Skip to content
Workflows
Skip navigation
Workflows
View as Markdown

Threat Actor Attribution

Reads the threat-attribution layer (actors, MITRE ATT&CK techniques and tactics, threat tags) straight off the graph. From an indicator: its threat tags (a lead) and any direct actor attribution (evidence, via the graph’s ATTRIBUTED_TO edge), the attributed actor’s techniques/tactics, and other indicators sharing a tag. From an actor name or alias: exact-name then alias resolution, similarly-named candidates, the actor’s techniques/tactics, and every indicator this graph directly attributes to them, bounded and threat-checked.

Published

This is the reference page: what each step asks the graph, and why. Run it on the Threat investigation use-case page.

On this page (4)

What it solves

A SOC analyst who gets a malicious verdict from an indicator workflow cannot ask "who, and what do they do" without writing Cypher by hand, and an intel analyst starting from an actor name has no graph-native way in at all — the retired actor-ttp workflow left this pivot with no direct equivalent.

Why

  1. 01Threat tags. A tag is a lead, not a named actor — this graph has no tag-to-actor edge (see below).
  2. 02Direct attribution. ATTRIBUTED_TO is the one edge this graph carries as evidence, not a lead.
  3. 03The attributed actor's techniques. Names what the attributed actor actually does, not just who they are.
  4. 04The attributed actor's tactics. An actor has no direct tactic edge — every tactic here is derived from a technique it uses.
  5. 05Indicators sharing a tag. A shared tag is a cluster lead — checked against the threat feeds next, not assumed malicious.
  6. 06Threat check on tag-sharing siblings. A coverage-qualified band, so a sibling with no feed history never reads as clean.
  7. 07Resolve by exact name. Actor names are exact and case-sensitive — tried before any alias or prefix candidate.
  8. 08Resolve by alias. Only runs when the exact name did not resolve — a known alias (case-sensitive) still finds the actor.
  9. 09Similar actor names. An indexed prefix scan — candidates to try next, never auto-resolved as a match.
  10. 10The actor's techniques. Both duplicate actor nodes are queried — a technique either twin uses still counts.
  11. 11The actor's tactics. The graph’s own current ATT&CK tactic ids — never a hard-coded tactic list.
  12. 12The actor's directly-attributed infrastructure. Bounded to 200 — the same ATTRIBUTED_TO edge the discovery form itself reads, not a malware-family pivot (see header).
  13. 13Threat check on the attributed infrastructure. A coverage-qualified band beside a named actor, not an unqualified "malicious" guess.
  14. 14ASN concentration. A shared ASN across several attributed IPs is itself an infrastructure signal.

What this cost

14 named steps across the threat-intel layer. The runner reports what each step returned, row by row, so the evidence and what it took to get it arrive together rather than as one number at the end.

How it uses the graph

Traverses the threat-intel layer of the graph, in 14 steps:

How it walks the graph14 steps
01Threat tags

Reading threat tags…

threat-intel
02Direct attribution

Reading direct actor attribution…

threat-intel
03The attributed actor's techniques

Reading the attributed actor’s MITRE ATT&CK techniques…

threat-intel
04The attributed actor's tactics

Grouping techniques by tactic…

threat-intel
05Indicators sharing a tag

Finding other indicators sharing a tag…

threat-intel
06Threat check on tag-sharing siblings

Checking tag-sharing siblings against the threat feeds…

threat-intel
07Resolve by exact name

Resolving the exact actor name…

threat-intel
08Resolve by alias

Checking alias membership…

threat-intel
09Similar actor names

Looking for similarly-named actors…

threat-intel
10The actor's techniques

Reading the actor’s MITRE ATT&CK techniques…

threat-intel
11The actor's tactics

Grouping the actor’s techniques by tactic…

threat-intel
12The actor's directly-attributed infrastructure

Reading the actor’s directly-attributed infrastructure…

threat-intel
13Threat check on the attributed infrastructure

Checking the attributed infrastructure against the threat feeds…

threat-intel
14ASN concentration

Reading which networks concentrate the actor’s IP infrastructure…

threat-intel