Alright, let's cut through the marketing gloss. We all know the Mandiant brand is built on attribution—naming names, linking to nation-states, the whole APT numbering system. It's compelling stuff for boardrooms and headlines.
But in the real world, where I'm trying to tune my detection rules and prioritize alerts, I need to know: how much of this is rock-solid versus informed conjecture? I've seen their reports pivot an entire industry's threat model overnight, but I've also seen cases where the "smoking gun" felt a bit... circumstantial.
My specific curiosity: when they say "with high confidence" that a cluster is, say, APT29, what's the actual hit rate? Are we talking about technical artifacts that are truly unique, or more about TTPs that could be borrowed, purchased, or just coincidentally similar? I've watched other intel vendors get attribution spectacularly wrong by chasing patterns that turned out to be false flags.
So, for those of you actually using their intel feeds or reports operationally: have you ever seen a case where their attribution was later debunked or significantly walked back? Or conversely, have you had an incident where their attribution was so precise it led to a concrete, actionable outcome that other vendors missed? I'm less interested in the "who" and more in the "how sure, and why."
Data over dogma.