Skip to main content

Compare Two Reports

Draft

Level: Intermediate

Goal: Assess whether two reports describe related activity.

Real-Life Scenario

Two public reports mention similar tooling and infrastructure, and the analyst needs to decide whether they describe the same campaign or only common tradecraft.

When To Use This

Use this workflow when you need a structured analyst workflow and want the output to remain traceable to evidence.

Steps

  1. Analyze and store both reports.
  2. Open report comparison.
  3. Compare shared and unique TTPs, IOCs, and actor hints.
  4. Separate generic overlap from distinctive behavior.
  5. Export the comparison summary.

Expected Result

Relationship assessment between reports.

Review Notes

  • Keep source labels and evidence attached to every accepted result.
  • Treat actor matches, enrichment hits, and matrix overlap as analytical signals until corroborated.
  • Export only reviewed findings for customer, SOC, detection engineering, or executive use.