Managing the Deprecation of Threat Actor Aliases

Managing the Deprecation of Threat Actor Aliases

Source: YouTube · SANS Digital Forensics and Incident Response · published Apr 2, 2026 · 29:29

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The speaker critiques the current attribution system, arguing that naming convention conflicts stem from structural issues rather than individual researcher errors 0:28.

Key Takeaways:
• The presentation focuses on attribution and the problems within threat actor naming conventions 0:22.
• Current issues regarding deconfliction and retirement of names reflect broader structural flaws in the industry 0:32.
• These structural problems are not the fault of any single company, group, or researcher but are a systemic challenge 0:40.
• The field must learn to contend with these inherent structural factors to improve attribution accuracy 0:45.

The talk highlights the need for systemic solutions to attribution challenges.

Sources:

  • 0:22 Introduction to the topic of attribution.
  • 0:28 Positing structural issues in naming conventions.
  • 0:32 Discussing deconfliction and retirement of names.
  • 0:40 Clarifying that issues are systemic, not individual fault.
  • 0:45 Emphasizing the need to adapt to these structural factors.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Good afternoon everyone. Hope everyone's having a good day. Enjoyed the talks for the last few days. I for one am very grateful to be here to present for you today, as well as to be going towards the end of the day on day two because it means I can draw a lot of great inspiration from some of these fantastic talks that we've heard over these two days. So, today I want to talk about attribution. Specifically, I'd like to posit that our current system for managing threat actor naming conventions, specifically around deconfliction and naming convention retirement, reflect broader structural issues that again are not the fault of any particular company, group of researchers, or anyone in particular, but rather a factor that we have to learn how to contend with and create problems that we learn…