Objective 1.4 · Lesson 1 of 2

Turn intelligence into a local decision

Threat information becomes intelligence when it helps somebody make a decision. A long indicator feed is less useful than a well-supported answer to a specific local question.

Start with the requirement and the source

Define the decision you want to support: whether a campaign affects your technology, whether a detection gap deserves attention, or whether an observed indicator needs urgent investigation. Open-source intelligence comes from publicly available material. Closed-source intelligence may come from restricted communities, commercial research, or private partnerships. Access restrictions do not automatically make a claim more accurate.

Record where a claim originated, when the underlying activity occurred, and any restrictions on sharing it. Separate a researcher’s observation from someone else’s summary. Threat-intelligence sharing can improve collective visibility, but shared artifacts may contain sensitive details. Apply the agreed handling and distribution rules and involve appropriate advisers when a proposed disclosure raises uncertainty.

Evaluate confidence across three different dimensions

Timeliness asks whether information is recent enough for the decision. Relevance asks whether the affected technology, behaviour, and context apply to your environment. Accuracy asks how well the claim is supported. A fresh report about software you do not use may be accurate yet irrelevant. An older behavioural observation may remain useful even after its associated IP address changes.

Confidence should describe the evidence rather than imitate certainty with a number. Identify independent corroboration, source reliability, contradictory observations, and missing data. Several feeds that copy the same report do not supply several independent confirmations. Low-confidence information can justify a limited search while remaining too weak to support a disruptive automated block.

Move from indicators towards behaviour

Atomic indicators describe discrete observables such as a file hash, address, or domain. Behavioural indicators describe patterns, such as a sequence of credential access followed by unusual resource use. The Pyramid of Pain explains why changing an observable can be easier for an adversary than changing a well-developed working method. Neither category eliminates the need for context.

Tactics describe an adversary’s objective, techniques describe approaches, and procedures describe their particular implementation. An advanced persistent threat label suggests sustained, capable activity; insider threats involve trusted access and may be intentional or unintentional. Avoid assigning an actor solely because one tool or technique appears. Shared tools and overlapping behaviours make attribution a separate, uncertain analytical judgement.

Keep these points in mind

  • Assess freshness, local relevance, and evidence quality separately.
  • Keep provenance and sharing restrictions with the intelligence.
  • Detection value and attribution confidence are different questions.

Pause and practise

Two feeds report the same suspicious domain and cite one blog post. What confidence adjustment and local action are appropriate?

Show a worked response

Treat the blog post as one underlying source rather than two independent confirmations. Check its date, evidence, and relevance to your assets. Search approved local DNS and connection records for the domain, recording coverage and results; reserve disruptive blocking for a decision justified by impact and corroboration.

Next lesson →
← Module overview