Interesting aspect of today's announcement by Microsoft that they're moving toward a new, tiered/nested #CTI #ThreatActor naming schema: in moving away from element names as placeholders for activity groups/clusters as defined through a methodology like #DiamondModel, and towards a schema that posits definite value in adversary attributes (primarily geography, for now), has Microsoft Threat Intel changed some aspects of methodology and clustering to include increasing amounts of "who-focused" linking?
FWIW, they're one of the only private shops that I think could do that sort of linking with any degree of success or accuracy on a consistent basis.