Get a quote

Analyst how-to · Threat intelligence

Threat intelligence

How to connect multiple indicators.

By Abhimanyu Gupta, Founder & Principal Operator

Triage leaves you with a pile: a handful of IPs, a couple of domains, a file hash, maybe an actor name from a report. A pile is not a story. Turning scattered indicators into a coherent picture is link analysis, and it is as easy to do badly, seeing connections that are not there, as to do well. Here is how to build the graph honestly.

At a glance

Starting point
Several indicators of different types, provenance uncertain
Goal
A graded graph showing which indicators belong to one story, and why
Unit of analysis
The link, not the node; every edge needs a justification
Two failure modes
Missing a real connection; inventing one from coincidence
Models
The Diamond Model for pivots; competing hypotheses for discipline
Rule
Confidence follows the weakest link in the chain, not the strongest

From a pile to a picture

A list of indicators has no shape. Link analysis gives it one by asking, of every pair, “is there a real relationship here, and how strong is it?” The result is a graph: nodes are the indicators, edges are the justified relationships between them. The value is not the drawing; it is the discipline the drawing forces, because an edge you cannot justify is an edge you should not draw.

This is the natural sequel to pivoting from a single indicator and investigating infrastructure. Those find candidate connections; connecting indicators is the discipline of deciding which candidates are real and how much they support a single narrative.

Beginners collect nodes; analysts justify edges. Every connection you assert should carry the evidence that supports it and a grade for how strong that evidence is. “These two hosts share a private TLS key” is a near-certain edge. “These two domains both use a popular registrar” is barely an edge at all. Writing the justification on each link is what separates an investigation from a mood board, it lets a reader, and later you, see exactly why the picture holds together.

Four bridges between indicators

The Diamond Model gives a useful set of directions to look for links, because indicators of one kind connect to another through a small number of bridges:

BridgeConnectsTypical strength
InfrastructureDomains and IPs sharing hosting, keys, or resolution historyStrong when the shared trait is rare
CapabilitySamples sharing code, config, or a familyStrong; tooling is expensive to change
BehaviourIndicators seen in the same technique or sequenceModerate to strong; the durable link
VictimologyTargets in the same sector, region, or windowContextual; supports, rarely proves
TemporalActivity clustered in the same timeframeSupporting; corroborates other bridges

The strongest graphs are held together by more than one bridge. Two hosts linked by a shared key and the same sample and the same target sector is a confident cluster; two hosts linked only by “active in the same month” is a coincidence waiting to be disproven.

Time is a connector

Timing is one of the most underused bridges. Indicators that light up together, domains registered the same afternoon, hosts that go live and go dark on the same schedule, samples first seen in the same narrow window, are more likely to belong to one operation than the same indicators scattered across a year. But temporal correlation is supporting evidence: it strengthens a link built on a firmer bridge and should rarely carry a connection on its own. Two unrelated things can happen at once.

Why confidence does not add up

A tempting error is to feel more certain as the graph grows. But confidence in a chain of inferences follows the weakest link, not the strongest, and it is closer to multiplying probabilities than adding them. If A links to B with high confidence, and B links to C with low confidence, then A to C is low, no matter how solid the first hop was. A long chain of “probably” ends in “probably not.”

Beware the impressive-looking graph. Fifty nodes connected by fifty weak edges is not fifty times as convincing as one strong link; it is often a monument to coincidence. Size is not confidence, and a dense diagram can hide the fact that not one of its edges would survive scrutiny.

The pattern that is not there

The human mind is a pattern-finding engine, and it finds patterns whether or not they exist, a tendency named apophenia. In link analysis it shows up as connecting indicators because you expect them to connect, then unconsciously seeking the evidence that confirms it. The discipline that counters it is to argue against yourself: state the competing explanation (“these are unrelated, and the shared trait is common”) and look for evidence that would break the link, not just support it. This is the core of the Analysis of Competing Hypotheses, and it is the single best guard against a confident, wrong picture.

When a cluster becomes a campaign

At some point a well-linked cluster earns a name and a story: this is one operation, with this infrastructure, using this tooling, against these targets, over this period. That promotion is a judgement, and it deserves the same honesty as any other: state the confidence, list the links that carry it, and keep “this is a coherent activity cluster” separate from “this is actor X.” Clustering (grouping related activity) and attribution (naming who is behind it) are different claims at very different confidence levels, and collapsing the two is how good analysis becomes a bad headline.

You can be highly confident that a set of indicators belongs to one operation and have almost no basis for saying who runs it. “One actor did all of this” is a strong, defensible claim; “and that actor is nation X” is a separate claim that usually needs far more.

Holding the graph together

Link analysis by hand becomes unmanageable fast: the edges multiply, the justifications get lost, and the confidence grades live in someone's head instead of on the graph. A correlation platform keeps the structure honest, resolving the relationships between indicators, keeping the evidence attached to each edge, and surfacing the connections you have without inventing the ones you do not. Forensia is built to connect indicators, reports, and the entities behind them into one investigation, with the provenance that lets you defend each link rather than just assert it.

Key takeaway

Connecting indicators is about justifying edges, not collecting nodes. Look for links across the Diamond bridges, prefer connections that more than one bridge supports, and treat timing as corroboration rather than proof.

Then discipline the picture: confidence follows the weakest link, a big graph is not a strong one, and argue against your own connections before you trust them. Keep clustering separate from attribution, and the story you build will survive someone else reading it.

References & further reading

  1. Caltagirone, Pendergast & Betz, The Diamond Model of Intrusion Analysis, for pivoting between the features of an intrusion.
  2. Richards J. Heuer Jr., Psychology of Intelligence Analysis, and the Analysis of Competing Hypotheses.
  3. MITRE, ATT&CK, for describing the behavioural bridge between indicators.
  4. David J. Bianco, The Pyramid of Pain, on why some links cost the adversary more than others.
  5. OverWatch Labs, How to validate threat intelligence, on grading the evidence each link rests on.
All posts Explore Forensia

Forensia

Connect the dots you can defend.

Forensia links indicators, reports and the entities behind them into one investigation, with the provenance that lets you justify each connection.