
Managing the Deprecation of Threat Actor Aliases
Source: YouTube · SANS Digital Forensics and Incident Response · published Apr 2, 2026 · 29:29
The speaker critiques the current attribution system, arguing that naming convention conflicts stem from structural issues rather than individual researcher errors 0:28.
Key Takeaways:
• The presentation focuses on attribution and the problems within threat actor naming conventions 0:22.
• Current issues regarding deconfliction and retirement of names reflect broader structural flaws in the industry 0:32.
• These structural problems are not the fault of any single company, group, or researcher but are a systemic challenge 0:40.
• The field must learn to contend with these inherent structural factors to improve attribution accuracy 0:45.
The talk highlights the need for systemic solutions to attribution challenges.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Good afternoon everyone. Hope everyone's having a good day. Enjoyed the talks for the last few days. I for one am very grateful to be here to present for you today, as well as to be going towards the end of the day on day two because it means I can draw a lot of great inspiration from some of these fantastic talks that we've heard over these two days. So, today I want to talk about attribution. Specifically, I'd like to posit that our current system for managing threat actor naming conventions, specifically around deconfliction and naming convention retirement, reflect broader structural issues that again are not the fault of any particular company, group of researchers, or anyone in particular, but rather a factor that we have to learn how to contend with and create problems that we learn…