To make sure we’re all talking about the same thing and not just dreaming something up, perhaps someone can put together an example of how you directly sighted or observed a threat actor vs you observed indicators or evidence of a threat actor. That exercise might help us come to the right answer ...
|