analyzing-campaign-attribution-evidence

Analyze attribution evidence to rank threat actor hypotheses with confidence levels.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/Axxxxxxaaann/KAIRI-Skills --skill analyzing-campaign-attribution-evidence-axxxxxxaaann
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: analyzing-campaign-attribution-evidence
Source: https://github.com/Axxxxxxaaann/KAIRI-Skills/tree/main/skills/analyzing-campaign-attribution-evidence
Command: npx skills add https://github.com/Axxxxxxaaann/KAIRI-Skills --skill analyzing-campaign-attribution-evidence-axxxxxxaaann

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

Campaign attribution analysis enables security teams to systematically evaluate evidence to determine which threat actor or group is responsible for a cyber operation. The skill consolidates infrastructure overlaps, TTP consistency, malware similarities, timing, and language cues into a confidence-weighted assessment.

Core Features & Use Cases

  • Integration of Diamond Model and ACH for structured attribution workflows.
  • Infrastructure overlap, TTP consistency, malware similarity, timing, and language artifact analyses to support robust conclusions.
  • Use cases include incident investigations, threat-hunting queries, and strategic threat intelligence reporting.

Quick Start

Provide a dataset of attribution evidence and run the agent to generate an initial attribution assessment.

Frequently Asked Questions about analyzing-campaign-attribution-evidence

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze attribution evidence for cyber campaigns?

To analyze attribution evidence, provide a dataset of infrastructure overlaps, TTPs, and malware similarities. The agent applies the Diamond Model and ACH to weigh competing hypotheses and generates a structured attribution score with confidence levels.

What is the Diamond Model used for in threat intelligence attribution?

The Diamond Model structures attribution workflows by correlating infrastructure overlaps, TTP consistency, and malware similarities. Combined with ACH, it systematically evaluates evidence to identify threat actors responsible for cyber campaigns.

How to apply ACH to rank competing threat actor hypotheses?

Apply ACH by providing attribution evidence like timing and language cues. The agent weighs competing hypotheses against this data, ranking them to produce a confidence-weighted assessment of responsible threat actors.

Does this campaign analysis approach use MITRE ATT&CK correlations for attribution?

Yes, MITRE ATT&CK correlations are applied alongside TTP consistency analysis. This integration helps weigh attribution evidence systematically to identify the threat actors responsible for cyber operations.

Can I use this for incident investigations and threat hunting queries?

Yes, attribution analysis supports incident investigations and threat-hunting queries. It consolidates infrastructure overlaps and TTP consistency into a confidence-weighted assessment for strategic threat intelligence reporting.

What data do I need to generate a report-ready attribution summary?

You need a dataset of attribution evidence including infrastructure overlaps, malware similarities, timing, and language cues. The agent processes this to produce a structured attribution score and a report-ready summary with confidence levels.