Skip to content

Attribution

Definition

The process of identifying the threat actor responsible for a cyberattack. Attribution is a confidence-weighted analytical conclusion, not a binary fact. It ranges from technical attribution (identifying the machine or infrastructure used) to legal attribution (establishing criminal or state responsibility in a court or diplomatic context).

Definition
Identifying the threat actor responsible for a cyberattack
Nature
Confidence-weighted analytical conclusion, not a binary fact
Technical level
Identifying the machine or infrastructure used
Legal level
Establishing criminal or state responsibility

Common questions

Why is attribution described as confidence-weighted rather than certain?+

Evidence such as IP addresses, malware code reuse, and infrastructure overlap can be spoofed, shared, or planted by a different actor to mislead investigators, so analysts express conclusions with a stated confidence level rather than treating any single indicator as proof.

Why does technical attribution not automatically support legal attribution?+

Identifying the infrastructure or tooling used in an attack shows how it was carried out but does not by itself meet the evidentiary or diplomatic standard needed to hold a specific individual, organisation, or state legally or politically responsible, which typically requires corroborating intelligence beyond the technical trail.

Related terms

Confidence Level
An explicit label attached to an attribution assessment indicating how strongly the available evidence supports the conclusion. Standard tiers are low, medium,...
False Flag
A deliberate deception in which an attacker plants indicators designed to make the intrusion appear to originate from a different actor. Common...
Technical vs Legal Attribution
Technical attribution identifies the infrastructure and tooling used in an attack and may link it to a known cluster or actor profile....
Threat Actor Cluster
A named collection of observed activity linked by shared infrastructure, malware, and TTPs, without necessarily having confirmed the real-world identity of the...
TTPs (Tactics, Techniques, and Procedures)
The behavioural fingerprint of a threat actor: the broad goals and approaches they pursue (tactics), the specific methods they use to achieve...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.