@C2IRIS High-confidence threat actor attribution will largely dismiss these static artifacts though. TTPs, code/infra reuse, working time zones and cui bono are higher fidelity than metadata and typos.
@C2IRIS The bar for developing critical 0-days is continually being raised. I would rather have foreign adversaries exploit n-days than 0-days. Technology has become more resilient because of security researchers. Would be interesting study to see where KEV list CVEs originated from
@polyfactual This works only if the implied probabilities are mispriced. If the 80-90 contract truly reflects the base rate, it is EV neutral. You still need informational or modeling edge.
I've been developing an experimental platform for clustering IOCs to reduce fragmentation in threat actor naming conventions combining OPRF cryptographic primitives, roaring bitmaps and Leiden clustering
@willcb New data is likely to be higher quality and more original now that LLMs can address most user queries, which will reduce the need for people to rehash existing information.