# Threat Actor Attribution

> Reads the threat-attribution layer (actors, MITRE ATT&CK techniques and tactics, threat tags) straight off the graph. From an indicator: its threat tags (a lead) and any direct actor attribution (evidence, via the graph’s ATTRIBUTED_TO edge), the attributed actor’s techniques/tactics, and other indicators sharing a tag. From an actor name or alias: exact-name then alias resolution, similarly-named candidates, the actor’s techniques/tactics, and every indicator this graph directly attributes to them, bounded and threat-checked.

*Source: https://www.whisper.security/docs/workflows/threat-actor-attribution*

---
## What it solves

A SOC analyst who gets a malicious verdict from an indicator workflow cannot ask "who, and what do they do" without writing Cypher by hand, and an intel analyst starting from an actor name has no graph-native way in at all — the retired actor-ttp workflow left this pivot with no direct equivalent.

## How it uses the graph

Traverses the threat-intel layer of the graph, in 14 steps:

01. **Threat tags** _(threat-intel)_ — Reading threat tags…
02. **Direct attribution** _(threat-intel)_ — Reading direct actor attribution…
03. **The attributed actor's techniques** _(threat-intel)_ — Reading the attributed actor’s MITRE ATT&CK techniques…
04. **The attributed actor's tactics** _(threat-intel)_ — Grouping techniques by tactic…
05. **Indicators sharing a tag** _(threat-intel)_ — Finding other indicators sharing a tag…
06. **Threat check on tag-sharing siblings** _(threat-intel)_ — Checking tag-sharing siblings against the threat feeds…
07. **Resolve by exact name** _(threat-intel)_ — Resolving the exact actor name…
08. **Resolve by alias** _(threat-intel)_ — Checking alias membership…
09. **Similar actor names** _(threat-intel)_ — Looking for similarly-named actors…
10. **The actor's techniques** _(threat-intel)_ — Reading the actor’s MITRE ATT&CK techniques…
11. **The actor's tactics** _(threat-intel)_ — Grouping the actor’s techniques by tactic…
12. **The actor's directly-attributed infrastructure** _(threat-intel)_ — Reading the actor’s directly-attributed infrastructure…
13. **Threat check on the attributed infrastructure** _(threat-intel)_ — Checking the attributed infrastructure against the threat feeds…
14. **ASN concentration** _(threat-intel)_ — Reading which networks concentrate the actor’s IP infrastructure…

## Why each step runs

1. **Threat tags.** A tag is a lead, not a named actor — this graph has no tag-to-actor edge (see below).
2. **Direct attribution.** ATTRIBUTED_TO is the one edge this graph carries as evidence, not a lead.
3. **The attributed actor's techniques.** Names what the attributed actor actually does, not just who they are.
4. **The attributed actor's tactics.** An actor has no direct tactic edge — every tactic here is derived from a technique it uses.
5. **Indicators sharing a tag.** A shared tag is a cluster lead — checked against the threat feeds next, not assumed malicious.
6. **Threat check on tag-sharing siblings.** A coverage-qualified band, so a sibling with no feed history never reads as clean.
7. **Resolve by exact name.** Actor names are exact and case-sensitive — tried before any alias or prefix candidate.
8. **Resolve by alias.** Only runs when the exact name did not resolve — a known alias (case-sensitive) still finds the actor.
9. **Similar actor names.** An indexed prefix scan — candidates to try next, never auto-resolved as a match.
10. **The actor's techniques.** Both duplicate actor nodes are queried — a technique either twin uses still counts.
11. **The actor's tactics.** The graph’s own current ATT&CK tactic ids — never a hard-coded tactic list.
12. **The actor's directly-attributed infrastructure.** Bounded to 200 — the same ATTRIBUTED_TO edge the discovery form itself reads, not a malware-family pivot (see header).
13. **Threat check on the attributed infrastructure.** A coverage-qualified band beside a named actor, not an unqualified "malicious" guess.
14. **ASN concentration.** A shared ASN across several attributed IPs is itself an infrastructure signal.

[Open the full use-case page, with the live runner](/products/intelligence/use-cases/threat-investigation/threat-actor-attribution)
