logo

Introducing Unit 42’s Attribution Framework

ID: 1fb02600-e58f-58d7-a55b-327c90d1170d

STIX ID: report--1fb02600-e58f-58d7-a55b-327c90d1170d

Feed Name: Palo Alto Networks Unit 42

Date Published: 2025-07-31

Date Updated: 2026-04-28

Author: Andy Piazza, Kyle Wilhoit and Robert Falcone

...
...

This report presents Unit 42’s Attribution Framework, a structured methodology for progressing from activity clusters to temporary threat groups and ultimately named threat actors using rigorously evaluated evidence. It prescribes the use of the Admiralty System for source reliability and information credibility, establishes minimum analytical standards across TTPs, infrastructure/tooling, victimology, and temporal analysis, and stresses transparency, consistency, and review governance. An illustrative example connects Stately Taurus and Bookworm to demonstrate how IoCs and TTPs are scored and reviewed before advancing attribution confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.