> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# From Indicator to Action

> How a single flagged campaign gets traced across countries, corroborated by independent sources, and mapped to concrete MITRE ATT&CK mitigations

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/mGgHxMsQTm71_QZa/images/case5.png?fit=max&auto=format&n=mGgHxMsQTm71_QZa&q=85&s=11b936a58a80cd6f5cbb123655f0ee1f" width="2114" height="1414" data-path="images/case5.png" />

This is one attack campaign shown from two angles. On the left, the countries it reached: Italy, Germany, Spain, the UK, the US, Serbia, France, and the Netherlands. On the right, the classification of the activity as MITRE ATT\&CK attack patterns and courses of action rather than a single severity label.

***

## Source diversity

The sources that flagged this activity include Olidata, an Italian MSP partner; Blocklist.de's fail2ban reporting service; Suricata-based network detection; DeceptionGrid, a honeypot network with no legitimate traffic to hide behind; and AquilaX, an AI-driven software security source, among others. These are distinct source types — public blocklists, commercial partners, honeypots, AI-assisted detection — with no operational relationship to one another. Independent agreement across source types is a factor in the trust weighting applied when a Crime Score is calculated.

## Classification, not just a score

The right panel classifies the campaign into MITRE ATT\&CK attack patterns — password guessing is shown as one example — paired with courses of action that map to specific configuration changes: account lockout policies against brute forcing, port closure and network segmentation against service scanning, file and process permission hardening against service-stop attempts, and credential-handling controls against valid-account abuse.

## Score versus technique

A Crime Score indicates confidence that an asset is malicious. MITRE ATT\&CK mapping indicates which technique is in use, and therefore which control addresses it. Blocking the IP addresses this instance. Applying the mapped course of action addresses the technique, which remains relevant the next time a different IP uses the same approach.

***

Proof of Value engagements map campaigns like this one against a client's own logs. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
