shared operator. Tell an ecosystem overlap from a relationship, and name the evidence that would distinguish them rather than assuming one.
  • Build a sixteen-field actor profile. Turn a graded assessment into a product with provenance, gaps and an expiry date, so a reader knows what it is safe to act on.
  • Write a falsifiable assessment. State the observation that would refute your own identity row, precisely enough that somebody could go out and look for it.

Who this path is for

  • Threat intelligence analysts who are already producing reporting and keep being asked who did it, without ever having been taught how to price the answer or how to decline.
  • SOC and incident response analysts who can read an intrusion end to end and now need the analytical half: evidence weighting, competing hypotheses and confidence they can defend.
  • Anyone who has finished Cyber Threat Intelligence and wants the attribution work that path deliberately stops short of.
  • Detection engineers and hunters who inherit actor profiles from somebody else and need to judge which rows in one are worth building on.

Guides for this path

Frequently asked questions

When the evidence would not survive the question of how many other operators could have produced it. A shared hosting provider, a commodity tool or a leaked builder stamp are consistent with thousands of operators, so they cannot carry a name however many of them you stack up. The path teaches you to write that refusal as a finding, with the reading you could not rule out stated on the page, rather than leaving a gap for the next reader to fill in with a guess.

Confidence says how much weight a claim will take, and it is set by the evidence rather than by conviction. This path grades every observation on a four-rung ladder first, weak, supporting, strong and exceptional, and derives the assessment's confidence from what survives after you subtract duplicate collection routes, unexplained contradictions and any competing reading still standing. A surviving alternative sets a ceiling on the confidence no amount of supporting evidence can lift.

A cluster is a set of activity that correlates well enough to track as one thing and carries a designator instead of a name. A named actor is a further claim about who is behind it, and it has its own evidence bill. Correlation earns you the cluster. Every step above it has to be paid for separately, which is why mature teams run unnamed clusters for months and why the path teaches you to work at cluster level.

You need to be working with threat intelligence, not necessarily employed as an analyst. The path assumes you can read a vendor report, recognise MITRE ATT&CK technique ids and say what an indicator is. If those are new, Cyber Threat Intelligence comes first. It does not assume access to corporate telemetry: the investigation surfaces are part of the platform and the lab range comes with the VPN configuration you need.

General CTI courses treat attribution as one topic among many and usually as a capability to acquire. This path treats it as a judgement with a cost, and spends as much time on the cases where you decline to name somebody as on the cases where you can. The evidence ladder, the confidence ceiling and the falsifiable identity row are the working tools, and seven missions make you use them on evidence you have to go and collect.

Four sections, nine modules, 38 lessons, 190 quizzes and seven hands-on missions, roughly ten hours at a normal pace. The missions run on live investigation surfaces and a lab range rather than on transcribed screenshots, so the evidence you grade is evidence you fetched. Completing every step earns the path certificate.

No, and that is deliberate. Naming a state sponsor is a judgement that rests on collection most analysts will never hold, and courses that promise it are teaching you to guess with confidence. What this path teaches is how to say precisely what your evidence does support, how sure you are, and what would change your mind. That sentence is usable by a decision maker. A name you cannot defend is not.