analyzing-campaign-attribution-evidence

Structure campaign evidence into Diamond Model and ACH attribution analyses.

Updated Apr 23, 2026
One-click install
npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill analyzing-campaign-attribution-evidence
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: analyzing-campaign-attribution-evidence
Source: https://github.com/YukiIto1999/ctf-sleuth/tree/main/.claude/skills/analyzing-campaign-attribution-evidence
Command: npx skills add https://github.com/YukiIto1999/ctf-sleuth --skill analyzing-campaign-attribution-evidence

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires attackcti, stix2, requests, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Campaign attribution analysis helps investigators determine which threat actor or group is responsible for a cyber operation by systematically evaluating evidence across multiple dimensions and using established analytical models.

Core Features & Use Cases

  • Diamond Model & ACH: structured evaluation of competing hypotheses to quantify confidence.
  • Infrastructure & TTP Analysis: assess infrastructure overlaps, malware similarities, timing, and language artifacts to support attribution decisions.
  • Deliverables: generate structured reports with evidence summaries and actionable insights for threat intel and defense teams.

Quick Start

Identify a campaign, collect relevant evidence, and run through the Diamond Model and ACH steps to produce a weighted attribution assessment.

Frequently Asked Questions about analyzing-campaign-attribution-evidence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I attribute cyber campaigns using the Diamond Model and ACH analysis?

Campaign attribution is performed by structuring collected evidence into the Diamond Model and applying Analysis of Competing Hypotheses (ACH) to systematically weigh and quantify confidence in identifying the most plausible threat actor.

What evidence dimensions are needed for threat actor attribution in OSINT investigations?

Threat actor attribution requires evaluating evidence across infrastructure overlaps, TTP matches, malware similarities, timing patterns, and language artifacts to synthesize a structured and quantified attribution report.

Can I use attackcti and stix2 libraries for campaign TTP matching and threat intelligence analysis?

Yes, campaign TTP matching and threat intelligence analysis leverage Python 3.9+ with standard CTI tooling including attackcti, stix2, and requests libraries to collect and synthesize threat data into structured attribution reports.

How do I generate a structured threat intelligence report for incident response attribution?

To generate a structured threat intelligence report, collect campaign evidence, run through the Diamond Model and ACH steps to evaluate competing hypotheses, and produce a weighted attribution assessment with actionable insights.

What is the best way to structure threat hunting evidence to quantify attribution confidence?

The best way to quantify attribution confidence is structuring threat hunting evidence into the Diamond Model and applying ACH-based analysis to weigh competing hypotheses, producing a systematic and mathematically grounded threat actor assessment.