What problem does it solve?
Security teams often see isolated incidents without realizing they belong to a single coordinated adversary campaign. This Skill links disparate events, indicators, and behaviors across time and organizations so analysts can attribute activity to common threat actors and produce campaign-level intelligence instead of fragmented alerts.
Core Features & Use Cases
- Multi-Dimensional Pivot Analysis: Correlates events across infrastructure, capability, temporal, and victimology dimensions using STIX 2.1 normalized data.
- Weighted Confidence Scoring: Applies a scoring model (infrastructure 40, capability 35, temporal 15, victimology 10) to classify campaign attribution as HIGH, MEDIUM, or LOW confidence.
- Campaign Graph & Reporting: Builds STIX campaign graphs in OpenCTI, Maltego, or Neo4j and produces structured reports with timelines, ATT&CK heatmaps, shared IOCs, and Sigma/YARA detection guidance.
- Use Case: An ISAC partner shares indicators matching your historical SIEM events; use this Skill to pivot across shared C2 infrastructure and malware configs, score the linkage, and publish a campaign report linking months of activity to one intrusion set.
Quick Start
Correlate these three MISP events sharing the same C2 subnet and Cobalt Strike config, score the campaign confidence, and draft a STIX campaign report with shared indicators.