Within the cyber security community, we very often see public reports identifying threat actor activity in very general terms. For example, a recent write-up regarding activity associated with threat actors deploying the Snatch ransomware stated that they, «...turned off Windows Defender...» without going any further. While there are a number of ways to accomplish this task, sharing the methodology details, or «toolmarks» not only provides actionable intel for proactive and DFIR threat hunting, but the granularity and context contributes to attribution. This presentation will demonstrate what «toolmarks» are through the use of examples.