Threat Actor Attribution
Reads the threat-attribution layer (actors, MITRE ATT&CK techniques and tactics, threat tags) straight off the graph. From an indicator: its threat tags (a lead) and any direct actor attribution (evidence, via the graph’s ATTRIBUTED_TO edge), the attributed actor’s techniques/tactics, and other indicators sharing a tag. From an actor name or alias: exact-name then alias resolution, similarly-named candidates, the actor’s techniques/tactics, and every indicator this graph directly attributes to them, bounded and threat-checked.
This is the reference page: what each step asks the graph, and why. Run it on the Threat investigation use-case page.
On this page (4)
What it solves
A SOC analyst who gets a malicious verdict from an indicator workflow cannot ask "who, and what do they do" without writing Cypher by hand, and an intel analyst starting from an actor name has no graph-native way in at all — the retired actor-ttp workflow left this pivot with no direct equivalent.
Why
- 01Threat tags. A tag is a lead, not a named actor — this graph has no tag-to-actor edge (see below).
- 02Direct attribution. ATTRIBUTED_TO is the one edge this graph carries as evidence, not a lead.
- 03The attributed actor's techniques. Names what the attributed actor actually does, not just who they are.
- 04The attributed actor's tactics. An actor has no direct tactic edge — every tactic here is derived from a technique it uses.
- 05Indicators sharing a tag. A shared tag is a cluster lead — checked against the threat feeds next, not assumed malicious.
- 06Threat check on tag-sharing siblings. A coverage-qualified band, so a sibling with no feed history never reads as clean.
- 07Resolve by exact name. Actor names are exact and case-sensitive — tried before any alias or prefix candidate.
- 08Resolve by alias. Only runs when the exact name did not resolve — a known alias (case-sensitive) still finds the actor.
- 09Similar actor names. An indexed prefix scan — candidates to try next, never auto-resolved as a match.
- 10The actor's techniques. Both duplicate actor nodes are queried — a technique either twin uses still counts.
- 11The actor's tactics. The graph’s own current ATT&CK tactic ids — never a hard-coded tactic list.
- 12The actor's directly-attributed infrastructure. Bounded to 200 — the same ATTRIBUTED_TO edge the discovery form itself reads, not a malware-family pivot (see header).
- 13Threat check on the attributed infrastructure. A coverage-qualified band beside a named actor, not an unqualified "malicious" guess.
- 14ASN concentration. A shared ASN across several attributed IPs is itself an infrastructure signal.
What this cost
14 named steps across the threat-intel layer. The runner reports what each step returned, row by row, so the evidence and what it took to get it arrive together rather than as one number at the end.
How it uses the graph
Traverses the threat-intel layer of the graph, in 14 steps:
Reading threat tags…
Reading direct actor attribution…
Reading the attributed actor’s MITRE ATT&CK techniques…
Grouping techniques by tactic…
Finding other indicators sharing a tag…
Checking tag-sharing siblings against the threat feeds…
Resolving the exact actor name…
Checking alias membership…
Looking for similarly-named actors…
Reading the actor’s MITRE ATT&CK techniques…
Grouping the actor’s techniques by tactic…
Reading the actor’s directly-attributed infrastructure…
Checking the attributed infrastructure against the threat feeds…
Reading which networks concentrate the actor’s IP infrastructure…