- Home
- Methodology
how we work
Methodology
Which sources we use, how we express confidence in an attribution, how often profiles are reviewed and the limits of this information.
Sources
Every profile is built exclusively from public, verifiable sources, and every profile cites at least two. We prioritize, in this order:
- MITRE ATT&CK: group identifier, aliases and documented techniques.
- Government advisories: CISA, FBI, NSA, NCSC (United Kingdom), ColCERT and national CSIRTs in the region.
- Technical reports from vendors and researchers (Mandiant/Google, Microsoft, CrowdStrike, ESET, Kaspersky, Check Point, Proofpoint, among others).
In this version of the portal we do not publish indicators of compromise (IOCs), nor campaigns, dates or attributions that are not backed by a cited source. If a fact is uncertain, it is left out.
Naming
Each vendor names groups differently (for example, APT28 is “Fancy Bear” for CrowdStrike and “Forest Blizzard” for Microsoft). We use the MITRE ATT&CK name as the primary name and list aliases with the vendor that uses them. Aliases are not always exact equivalents: each vendor defines its groups from its own visibility, so there may be partial overlaps.
Attribution confidence levels
Cyber attribution is probabilistic. Each profile states the suspected country or sponsor and a confidence level for that attribution:
- High: public attribution by one or more governments (indictments, joint advisories from agencies such as CISA, FBI, NSA or NCSC) and consistent with several independent vendors.
- Moderate: several security vendors agree on the attribution based on infrastructure, code or victimology, but without a formal government attribution.
- Low: attribution based on limited indicators (language, time zone, targets) or on a single source, or the origin is undetermined. It is presented as a hypothesis.
Latin America and Colombia flag
A group is flagged as active in Latin America (or in Colombia) only when a public report documents campaigns against organizations in the region. The absence of the flag means we know of no public reports, not that the group is irrelevant to the region.
Review status
- Draft: compiled from public sources, pending validation by an analyst. Shown with a notice and not indexed by search engines.
- Reviewed: a Ventura Systems analyst checked every statement against the cited references.
Update policy
- Full review of each profile at least once per quarter.
- Out-of-cycle updates when MITRE ATT&CK publishes a new version, or when a relevant government advisory or report appears, especially if it involves Latin America.
- Each profile’s “Updated” date reflects its last substantive change. Changes are recorded in the repository history.
- New versions are announced in the RSS feed.
Disclaimer
The information on this portal is provided for informational and defensive purposes. It is based on third-party public sources whose accuracy we cannot guarantee, and it does not constitute an official attribution by Ventura Systems. Recommendations are general: validate any change in your environment before applying it. Trademarks and group names belong to their respective owners.
Found an error or have a source we should consider? Contact us.