Thesesessionsresembleeachother.Thatisthewholeclaim.

Correlation clusters sessions on two axes: fingerprint similarity from the connection layer, and TTP-sequence distance from what the sessions actually did, compared as ordered sequences rather than as sets. Order carries information that a set of techniques throws away.

Why sequence and not just set

Two sessions can touch the same six techniques and be nothing alike. One that goes discovery → network → metadata → credentials is describing a different operator from one that lands an exploit first and enumerates afterwards. Comparing the sequences keeps that difference.

Where it will be wrong

Shared tooling is cheap. Two unrelated operators running the same public toolkit will cluster tightly on fingerprint and look like one campaign. The design accepts that rather than hiding it behind a confident label.

The line it does not cross

A campaign is a statement about sessions. It is not a statement about a person, a group, or a country, and nothing in the system produces one. Behavioural clustering is not attribution, and treating it as attribution is how analysts end up confidently wrong in public.

Worked against one recorded session

Session sess_7f3a91, 24 observations over 257s. Everything below is generated from that transcript by rule. No model touched any of it.

The ordered technique sequence, which is what L7 compares
T1033T1082T1033T1083T1087.001T1518T1057T1016T1049T1518.001T1046T1548.001T1552.001T1552.001T1552.004T1552.005T1090T1190T1003.008T1552.001T1098.004T1053.003T1041T1105T1070.003

As a set this is 22 techniques. As a sequence it is 25 ordered steps, and the ordering is what separates a session that hunted credentials before exploiting from one that did it the other way round.