{"id":11718,"date":"2026-03-25T13:19:09","date_gmt":"2026-03-25T13:19:09","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11718"},"modified":"2026-03-25T13:19:09","modified_gmt":"2026-03-25T13:19:09","slug":"using-linguistics-and-psychological-profiling-in-threat-actor-attribution","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/using-linguistics-and-psychological-profiling-in-threat-actor-attribution\/","title":{"rendered":"Using Linguistics and Psychological Profiling in Threat Actor Attribution"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">Using Linguistics and Psychological Profiling in Threat Actor Attribution<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Traditional threat actor attribution primarily focuses on TTPs (Tactics, Techniques, and Procedures), but this method is increasingly ineffective when adversaries employ similar strategies or attempt to mask their identities. This paper introduces an advanced attribution methodology that combines cyber linguistics, behavioral profiling, and Natural Language Processing (NLP). By analyzing linguistic markers such as vocabulary, syntax, tone, intent, and prominent words, alongside sentiment analysis, we identify distinct patterns that differentiate threat actor groups. This approach reveals not only behavioral traits but also the psychological drivers behind attack campaigns. By integrating NLP techniques for tone and intent detection, we provide more nuanced insights into the actors&#8217; motivations. This advanced model enhances attribution accuracy, enabling threat intelligence teams to refine defensive strategies and proactively counter emerging threats. This work represents a step forward in making attribution more precise, dynamic, and actionable for the cybersecurity community.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Rishika-Desai.png\" alt=\"\" class=\"wp-image-11719\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Rishika-Desai.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Rishika-Desai-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Rishika-Desai-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Rishika-Desai-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong>Rishika Desai &#8211; BforeAI<\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rishika Desai is a leading threat intelligence and cybercrime researcher with a strong focus on OSINT and dark web investigations. Featured in Forbes and Dark Reading as a subject matter expert, she was also awarded as Rising Star of the Year 2025 by BSides Bangalore. Rishika regularly shares her insights at global conferences and is known for her engaging, real-world approach to cybersecurity education. As a mentor and founder of a thriving cyber community, she is dedicated to shaping the next generation of cyber defenders.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back Using Linguistics and Psychological Profiling in Threat Actor Attribution Traditional threat actor attribution primarily focuses on TTPs (Tactics, Techniques, and Procedures), but this method is increasingly ineffective when adversaries employ similar strategies or attempt to mask their identities. This paper introduces an advanced attribution methodology that combines cyber linguistics, behavioral<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/using-linguistics-and-psychological-profiling-in-threat-actor-attribution\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11718","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11718"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11718\/revisions"}],"predecessor-version":[{"id":11720,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11718\/revisions\/11720"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}