A SOC analyst correlates EDR telemetry showing LSASS access, scheduled-task persistence, and SMB lateral movement. Threat intel reports a named group uses similar TTPs, but another group shares them. To enrich the incident with likely technique families, which approach is most reliable?
Select an answer to reveal the explanation.
Short Explanation
Think of group names like license plates: they can point to a suspect, but the TTPs are the actual behavior at the scene. You should map the observed techniques first, then use attribution as supporting context. If you let the label drive the hunt, you might miss shared tradecraft and chase the wrong story.
Full Explanation
Attack methodology frameworks such as MITRE ATT&CK organize adversary behavior into tactics, techniques, and procedures, making observed artifacts the most dependable basis for enrichment. When endpoint and network telemetry already show credential access, persistence, and lateral movement, those behaviors can be mapped directly to technique families, while group attribution can suggest likely variants or campaign context. Attribution is useful when it helps prioritize hunting hypotheses, correlate historical activity, or anticipate follow-on behavior, but it should not override direct evidence because different groups can reuse commodity tools and public tradecraft. A named-group label is weaker than TTP evidence when multiple groups share common techniques, because labels often reflect reporting conventions, tool overlap, or incomplete intelligence rather than a unique signature. Relying only on a feed label can misclassify activity and hide techniques that do not fit the assumed group. Inventing a group label from one alert creates confirmation bias and fragments analysis, weakening traceability to artifacts and validated intelligence. Exam caveat: choose the approach that treats ATT&CK or TTP mapping as the primary enrichment method and group attribution as corroborating context. Operational check: normalize each alert into ATT&CK technique IDs, then compare the resulting technique set with the named group's documented profile before updating the incident record.