Attack infrastructure automatically clustered by shared indicators. Campaigns are formed when IPs share C2 servers, botnet families, subnet space, commands, or temporal patterns.
Analyzing infrastructure relationships...
Confidence = sum of matched indicator weights. Union-find clustering merges connected IPs into campaigns.