Detect what conventional intelligence misses.Attribute what others cannot.
The Sovereignty Infinium's Threat Detection & Attribution capability detects adversary activity across seventeen threat categories, tracks advanced persistent threats, and produces structured attribution judgments on the Sherman Kent scale. It fuses surface, deep, dark, cyber, financial, broadcast, sensor, and HUMINT channels into a single threat picture — then delivers decision-grade intelligence at the tempo the threat operates at.
17 THREAT CATEGORIES
10 ATTRIBUTION METHODS
SHERMAN KENT CONFIDENCE
MITRE ATT&CK MAPPED
STIX/TAXII READY
The threat graph
Adversary · TTP · Infrastructure · Confidence
87% confidence
Sample attribution · Sherman Kent
ATT&CK-mapped TTPs
Infrastructure cluster
Confidence-weighted ring
10 attribution methods
Conventional threat intel operates at the wrong altitude.
It is either too high (vendor threat feeds delivering yesterday's indicators) or too low (SOC alerts delivering today's incidents but no context). The result is a strategic-operational gap: decision-makers know a campaign is happening but cannot answer the four questions that matter most — Who is doing this? What is their objective? What are they likely to do next? How confident are we?
Source fragmentation
Most threat teams subscribe to commercial feeds, run internal telemetry, monitor dark-web forums, and collect open-source indicators — each in a different tool, with different taxonomies, against different clocks
The platform unifies these into a single threat picture. A real threat produces signals across all four; a partial view misses the campaign
Attribution theater
Public "attribution" statements name a state actor without a structured confidence judgment, an analytic chain, or the underlying tradecraft evidence. This is not attribution. It is rhetoric
Decision-makers need attribution that survives audit, court, coalition, and the morning brief. 10 methods, multi-signal ensemble, full audit trail
Indicator myopia
IP addresses, hashes, and domains age out in days. Adversary tradecraft (TTPs) ages out in years. Most threat feeds are indicator-only; the tradecraft is missing
TTP mapping to MITRE ATT&CK. IOC extraction. IOA behavioral sequences. Tradecraft survives retooling
Discipline silos
A cyber operator sees an intrusion but not the deep-web chatter about the same actor. An OSINT analyst sees the chatter but not the IOC. A financial investigator sees the wallet movement but not the C2
A HUMINT source corroborates the rest but has no system to write into. The multi-INT graph resolves across every discipline
Attribution is not a name. It is a chain of evidence, a tradecraft pattern, a confidence judgment, and an audit trail. Anything less is theater.
A fusion capability, not a single tool.
Threat Detection & Attribution is the Sovereignty Infinium capability that detects adversary activity across seventeen threat categories, maps tradecraft to MITRE ATT&CK, maintains a structured APT registry, and produces auditable attribution judgments at strategic, operational, and tactical horizons.
The 17 threat categories
State-sponsored cyber attack
Non-state cyber attack
Physical attack / terrorism
Insurgent / paramilitary
Influence operation
Disinformation campaign
Foreign interference
Economic coercion / sanctions
Supply-chain disruption
Critical-infrastructure failure
Public-health emergency
Natural disaster
Climate / environmental shock
Market / financial shock
Reputational attack
Border / migration crisis
Diplomatic / political crisis
The 10 attribution methods
Applied in parallel, weighted ensemble, full audit trail
TTP matching (ATT&CK similarity)
Tool / malware signature
Infrastructure reuse (IP/domain/hosting)
Linguistic / cultural markers
Operational tempo and pattern-of-life
Past victimology
Ideological alignment
Timing / event correlation
Leak / insider claim
Multi-signal ensemble
The 10 threat actor classes
Multi-Factor Threat Score
Composite severity, 8 factors
Actor capability
Intent
Opportunity
Prior behavior
Infrastructure readiness
Target exposure
Propagation speed
Reversibility
The 10 vulnerability classes
Software (CVE, RCE, XSS, SQLi, SSRF)
Configuration
Network
Physical
Human
Process
Supply chain
Zero-day
N-day
AI/ML (adversarial, model inversion, prompt injection, training-data poisoning)
A seven-stage pipeline, with continuous feedback.
The capability operates as a seven-stage pipeline, with continuous feedback from later stages refining earlier ones. Every stage is auditable, provenance-tracked, and operator-reviewable.
Continuous multi-INT collection
Surface, deep, dark, cyber, financial, broadcast, sensor, HUMINT. Per-source reliability scored on the Admiralty scale at ingest.
Multi-modal processing
NLP in 17+ languages, computer vision, ASR, translation, knowledge-graph construction, deduplication, dedup-fencing.
Threat-specific detection models
17 categories each with a dedicated model stack. 10+ graph metrics. Anomaly detection per actor, sector, region. Bot/CIB + deepfake.
TTP mapping & indicator extraction
Tradecraft mapped to MITRE ATT&CK (Enterprise, ICS, Mobile, Containers). IOCs + IOAs + COAs.
Threat actor profiling
Each actor is a structured dossier. New signals update in real time. Cross-actor correlation identifies shared infrastructure, tooling, tradecraft.
Multi-method attribution
10 attribution methods applied in parallel. Each method produces a vote. Multi-signal ensemble produces a weighted vote with full audit trail.
Confidence judgment & product
Sherman Kent confidence (High/Medium/Low). Structured Analytic Techniques applied. Human-analyst review for every High-confidence attribution.
AI + human fusion for this capability
Task
AI
Human
Ingest 500M+ daily signals across 11+ source categories
✓
—
Translate and transcribe 17+ languages in real time
✓
—
Match TTPs to MITRE ATT&CK and to prior campaigns
✓
—
Detect IOCs, IOAs, and behavioral patterns at scale
✓
—
Cross-correlate indicators across INTs
✓
—
Generate candidate attribution hypotheses
✓
—
Apply ACH and other structured techniques to high-stakes judgments
—
✓
Make the call between High / Medium / Low confidence
—
✓
Sign off on a High-confidence attribution
—
✓
Counsel a decision-maker on the implications of an attribution
—
✓
Every High-confidence attribution has a named analyst owner, a documented analytic chain, and a defensible methodology. The platform does not hide its errors. Every alert is dispositioned and feeds the calibration loop.
Decision-grade output across the intelligence cycle.
Daily Threat Intelligence Brief
Campaign and indicator roll-up, sector- and region-filtered. 5 pages, SECRET-equivalent marking by default.
APT Dossier Update
Per-actor dossier refresh on new signal. Includes confidence delta.
Attribution Judgment
Structured product with executive summary, analytic chain, confidence level, alternative hypotheses considered.
Threat Hunt Hypothesis
Operational product for SOC and hunt teams. Includes ATT&CK TTPs, expected detection points, false-positive risks.
Vulnerability Advisory
CVE-class advisory with exploitation-context, target relevance, mitigation.
IOC Feed (STIX/TAXII)
Push feed in industry-standard formats.
Detection Rule Pack
YARA, Sigma, Snort, Suricata rules per threat, with deployment notes.
Strategic TI Assessment
Sector/regional/national-level assessment, monthly.
Key performance indicators
<60s
Detection latency (T+0 to first alert)
4h/24h/7d
Mean time to attribution (H/M/L)
<8%
False positive rate (calibrated)
≥85%
High-confidence judgments surviving analyst review
<1h
IOC freshness from first-observed to publication
≥92%
MITRE ATT&CK coverage in client environment
<6h
Dossier freshness (active APTs)
≥70%
Cross-INT corroboration rate (H-confidence)
Update frequencies
Real-time
Alerts
Sub-hour
Dossier updates
Daily
Briefs
Weekly
Tactical reports
Monthly
Strategic assessments
Quarterly
Threat landscape
Three threats, three attribution outcomes.
Scenario 01
APT Intrusion Pre-empted, 4 Days Before Exploitation
Situation
A tier-one asset at a critical-infrastructure operator was scheduled for a focused intrusion attempt. The asset was on a watchlist following a sector-wide campaign against similar targets. The conventional SOC saw no internal telemetry indicating preparation.
Challenge
Conventional threat feeds carried the post-exploit indicators (hashes, IPs) of the prior campaign, but the new campaign was a clean retool. No IOC overlap. The intelligence gap was in staging, not in exploitation.
Approach
The Sovereignty Infinium’s threat fusion engine correlated: (a) chatter on two dark-web forums referencing the target’s stack with specific tradecraft; (b) a new domain registered with infrastructure overlap to a previously-attributed actor (TTP-method #1, #3); (c) linguistic markers in forum posts consistent with a known actor’s native-language style (TTP-method #4); (d) timing correlation with a strategic event in the target’s sector (TTP-method #8). The multi-signal ensemble produced a candidate attribution. Confidence: 87% (High).
Outcome
The asset team was notified 4 days before the exploitation attempt. The staging infrastructure was pre-emptively blocked. The exploitation attempt never reached initial access. Zero operational impact.
Lessons
Indicator-only detection misses retooled campaigns. Tradecraft correlation across INTs catches what indicators cannot. The 4-day lead was the difference between a control-room exercise and a regulator-reportable incident.
Scenario 02
Sanctions-Evasion Network Mapped Across Three Jurisdictions
Situation
A sanctioned entity was suspected of operating through a layered corporate structure spanning three jurisdictions. The conventional CTI picture showed the surface shell companies; the financial picture showed the wires. Neither view showed the connection.
Challenge
Three different data domains — corporate registry, financial flow, cyber chatter — each with its own tool, its own analyst, its own clock. The intel gap was in the seam between them.
Approach
The platform’s cross-INT entity resolution linked the corporate shells to the financial flows via shared identifiers, to the cyber chatter via tradecraft overlap, and to a known state-tolerated actor (TTP-method #9 corroborating). The Multi-Factor Threat Score classified the cluster as economic-coercion-grade (threat category 8) with propagation speed ‘fast’ and reversibility ‘low.’
Outcome
A sanctions-evasion dossier was delivered to the client within 9 days of the first signal. The dossier was used in a multilateral designation process. Network disruption commenced 14 days after dossier delivery.
Lessons
Sanctions evasion is a cross-domain problem. Domain-specific tools produce domain-specific blind spots. Fusion is not a feature; it is the requirement.
Scenario 03
Coordinated Influence Operation Pre-staged, 6 Weeks Before Launch
Situation
A state’s election cycle was 6 months out. Conventional threat teams were focused on election-day operations. The Sovereignty Infinium’s threat fusion engine detected an asset-creation pattern on fringe platforms consistent with pre-launch influence-operation tradecraft.
Challenge
Pre-launch activity produces no operational signal — no influence, no amplification, no measurable effect. Most detection systems are tuned to operational-phase signal and miss the reconnaissance.
Approach
The platform’s campaign-anatomy model (recon → launch → propagation → mutation → convergence → saturation → decay) flagged the pre-launch phase. Network analysis on the fringe accounts identified hub-spoke topology. Linguistic markers in account bios and posts were consistent with a known state-tolerated actor’s content style (TTP-method #4, #7). TTP-method #8 (timing correlation) confirmed alignment with a strategic interest. Confidence: 76% (Medium).
Outcome
A 6-week pre-launch warning was issued. The client activated an inoculation campaign (CM-01: pre-bunk). At operational launch, the targeted audience was already inoculated. Reach of the operation was limited to a fraction of projected baseline.
Lessons
Influence operations are most vulnerable before launch. Detection that focuses on operational-phase signal surrenders the lead time that makes inoculation possible.
The connective tissue of the platform.
Threat Detection & Attribution is the connective tissue of the platform. It does not operate in isolation; it amplifies and is amplified by the other capabilities.
Cyber Threat Intelligence (Capability 10)
Provides the IOC, IOA, TTP, and detection-rule layer. The Cyber TI capability operates on the same adversary graph, the same ATT&CK mapping, the same confidence framework. STIX/TAXII exchange is bi-directional.
Disinformation & Influence Operations (Capability 6)
Provides the campaign-anatomy model, the bot/CIB detection, the deepfake detection, and the counter-narrative playbook. Threat Detection & Attribution maps influence operations to threat-actor dossiers, providing the "who" behind the "what."
Geopolitical Foresight (Capability 8)
Provides strategic context for attribution. A campaign that aligns with a known state's strategic interest carries a different confidence weight than a campaign that does not. TTP-method #8 is, in effect, geopolitical input.
Financial & Economic Intelligence (Capability 11)
Sanctions-evasion mapping, illicit financial flows, corporate-disclosure monitoring, and sovereign credit signals feed the economic-coercion threat category (8) and the market-shock category (14).
Media Intelligence (Capability 7)
Provides the cross-language, cross-platform visibility that detects the operational-phase signal of an influence operation.
Reputation & Perception (Capability 4)
Tracks the impact of a threat-actor campaign on the client's perception. Tracks whether the campaign achieved its effect.
Predictive Foresight (Capability 2)
Threat Detection & Attribution produces the "now" picture. Predictive Foresight produces the "next" picture. The handoff is the tradecraft evolution trajectory: what an actor did, what they are likely to do next, on what horizon.
Command Center & War Room (Capability 13)
All alerts route through the Command Center. Sub-second alerting on 8 notification channels. Crisis workflows for the 6 canonical crisis types.
The Pattern
From capable tools to one intelligence system.
Threat Detection & Attribution is what makes the other capabilities fused rather than stitched. Without it, the platform is a stack of capable tools. With it, the platform is one intelligence system.
Honest boundaries.
Honesty is a feature. Threat Detection & Attribution has real limits, and we name them.
01
Attribution confidence is not certainty. A High-confidence attribution is a structured judgment, not a court-of-law finding. Confidence is documented, the analytic chain is documented, alternative hypotheses are documented. The platform never presents attribution as infallible.
02
Detection is not prevention. Detecting a campaign 6 weeks early provides the time to act; it does not itself constitute action. The platform delivers intelligence. The client decides. The decision is theirs.
03
Data quality matters. Detection accuracy depends on the breadth, freshness, and quality of source data. We commit to specific source coverage (11+ source categories, 47+ platforms, 200+ geographies, 17+ languages). Coverage gaps produce detection gaps. We disclose coverage on request.
04
Tuned vs. un-tuned deployments. A fresh deployment requires a calibration period. False-positive rates in the first 30 days are typically higher than steady-state. We commit to <8% at steady state; we do not commit to <8% in week 1.
05
Adversary adaptation is a moving target. Adversaries adapt. Detection models must be re-trained. The platform’s continuous validation cycle is the response; it is not a guarantee.
06
Some capabilities are subject to national export controls. Attribution tooling, certain IOC/IOA products, and certain detection models may be subject to export-control regimes. We do not deploy restricted capabilities to non-eligible jurisdictions.
07
Model accuracy varies by task and data quality. Sentiment analysis is more accurate in well-resourced languages than in low-resource languages. ATT&CK mapping is more accurate against documented tradecraft than against novel tradecraft. Confidence intervals vary by task; we publish them.
08
Confidence levels follow the Sherman Kent scale. High does not mean certain. It means a structured judgment supported by strong evidence, multiple independent methods, and surviving structured analytic techniques. Medium and Low are documented judgments, not failures of process.
09
False positives are not bugs. They are the cost of detection at the leading edge. We tune; we do not promise zero.
See how attribution is built — not asserted.
A 60-minute confidential briefing. With a Sovereignty Infinium principal. We will walk through an anonymized attribution end-to-end, show the analytic chain, the confidence judgment, the alternative hypotheses, and the tradecraft evidence. We will not pitch.
- Response within 1 business day
- Mutual NDA · no obligation
- Under your security protocols
Or write to briefing@sovereignty.co.in
What you walk away with
An attribution, with the chain shown.
- We pick an anonymized adversary cluster
- We run the 10 attribution methods in parallel
- You see the analytic chain, not just the headline
- We show alternative hypotheses considered and rejected