CAPABILITIES / THREAT DETECTION & ATTRIBUTION

Detect what conventional intelligence misses.Attribute what others cannot.

The Sovereignty Infinium's Threat Detection & Attribution capability detects adversary activity across seventeen threat categories, tracks advanced persistent threats, and produces structured attribution judgments on the Sherman Kent scale. It fuses surface, deep, dark, cyber, financial, broadcast, sensor, and HUMINT channels into a single threat picture — then delivers decision-grade intelligence at the tempo the threat operates at.

17 THREAT CATEGORIES

10 ATTRIBUTION METHODS

SHERMAN KENT CONFIDENCE

MITRE ATT&CK MAPPED

STIX/TAXII READY

The threat graph

Adversary · TTP · Infrastructure · Confidence

87% confidence

Sample attribution · Sherman Kent

ATT&CK-mapped TTPs

Infrastructure cluster

Confidence-weighted ring

10 attribution methods

The Problem

Conventional threat intel operates at the wrong altitude.

It is either too high (vendor threat feeds delivering yesterday's indicators) or too low (SOC alerts delivering today's incidents but no context). The result is a strategic-operational gap: decision-makers know a campaign is happening but cannot answer the four questions that matter most — Who is doing this? What is their objective? What are they likely to do next? How confident are we?

Source fragmentation

Most threat teams subscribe to commercial feeds, run internal telemetry, monitor dark-web forums, and collect open-source indicators — each in a different tool, with different taxonomies, against different clocks

The platform unifies these into a single threat picture. A real threat produces signals across all four; a partial view misses the campaign

Attribution theater

Public "attribution" statements name a state actor without a structured confidence judgment, an analytic chain, or the underlying tradecraft evidence. This is not attribution. It is rhetoric

Decision-makers need attribution that survives audit, court, coalition, and the morning brief. 10 methods, multi-signal ensemble, full audit trail

Indicator myopia

IP addresses, hashes, and domains age out in days. Adversary tradecraft (TTPs) ages out in years. Most threat feeds are indicator-only; the tradecraft is missing

TTP mapping to MITRE ATT&CK. IOC extraction. IOA behavioral sequences. Tradecraft survives retooling

Discipline silos

A cyber operator sees an intrusion but not the deep-web chatter about the same actor. An OSINT analyst sees the chatter but not the IOC. A financial investigator sees the wallet movement but not the C2

A HUMINT source corroborates the rest but has no system to write into. The multi-INT graph resolves across every discipline

Attribution is not a name. It is a chain of evidence, a tradecraft pattern, a confidence judgment, and an audit trail. Anything less is theater.

The Capability

A fusion capability, not a single tool.

Threat Detection & Attribution is the Sovereignty Infinium capability that detects adversary activity across seventeen threat categories, maps tradecraft to MITRE ATT&CK, maintains a structured APT registry, and produces auditable attribution judgments at strategic, operational, and tactical horizons.

The 17 threat categories

1

State-sponsored cyber attack

2

Non-state cyber attack

3

Physical attack / terrorism

4

Insurgent / paramilitary

5

Influence operation

6

Disinformation campaign

7

Foreign interference

8

Economic coercion / sanctions

9

Supply-chain disruption

10

Critical-infrastructure failure

11

Public-health emergency

12

Natural disaster

13

Climate / environmental shock

14

Market / financial shock

15

Reputational attack

16

Border / migration crisis

17

Diplomatic / political crisis

The 10 attribution methods

Applied in parallel, weighted ensemble, full audit trail

1

TTP matching (ATT&CK similarity)

2

Tool / malware signature

3

Infrastructure reuse (IP/domain/hosting)

4

Linguistic / cultural markers

5

Operational tempo and pattern-of-life

6

Past victimology

7

Ideological alignment

8

Timing / event correlation

9

Leak / insider claim

10

Multi-signal ensemble

The 10 threat actor classes

StateState-sponsoredState-toleratedNon-state ideologicalNon-state politicalNon-state criminalNon-state hacktivistInsiderHybridIndividual

Multi-Factor Threat Score

Composite severity, 8 factors

Actor capability

Intent

Opportunity

Prior behavior

Infrastructure readiness

Target exposure

Propagation speed

Reversibility

The 10 vulnerability classes

01

Software (CVE, RCE, XSS, SQLi, SSRF)

02

Configuration

03

Network

04

Physical

05

Human

06

Process

07

Supply chain

08

Zero-day

09

N-day

10

AI/ML (adversarial, model inversion, prompt injection, training-data poisoning)

The Mechanism

A seven-stage pipeline, with continuous feedback.

The capability operates as a seven-stage pipeline, with continuous feedback from later stages refining earlier ones. Every stage is auditable, provenance-tracked, and operator-reviewable.

1

Continuous multi-INT collection

Surface, deep, dark, cyber, financial, broadcast, sensor, HUMINT. Per-source reliability scored on the Admiralty scale at ingest.

2

Multi-modal processing

NLP in 17+ languages, computer vision, ASR, translation, knowledge-graph construction, deduplication, dedup-fencing.

3

Threat-specific detection models

17 categories each with a dedicated model stack. 10+ graph metrics. Anomaly detection per actor, sector, region. Bot/CIB + deepfake.

4

TTP mapping & indicator extraction

Tradecraft mapped to MITRE ATT&CK (Enterprise, ICS, Mobile, Containers). IOCs + IOAs + COAs.

5

Threat actor profiling

Each actor is a structured dossier. New signals update in real time. Cross-actor correlation identifies shared infrastructure, tooling, tradecraft.

6

Multi-method attribution

10 attribution methods applied in parallel. Each method produces a vote. Multi-signal ensemble produces a weighted vote with full audit trail.

7

Confidence judgment & product

Sherman Kent confidence (High/Medium/Low). Structured Analytic Techniques applied. Human-analyst review for every High-confidence attribution.

AI + human fusion for this capability

Ingest 500M+ daily signals across 11+ source categories

Translate and transcribe 17+ languages in real time

Match TTPs to MITRE ATT&CK and to prior campaigns

Detect IOCs, IOAs, and behavioral patterns at scale

Cross-correlate indicators across INTs

Generate candidate attribution hypotheses

Apply ACH and other structured techniques to high-stakes judgments

Make the call between High / Medium / Low confidence

Sign off on a High-confidence attribution

Counsel a decision-maker on the implications of an attribution

Every High-confidence attribution has a named analyst owner, a documented analytic chain, and a defensible methodology. The platform does not hide its errors. Every alert is dispositioned and feeds the calibration loop.

Outputs

Decision-grade output across the intelligence cycle.

Daily Threat Intelligence Brief

Campaign and indicator roll-up, sector- and region-filtered. 5 pages, SECRET-equivalent marking by default.

APT Dossier Update

Per-actor dossier refresh on new signal. Includes confidence delta.

Attribution Judgment

Structured product with executive summary, analytic chain, confidence level, alternative hypotheses considered.

Threat Hunt Hypothesis

Operational product for SOC and hunt teams. Includes ATT&CK TTPs, expected detection points, false-positive risks.

Vulnerability Advisory

CVE-class advisory with exploitation-context, target relevance, mitigation.

IOC Feed (STIX/TAXII)

Push feed in industry-standard formats.

Detection Rule Pack

YARA, Sigma, Snort, Suricata rules per threat, with deployment notes.

Strategic TI Assessment

Sector/regional/national-level assessment, monthly.

Key performance indicators

<60s

Detection latency (T+0 to first alert)

4h/24h/7d

Mean time to attribution (H/M/L)

<8%

False positive rate (calibrated)

≥85%

High-confidence judgments surviving analyst review

<1h

IOC freshness from first-observed to publication

≥92%

MITRE ATT&CK coverage in client environment

<6h

Dossier freshness (active APTs)

≥70%

Cross-INT corroboration rate (H-confidence)

Update frequencies

Real-time

Alerts

Sub-hour

Dossier updates

Daily

Briefs

Weekly

Tactical reports

Monthly

Strategic assessments

Quarterly

Threat landscape

Anonymized Use Cases

Three threats, three attribution outcomes.

Scenario 01

APT Intrusion Pre-empted, 4 Days Before Exploitation

Situation

A tier-one asset at a critical-infrastructure operator was scheduled for a focused intrusion attempt. The asset was on a watchlist following a sector-wide campaign against similar targets. The conventional SOC saw no internal telemetry indicating preparation.

Challenge

Conventional threat feeds carried the post-exploit indicators (hashes, IPs) of the prior campaign, but the new campaign was a clean retool. No IOC overlap. The intelligence gap was in staging, not in exploitation.

Approach

The Sovereignty Infinium’s threat fusion engine correlated: (a) chatter on two dark-web forums referencing the target’s stack with specific tradecraft; (b) a new domain registered with infrastructure overlap to a previously-attributed actor (TTP-method #1, #3); (c) linguistic markers in forum posts consistent with a known actor’s native-language style (TTP-method #4); (d) timing correlation with a strategic event in the target’s sector (TTP-method #8). The multi-signal ensemble produced a candidate attribution. Confidence: 87% (High).

Outcome

The asset team was notified 4 days before the exploitation attempt. The staging infrastructure was pre-emptively blocked. The exploitation attempt never reached initial access. Zero operational impact.

Lessons

Indicator-only detection misses retooled campaigns. Tradecraft correlation across INTs catches what indicators cannot. The 4-day lead was the difference between a control-room exercise and a regulator-reportable incident.

Scenario 02

Sanctions-Evasion Network Mapped Across Three Jurisdictions

Situation

A sanctioned entity was suspected of operating through a layered corporate structure spanning three jurisdictions. The conventional CTI picture showed the surface shell companies; the financial picture showed the wires. Neither view showed the connection.

Challenge

Three different data domains — corporate registry, financial flow, cyber chatter — each with its own tool, its own analyst, its own clock. The intel gap was in the seam between them.

Approach

The platform’s cross-INT entity resolution linked the corporate shells to the financial flows via shared identifiers, to the cyber chatter via tradecraft overlap, and to a known state-tolerated actor (TTP-method #9 corroborating). The Multi-Factor Threat Score classified the cluster as economic-coercion-grade (threat category 8) with propagation speed ‘fast’ and reversibility ‘low.’

Outcome

A sanctions-evasion dossier was delivered to the client within 9 days of the first signal. The dossier was used in a multilateral designation process. Network disruption commenced 14 days after dossier delivery.

Lessons

Sanctions evasion is a cross-domain problem. Domain-specific tools produce domain-specific blind spots. Fusion is not a feature; it is the requirement.

Scenario 03

Coordinated Influence Operation Pre-staged, 6 Weeks Before Launch

Situation

A state’s election cycle was 6 months out. Conventional threat teams were focused on election-day operations. The Sovereignty Infinium’s threat fusion engine detected an asset-creation pattern on fringe platforms consistent with pre-launch influence-operation tradecraft.

Challenge

Pre-launch activity produces no operational signal — no influence, no amplification, no measurable effect. Most detection systems are tuned to operational-phase signal and miss the reconnaissance.

Approach

The platform’s campaign-anatomy model (recon → launch → propagation → mutation → convergence → saturation → decay) flagged the pre-launch phase. Network analysis on the fringe accounts identified hub-spoke topology. Linguistic markers in account bios and posts were consistent with a known state-tolerated actor’s content style (TTP-method #4, #7). TTP-method #8 (timing correlation) confirmed alignment with a strategic interest. Confidence: 76% (Medium).

Outcome

A 6-week pre-launch warning was issued. The client activated an inoculation campaign (CM-01: pre-bunk). At operational launch, the targeted audience was already inoculated. Reach of the operation was limited to a fraction of projected baseline.

Lessons

Influence operations are most vulnerable before launch. Detection that focuses on operational-phase signal surrenders the lead time that makes inoculation possible.

How It Fits

The connective tissue of the platform.

Threat Detection & Attribution is the connective tissue of the platform. It does not operate in isolation; it amplifies and is amplified by the other capabilities.

Cyber Threat Intelligence (Capability 10)

Provides the IOC, IOA, TTP, and detection-rule layer. The Cyber TI capability operates on the same adversary graph, the same ATT&CK mapping, the same confidence framework. STIX/TAXII exchange is bi-directional.

Disinformation & Influence Operations (Capability 6)

Provides the campaign-anatomy model, the bot/CIB detection, the deepfake detection, and the counter-narrative playbook. Threat Detection & Attribution maps influence operations to threat-actor dossiers, providing the "who" behind the "what."

Geopolitical Foresight (Capability 8)

Provides strategic context for attribution. A campaign that aligns with a known state's strategic interest carries a different confidence weight than a campaign that does not. TTP-method #8 is, in effect, geopolitical input.

Financial & Economic Intelligence (Capability 11)

Sanctions-evasion mapping, illicit financial flows, corporate-disclosure monitoring, and sovereign credit signals feed the economic-coercion threat category (8) and the market-shock category (14).

Media Intelligence (Capability 7)

Provides the cross-language, cross-platform visibility that detects the operational-phase signal of an influence operation.

Reputation & Perception (Capability 4)

Tracks the impact of a threat-actor campaign on the client's perception. Tracks whether the campaign achieved its effect.

Predictive Foresight (Capability 2)

Threat Detection & Attribution produces the "now" picture. Predictive Foresight produces the "next" picture. The handoff is the tradecraft evolution trajectory: what an actor did, what they are likely to do next, on what horizon.

Command Center & War Room (Capability 13)

All alerts route through the Command Center. Sub-second alerting on 8 notification channels. Crisis workflows for the 6 canonical crisis types.

The Pattern

From capable tools to one intelligence system.

Threat Detection & Attribution is what makes the other capabilities fused rather than stitched. Without it, the platform is a stack of capable tools. With it, the platform is one intelligence system.

What It Does Not Do

Honest boundaries.

Honesty is a feature. Threat Detection & Attribution has real limits, and we name them.

01

Attribution confidence is not certainty. A High-confidence attribution is a structured judgment, not a court-of-law finding. Confidence is documented, the analytic chain is documented, alternative hypotheses are documented. The platform never presents attribution as infallible.

02

Detection is not prevention. Detecting a campaign 6 weeks early provides the time to act; it does not itself constitute action. The platform delivers intelligence. The client decides. The decision is theirs.

03

Data quality matters. Detection accuracy depends on the breadth, freshness, and quality of source data. We commit to specific source coverage (11+ source categories, 47+ platforms, 200+ geographies, 17+ languages). Coverage gaps produce detection gaps. We disclose coverage on request.

04

Tuned vs. un-tuned deployments. A fresh deployment requires a calibration period. False-positive rates in the first 30 days are typically higher than steady-state. We commit to <8% at steady state; we do not commit to <8% in week 1.

05

Adversary adaptation is a moving target. Adversaries adapt. Detection models must be re-trained. The platform’s continuous validation cycle is the response; it is not a guarantee.

06

Some capabilities are subject to national export controls. Attribution tooling, certain IOC/IOA products, and certain detection models may be subject to export-control regimes. We do not deploy restricted capabilities to non-eligible jurisdictions.

07

Model accuracy varies by task and data quality. Sentiment analysis is more accurate in well-resourced languages than in low-resource languages. ATT&CK mapping is more accurate against documented tradecraft than against novel tradecraft. Confidence intervals vary by task; we publish them.

08

Confidence levels follow the Sherman Kent scale. High does not mean certain. It means a structured judgment supported by strong evidence, multiple independent methods, and surviving structured analytic techniques. Medium and Low are documented judgments, not failures of process.

09

False positives are not bugs. They are the cost of detection at the leading edge. We tune; we do not promise zero.

When You're Ready

See how attribution is built — not asserted.

A 60-minute confidential briefing. With a Sovereignty Infinium principal. We will walk through an anonymized attribution end-to-end, show the analytic chain, the confidence judgment, the alternative hypotheses, and the tradecraft evidence. We will not pitch.

  • Response within 1 business day
  • Mutual NDA · no obligation
  • Under your security protocols

Or write to briefing@sovereignty.co.in

What you walk away with

An attribution, with the chain shown.

  • We pick an anonymized adversary cluster
  • We run the 10 attribution methods in parallel
  • You see the analytic chain, not just the headline
  • We show alternative hypotheses considered and rejected
We will not pitch. 60 minutes. One anonymous case. Full analytic chain. Audit-grade provenance.

Sovereignty Infinium is built for sovereign clients · All engagements operate under mutual non-disclosure · Some capabilities subject to national export controls

SOC 2 Type IIISO 27001GDPRFedRAMPFIPS 140-3Common Criteria EAL5+