# Modeling Attackers and Their Motives

DevFeed: [Modeling Attackers and Their Motives](<https://devfeed.tech/articles/modeling-attackers-and-their-motives-36894.md>)

Original publisher: [Read original article](<https://shostack.org/blog/modeling-attackers-and-their-motives/>)

Author: Adam

Published: 2014-11-11T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [intelligence](<https://devfeed.tech/topics/intelligence.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [intelligence](<https://devfeed.tech/tags/intelligence.md>), [reports](<https://devfeed.tech/tags/reports.md>)

## AI overview

This commentary argues that readers should focus on actionable facts in threat reports, such as filenames, hashes, and IP addresses, rather than becoming overly focused on attackers' identities and motives. That focus can cause organizations to miss other attackers or misunderstand how threats may change.

## Source excerpt

There are a number of reports out recently, breathlessly presenting their analysis of one threatening group of baddies or another. Most readers should, at most, skim their analysis of the perpetrators. Read on for why.