reverse-operator-attribution
Installation
SKILL.md
Reverse Operator Attribution
Use this skill after basic malware analysis exists and the next question is who likely built, operated, funded, or hosted the capability.
Minimum evidence package
Do not start attribution from a vague family label alone. Gather at least:
- one build or source-environment leak, or one unique literal / typo
- one infrastructure, wallet, contract, or update-path pivot
- one timestamp, version tuple, or deployment-habit clue
- one competing explanation worth stress-testing
Guardrails
- Separate facts, inferences, hypotheses, and unknowns.
- Prefer uniqueness over volume.
- Treat language, culture, timezone, and geography as weak signals until corroborated.
- Distinguish developer, builder, operator, relay owner, and victim. They may not be the same entity.
- Mark any action that requires provider cooperation, legal process, or law-enforcement support.