The motivations behind similarity analysis
In the previous chapter, we spent a lot of time focusing on identifying artifact and indicator information that we could utilize to hunt and pivot on to identify relationships between files and their infrastructure. As you begin hunting and pivoting to discover new related information, it's important to utilize visualization tools as you start grouping what you've discovered from the files and infrastructure together. Visualization tools will help you manage the dataset of related information and allow researchers to understand connections between events and the infrastructures where these events occur.
Additionally, it is important to understand that not just the observed artifacts and indicators from your hunting and pivoting processes are used to cluster observations behavior. You can easily begin utilizing computational processes to generate new artifacts that also can be used to create relationships among files, artifacts...