Start with the requirement and the source
Define the decision you want to support: whether a campaign affects your technology, whether a detection gap deserves attention, or whether an observed indicator needs urgent investigation. Open-source intelligence comes from publicly available material. Closed-source intelligence may come from restricted communities, commercial research, or private partnerships. Access restrictions do not automatically make a claim more accurate.
Record where a claim originated, when the underlying activity occurred, and any restrictions on sharing it. Separate a researcher’s observation from someone else’s summary. Threat-intelligence sharing can improve collective visibility, but shared artifacts may contain sensitive details. Apply the agreed handling and distribution rules and involve appropriate advisers when a proposed disclosure raises uncertainty.
Evaluate confidence across three different dimensions
Timeliness asks whether information is recent enough for the decision. Relevance asks whether the affected technology, behaviour, and context apply to your environment. Accuracy asks how well the claim is supported. A fresh report about software you do not use may be accurate yet irrelevant. An older behavioural observation may remain useful even after its associated IP address changes.
Confidence should describe the evidence rather than imitate certainty with a number. Identify independent corroboration, source reliability, contradictory observations, and missing data. Several feeds that copy the same report do not supply several independent confirmations. Low-confidence information can justify a limited search while remaining too weak to support a disruptive automated block.
Move from indicators towards behaviour
Atomic indicators describe discrete observables such as a file hash, address, or domain. Behavioural indicators describe patterns, such as a sequence of credential access followed by unusual resource use. The Pyramid of Pain explains why changing an observable can be easier for an adversary than changing a well-developed working method. Neither category eliminates the need for context.
Tactics describe an adversary’s objective, techniques describe approaches, and procedures describe their particular implementation. An advanced persistent threat label suggests sustained, capable activity; insider threats involve trusted access and may be intentional or unintentional. Avoid assigning an actor solely because one tool or technique appears. Shared tools and overlapping behaviours make attribution a separate, uncertain analytical judgement.