reverse-operator-attribution

Installation
SKILL.md

Reverse Operator Attribution

Use this skill after basic malware analysis exists and the next question is who likely built, operated, funded, or hosted the capability.

Minimum evidence package

Do not start attribution from a vague family label alone. Gather at least:

  • one build or source-environment leak, or one unique literal / typo
  • one infrastructure, wallet, contract, or update-path pivot
  • one timestamp, version tuple, or deployment-habit clue
  • one competing explanation worth stress-testing

Guardrails

  • Separate facts, inferences, hypotheses, and unknowns.
  • Prefer uniqueness over volume.
  • Treat language, culture, timezone, and geography as weak signals until corroborated.
  • Distinguish developer, builder, operator, relay owner, and victim. They may not be the same entity.
  • Mark any action that requires provider cooperation, legal process, or law-enforcement support.
Installs
4
First Seen
May 24, 2026
reverse-operator-attribution — knowlet/reverse-skills