Cyber threat attribution is crucial for understanding the threat landscape, but it's often a complex and challenging process. This presentation introduces Unit 42's Attribution Framework, a structured methodology designed to bring rigour and transparency to attribution efforts. The framework provides a data-driven approach, moving beyond guesswork and intuition to link threat activity to activity clusters, temporary groups, or formalized threat actor groups with clearly defined confidence levels. By leveraging a modified Admiralty System, we introduce a quantifiable scoring mechanism to assess both the reliability of sources (e.g. internal telemetry versus public reports) and the credibility of individual pieces of evidence. Combined with the Diamond Model of Intrusion Analysis, this ensures a comprehensive approach to evidence gathering and analysis, covering all facets of an attack.