What problem does it solve? Determining who is behind a cyber attack is error-prone: shared infrastructure, commodity tooling, and false flags routinely cause misattribution. This Skill provides a rigorous methodology for threat attribution that grades evidence strength, prevents overclaiming, and produces defensible, confidence-rated conclusions. ## Core Features & Use Cases - Diamond Model Analysis: Maps adversary, capability, infrastructure, and victim corners to identify attribution gaps and structure multi-event correlation. - Infrastructure Graphing: Clusters C2 domains, IPs, and certificates using whois, certificate transparency (crt.sh), dnsx, and networkx to distinguish control-plane from shared-plane evidence. - Confidence Grading & Reporting: Applies a three-tier confidence scale (low/medium/high) with strict wording rules, counter-evidence tracking, and a sanitized report template. - Use Case: Given several intrusion events sharing C2 domains, correlate registration data, certificate reuse, and unique malware strings to determine whether they form one campaign and issue a "suspected same activity" statement with documented evidence chains. ## Quick Start Use the re-attribution skill to analyze these C2 domains and malware samples, build an infrastructure graph, and produce a confidence-graded attribution report.