logo

How to Identify a Cyber Adversary: Standards of Proof

ID: a40426d2-8b58-5295-9903-ff14f8581e58

STIX ID: report--a40426d2-8b58-5295-9903-ff14f8581e58

Feed Name: Dark Reading

Date Published: 2024-03-12

Date Updated: 2026-04-21

Author: Charles A. Garzoni

...
...

This commentary (part one of two) explains the purpose and process of cyber attribution, distinguishing between private attribution assessments and public disclosure actions. It outlines intelligence community confidence and probability standards (ICD 203), contrasts them with judicial standards of proof, and emphasizes the contextual nature and half-life of technical indicators and TTPs. The piece argues that attribution informs better defense and strategic responses, using APT1 as an illustrative example, and sets the stage for a follow-up on methods for attributing events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.