Threat Analysis: Mission Domain Intelligence Guide
An indicator list is not intelligence. Intelligence is a judgement, held to a stated confidence, that changes what a decision-maker does on Monday.
An indicator list is not intelligence. Intelligence is a judgement, held to a stated confidence, that changes what a decision-maker does on Monday.
What Threat Analysis covers as a mission domain
Threat analysis is the tradecraft that turns collection into decisions. It covers requirements definition, collection planning, source evaluation, structured analytic technique, confidence and estimative language, and delivery into a decision cycle that produces feedback. The subject matter may be any adversary, but the discipline is constant: identify what the customer must decide, work out what evidence would move that decision, gather it from sources whose reliability you can characterise, test competing explanations, and communicate uncertainty honestly rather than hedging everything into uselessness.
The domain structures itself across levels. Strategic analysis informs investment and policy over years. Operational analysis shapes campaign-level defence and investigation priorities over months. Tactical analysis feeds detection and response within hours. Each level has distinct products, cadences and shelf lives, and a common failure is producing tactical artefacts and presenting them as strategic insight to an audience that cannot use them.
Why it matters
Poor analysis is expensive in a way that is hard to see. Budgets go to the loudest threat rather than the likeliest one, controls get built against last year's campaign, and an unfalsifiable assessment cannot be learned from when it is wrong. Good analysis reduces the number of decisions made on anecdote, and gives leadership a defensible record of what was known, when, and with what confidence.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- A shift in an adversary's target selection toward a new sector, supplier tier or geography ahead of any change in tooling
- Capability transfer downward, where a technique previously seen only in state operations appears in commodity criminal tooling
- Reconnaissance volume against a specific external asset rising before any exploitation, visible in scan and probe telemetry
- Divergence between two normally consistent reporting streams, which usually indicates a collection gap rather than a real change
- A source whose reporting never contradicts your existing assessment, which is a reliability warning rather than a confirmation
- Rapid decay in indicator hit rates, signalling that detections rest on ephemeral artefacts rather than durable behaviour
- Priority intelligence requirements that have gone unanswered for successive cycles, exposing a structural collection deficiency
- Repeated customer questions arriving outside the requirement set, which is evidence the requirements no longer match the decisions being made
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- MITRE ATT&CK and D3FEND — Shared vocabularies for adversary behaviour and defensive countermeasures, enabling comparable coverage assessment
- ODNI Intelligence Community Directive 203 — Published analytic standards on sourcing, uncertainty expression and alternative analysis
- CIA Tradecraft Primer on structured analytic techniques — Practical method descriptions for ACH, key assumptions checks, devil's advocacy and red teaming
- Verizon DBIR and the VERIS framework — Large-sample incident data and a schema for coding incidents consistently across organisations
- ENISA Threat Landscape — Annual European baseline of threat categories, trends and sector exposure for strategic framing
- FIRST CVSS, EPSS and the Traffic Light Protocol — Standardised severity scoring, exploitation likelihood estimates and the sharing markings that govern onward distribution
- National CERT advisories and sector ISAC reporting — Validated current activity for corroboration and for testing whether your collection is missing what others see
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Define the requirement — Write down the decision the product supports and the question in a form that has a possible answer of no. Get the customer to confirm it.
- Plan collection — Map each requirement to specific sources, identify gaps, and decide in advance what would count as sufficient evidence.
- Evaluate sources — Grade source reliability and information credibility separately, and record it, so a single well-written vendor blog does not carry an assessment.
- Generate and test hypotheses — List competing explanations including benign ones, then look for evidence that discriminates between them rather than evidence that supports the favourite.
- Record assumptions — State the load-bearing assumptions explicitly, with the consequence if each is wrong. This is what makes the assessment reviewable later.
- Express confidence precisely — Use consistent estimative language, separate likelihood from confidence, and never conflate a large evidence volume with high quality.
- Deliver and close the loop — Brief in the customer's format, capture what they did with it, and record the outcome so accuracy can be measured over time.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Cyber Intelligence — Adversary Activity in Networks and Systems
- Risk Intelligence — Structured Assessment of Threat and Consequence
- Threat Actor Intelligence — Tracking Adversary Groups Over Time
- Vulnerability Intelligence — Weaknesses, Exploitation, and Prioritization
- Open Source Intelligence — Publicly Available Information, Systematically Collected
- News Intelligence — Media Reporting as an Intelligence Source
Worked in these data points
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
- CVE / Vulnerability — Common Vulnerabilities and Exposures identifier for a known flaw.
- Malware Family — A named class of related malicious software.
- IP Address — Internet Protocol address identifying a device or server on a network.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- Keyword / Narrative — A search term, topic, hashtag, or narrative tracked across media and platforms.
Adjacent mission domains
Inside the platform: where Threat Analysis lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
threats.php— Threat Analysis dashboarddomain.php?d=threat— Mission domain hubtheater.php?d=threat— Threat theater viewdetection-rules.php— CVE / Vulnerability profilehash-profile.php— Malware Family profileip-profile.php— IP Address profileurl-profile.php— Domain Name profilesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Threat Analysis:
- APT Intrusion Analysis — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Infrastructure Pivoting — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Malware Triage — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Detection Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Define the requirement is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Evaluate sources turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Deliver and close the loop feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Threat Analysis
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Analytic tradecraft is the discipline that keeps J2 reporting usable under time pressure. A defence analyst applies it to convert commander's critical information requirements into collection tasking, to grade sources consistently, and to produce assessments whose confidence and assumptions are visible to the staff who act on them. It underpins intelligence preparation of the operational environment, indications and warning, and the running estimate. Constraints are procedural: products must fit the battle rhythm, use the estimative language the command recognises, and separate assessment from fact clearly enough that a planner does not treat a moderate confidence judgement as a targeting input.
🕵 National intelligence
This is the core professional skill of national intelligence. It covers requirements management, collection planning against gaps, source evaluation, structured techniques for testing hypotheses, calibrated estimative language and disciplined dissemination. Value comes from traceability: any judgement in a finished product should be followable back to the reporting that supports it and the assumptions that carry it. Classification and compartmentation shape the work, since the most persuasive material often cannot appear in the released version, which is why tearline drafting is a habit rather than an afterthought. Performance is measured by decision impact and by calibration over time, not by production counts.
👮 Law enforcement
In law enforcement, analytic rigour is what separates intelligence that guides tasking from material that misleads it. Analysts apply grading schemes to source and content, keep the intelligence record distinct from the evidential record, and mark clearly what may be actioned and what may only be developed. The discipline matters for legality as much as accuracy: an unsupported intelligence judgement can drive a stop, a search or a listing that later fails scrutiny. Products feed tasking and coordination processes, problem profiles and threat assessments, and must state confidence and provenance so decision makers can weigh proportionality and necessity properly.
🔍 Private investigation and corporate security
Private sector analysts work with weaker sourcing and stronger commercial pressure to be definite, which is exactly why method matters. Structured techniques force alternatives into view before a client hears a conclusion, and consistent source grading stops a single vendor report from becoming a fact through repetition. Products support due diligence, threat assessments for executives and sites, investment decisions and litigation. A private actor cannot compel disclosure, so gaps are permanent and must be stated. Reports should distinguish observation, inference and speculation on the page, since they will be read by lawyers, insurers and sometimes regulators.
📰 Journalism and OSINT media
Investigative teams increasingly borrow intelligence tradecraft: hypothesis testing, source evaluation, explicit confidence, and structured challenge before publication. The adaptation needed is that journalism must be able to show its work publicly, so the standard is not only that a judgement is sound but that a reader can see why. Corroboration rules should be written down and applied consistently rather than negotiated per story. Source protection shapes what method can be described. Right of reply and correction policies are part of the analytic process, because a documented response from a subject is evidence that improves the assessment rather than a formality after it.
🌍 NGO, humanitarian and human rights
Humanitarian and human rights organisations use analytic method for context analysis, protection risk assessment and accountability documentation. The discipline that matters most is separating what a community reported from what the organisation assessed, because conflating them can endanger informants and undermine later legal use. Do no harm requires assessing the consequences of publishing an analysis, not only its accuracy. Duty of care includes managing analyst exposure to distressing material and being honest with partners about uncertainty. Structured techniques also counter the strong institutional pull toward findings that support an advocacy position already adopted.
🎓 University and research
Researchers examine analytic method as a subject and use it as a practice. Reproducibility means documenting how sources were selected, how coding decisions were made and how confidence was assigned, then publishing the frame so another team can repeat the exercise. Forecasting research offers directly applicable findings on calibration, aggregation and the value of structured decomposition. Ethics approval applies wherever the analysis rests on human participants or sensitive field data. Cite primary standards rather than textbook summaries, register analysis plans where possible to prevent post hoc reinterpretation, and publish the judgements that turned out wrong, since that record is where the field actually improves.
Playbook: working Threat Analysis end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Clarify the real question
Interrogate the request until you have a question that could be answered wrongly. Vague tasking produces vague products, so establish the decision behind it, who takes that decision, by when, and what they would do differently under each plausible answer. Rewrite the question and get it agreed. A good output is one sentence a collector and a customer both recognise, plus an explicit statement of what is out of scope.
Phase 2 — Decompose into information requirements
Break the question into components that can actually be collected against, and identify which are facts, which are judgements and which are assumptions you will have to make. Mark each as answerable from open sources, from internal holdings, from legal process or not at all. The output is a requirements matrix that shows where the answer will come from and where it will not, which is also your gap list.
Phase 3 — Plan collection deliberately
Match each requirement to a source type with an expected cost and lead time, and prioritise by how much the answer would move the judgement rather than by ease of collection. Note where two independent sources are needed because the requirement carries the assessment. Stop planning when you can state what will be collected, by whom, and by when, and start again when a gap turns out to be unfillable.
Phase 4 — Evaluate sources before content
Grade reliability of the source and credibility of the information separately, and record the basis for each. Check for circular reporting, where three apparently independent items trace to one origin, which is the most common corruption of an open source picture. The output is a source register that travels with the product, so a reader can see which sentence rests on which grade.
Phase 5 — Generate competing hypotheses
Write down at least three explanations including the one you consider unlikely and the one that would be most inconvenient. Generate them before examining the evidence in detail, because the sequence matters. A good output is a hypothesis set that a critic would recognise as fair, rather than one strong candidate accompanied by two obviously weak alternatives added for form.
Phase 6 — Test evidence against hypotheses
Score each item of evidence for how consistent it is with each hypothesis, focusing on diagnosticity: evidence consistent with everything tells you nothing. Identify the items that discriminate. Look actively for evidence that would disconfirm your leading hypothesis. The output identifies the smallest set of findings that would change the judgement, which is also your collection priority for the next round.
Phase 7 — Surface assumptions and check them
List the assumptions the judgement rests on, mark which are load bearing, and ask what would happen if each were false. Assumptions about continuity, about rational behaviour and about the completeness of your collection are the usual failure points. A good output names two or three assumptions explicitly in the product text, not in an annexe, so the reader carries them forward.
Phase 8 — Assign calibrated confidence
Use defined estimative terms consistently, keep confidence in the judgement separate from the reliability of the underlying sources, and avoid numerical precision the evidence cannot support. State the reason for the confidence level in the same sentence. Where a judgement rests on a single source, say so in the body. The output should let a reader predict how you would react if one source were withdrawn.
Phase 9 — Apply structured challenge
Put the draft through a review that is adversarial by design: a devil's advocate, a red team read, or a premortem asking why this assessment failed six months from now. The reviewer must be able to change the product, or the exercise is theatre. A good output is a recorded set of challenges and how each was addressed, including the ones that were rejected and why.
Phase 10 — Write for the decision
Lead with the judgement and its confidence, then implications for the customer, then the evidence, then the gaps. Keep length proportionate to the decision. Never bury a caveat in a subordinate clause or a footnote. The test of a good product is that it can be briefed accurately in ninety seconds and defended in detail for an hour without the two versions differing.
Phase 11 — Disseminate with correct handling
Mark at paragraph level so releasable versions can be extracted without rewriting, respect originator control, and record who received what. Include a named point of contact for challenge. Where the assessment may support legal or regulatory action, ensure the underlying evidence is preserved separately, because a finished assessment is not evidence and cannot be retrofitted into one. Record the dissemination list so a later correction can reach everyone who saw it.
Phase 12 — Log the judgement and review it
Record the judgement, its confidence and its expiry or review trigger in a register, then revisit it when the trigger fires or the review date arrives. Score outcomes honestly, including partial hits. Calibration only improves where the record exists. A good output is an annual review showing where the team was overconfident and in which subject areas, which then drives training rather than blame.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| ODNI analytic standards | Open | Published standards covering objectivity, sourcing, alternative analysis and estimative language for intelligence products. | Baseline definitions for confidence language and sourcing requirements in written assessments. Also the reference point when customers query estimative wording. |
| CIA Center for the Study of Intelligence publications | Open | Declassified studies on analytic method, cognitive bias and intelligence failure, including classic tradecraft texts. | Reference material for structured technique training and for case studies of analytic failure. |
| Admiralty grading scale documentation | Open | Alphanumeric scheme grading source reliability and information credibility as independent dimensions. Widely used across NATO members and allied policing organisations. | Consistent source evaluation that travels with reporting between organisations. Recipients can interpret grades without access to your sourcing. |
| College of Policing authorised professional practice | Open | United Kingdom professional guidance on intelligence management, grading and tasking processes for policing. | Aligning law enforcement analytic products with recognised national practice and grading schemes. |
| Europol strategic assessments | Open | Published serious organised crime and cyber crime threat assessments with documented methodology sections. | Worked examples of assessment structure, confidence statement and methodology transparency. Also useful for showing customers what transparency looks like. |
| Good Judgment and forecasting research | Open | Empirical work on forecast accuracy, calibration training, aggregation and team structure. Includes findings on training effects and the value of aggregation. | Evidence based methods for improving and measuring analyst calibration. Provides the scoring approach for a judgement log. |
| Berkeley Protocol on Digital Open Source Investigations | Open | Standards for open source collection, verification, preservation and analyst welfare in accountability work. | Method framework where analysis may later support legal or human rights proceedings. |
| FIRST Traffic Light Protocol | Open | Definitions governing how shared information may be redistributed between organisations and communities. | Correct handling markings on products that combine internal and partner sourced material. |
| RAND Corporation methodology publications | Open | Research on analytic methods, scenario construction, red teaming and assessment of uncertainty. | Technique references for scenario work and structured challenge in strategic products. Also useful for designing red team and premortem exercises. |
| Sherman Kent School estimative language guidance | Open | Foundational work defining probability terms and their consistent application in estimates. Underpins most current probability yardsticks in use today. | Setting an agreed word to probability mapping so readers interpret terms consistently. |
| UK Professional Head of Intelligence Assessment guidance | Open | United Kingdom common analytical standards and probability yardstick used across assessment bodies. | Alternative estimative framework and a reference when working with UK partners. Includes the probability yardstick used across UK assessment bodies. |
| Open source news archives with provenance | Licensed | Searchable historical media archives allowing verification of when a claim first appeared and where. | Detecting circular reporting by tracing a claim back to its first publication. |
| GDELT Project | Open | Large scale coded event and media tone dataset derived from global news monitoring. | Establishing baselines and detecting shifts in reporting volume around an issue. Useful for detecting circular reporting through first publication timing. |
| Academic journals on intelligence studies | Licensed | Peer reviewed research on analytic method, intelligence failure, organisational structure and oversight. | Grounding methodological claims in evidence rather than professional folklore. Also documents historical intelligence failures in analytic detail. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Threat Analysis. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Analysis of competing hypotheses matrices — Structures evidence against alternative explanations to expose diagnosticity. Limitation: easily gamed if hypotheses are written after the conclusion is formed.
- Key assumptions check templates — Forces load bearing assumptions into the open before drafting. Limitation: teams often list trivial assumptions and omit the ones they cannot imagine being wrong.
- Structured brainstorming and premortem sessions — Generates alternatives and failure modes with the whole team. Limitation: dominated by senior voices unless facilitated with written first rounds.
- Source registers and grading fields in a case system — Keeps reliability and credibility grades attached to every item. Limitation: grades drift toward the middle when analysts are not audited.
- Judgement and forecast logs — Records predictions with confidence and review dates for later scoring. Limitation: only valuable if outcomes are actually scored and the results are discussed.
- Timeline and link analysis software — Organises events and relationships to expose sequence and structure. Limitation: visual output implies confidence that the underlying grading may not support.
- Collaborative drafting with tracked challenge — Preserves the record of review comments and how each was resolved. Limitation: challenge only works if the reviewer has authority to change the product.
- Bayesian or scenario weighting aids — Makes the effect of new evidence on a judgement explicit. Limitation: false precision if priors are invented rather than reasoned and documented.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Detection Rules — Generates YARA, Sigma and Snort/Suricata logic from the selected indicators, ready to deploy.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Circular reporting is the most common defect in an open source picture. Three outlets citing one another produce the same confidence signal as three independent sources unless someone traces each claim back to its origin.
- Diagnosticity, not volume, is what moves a judgement. Evidence consistent with every hypothesis is decorative, and reports that accumulate it feel rigorous while adding nothing to the conclusion.
- Keep source reliability and information credibility separate. A reliable source can pass on a false report and an unreliable one can be right, and collapsing the two into a single score destroys the information both carry.
- State the falsifier. A judgement should be accompanied by the specific finding that would overturn it, which converts an assessment into something testable and gives collection its next priority.
- Confidence is about the strength of the reasoning, not the volume of collection. Analysts routinely raise confidence because more material arrived, when the new material was neither independent nor diagnostic.
- Write the caveat into the sentence that carries the judgement. Caveats parked in a methodology annexe do not travel into briefings, and the briefing is what the decision maker remembers.
- Structured challenge only works when the challenger can change the product. Review that produces comments the author may ignore is an audit trail for a failure, not a defence against one.
- Log judgements with review dates. Teams that only archive published products cannot tell whether they are calibrated, and will repeat the same class of error for years without noticing.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Threat Analysis is producing anything, and they are worth baselining before you change process or tooling.
- Calibration of stated confidence against outcomes, scored periodically across the whole body of judgements rather than selected successes.
- Proportion of products where the customer records that a decision was informed or changed, captured through structured feedback.
- Share of assessments that explicitly state a falsifier and at least one alternative hypothesis considered.
- Rate of circular reporting caught during review, measured as claims traced to a single origin before publication.
- Time from requirement agreement to first usable product, tracked against the decision deadline rather than an internal service level.
- Proportion of judgements formally reviewed at their review date rather than left standing by default.
- Reduction in requirements left open with no collection plan, indicating that gaps are being managed rather than accumulated.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Confirmation bias dressed as corroboration, where three sources all trace back to one original report
- Anchoring on the first plausible explanation and then treating later evidence as detail rather than as a test
- Producing unfalsifiable assessments hedged so heavily that no outcome could ever show them wrong
- Satisficing under deadline: accepting the first adequate hypothesis rather than the best-supported one
- Mistaking volume for insight, and shipping indicator lists or news roundups as finished intelligence
- Failing to record assumptions, which makes post-mortem learning impossible when the assessment does not hold
Legal and ethical considerations
Products carry handling obligations. Apply and honour traffic light protocol markings, and remember that onward sharing beyond the marking is a breach of trust that ends access. Protect sources, including inadvertent identification through unusual detail. Naming individuals or companies as threat actors carries defamation exposure and, where personal data is involved, requires a lawful basis and accuracy obligations under data protection law. Keep classified and open material in separate systems, and never launder classified judgements into an open product.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Threat Analysis, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 intelligence disciplines, 6 data points, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
How do we stop structured techniques becoming a paperwork exercise?
Tie them to decisions and keep them short. A key assumptions check that takes twenty minutes with the whole team and changes one sentence of the draft is worth more than a fully populated matrix completed after the conclusion was written. Require that the technique be run before the judgement is drafted, that the challenger has authority to change the product, and that the output is visible in the final text. Where a technique never changes anything, drop it rather than performing it, and record why.
What is the right way to express uncertainty to a non specialist customer?
Use a fixed, published set of terms with agreed probability ranges, apply them consistently, and put the reason for the confidence in the same sentence as the judgement. Avoid mixing verbal and numerical expressions in the same product, and never invent decimal precision. Tell the customer what would change your view, because that is more useful than the confidence word itself. Brief the yardstick to customers once, then use it every time, since inconsistency between analysts is what actually destroys the meaning of these terms.
How many independent sources are enough?
It depends on the diagnosticity and the consequence, not on a fixed count. For a routine judgement supporting a reversible decision, one well graded source may suffice if it is explicitly identified as such. For a judgement supporting an irreversible action, insist on independent corroboration and verify that independence rather than assuming it. The practical rule is to state how many genuinely independent lines support the central claim, so a reader can judge the weight. Two sources that both trace to one origin are one source.
Can commercial threat intelligence reports be treated as sources?
Yes, with grading. Vendor reporting is often technically strong and it is also a marketing product, so evaluate the evidence presented rather than the conclusion asserted. Check whether the report shows its work, whether its clustering criteria are stated, and whether other vendors observed the same activity independently. Do not let a vendor name become a fact through repetition across your own products. Where a vendor claim is load bearing in your assessment, record it as a single source and say so, exactly as you would with any other single source judgement.
How should analysts handle pressure to be more definite than the evidence allows?
Answer the underlying need rather than the request. Customers usually want to know what to do, not what is certain, so give them the judgement, the confidence, and the decision implications under each plausible alternative. Offer a clear statement of what collection would resolve the uncertainty and by when. If the pressure persists, document the request and your response, because assessments that were hardened under pressure are the ones examined most closely after a failure, and the record protects both the analyst and the organisation.
What separates a good analyst from a fast one?
The willingness to state what would prove them wrong, and the habit of tracing claims to their origin. Fast analysis assembles available material into a coherent story, which is easy because coherence is cheap. Good analysis identifies the small number of findings that actually discriminate between explanations, checks whether apparently independent sources are independent, and reports gaps as findings rather than hiding them. Speed matters and is often necessary, but the difference shows up months later in whether the judgement survived contact with events.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- ICD 203 Analytic Standards, defining objectivity, independence, alternative analysis and consistent estimative language.
- ICD 206 Sourcing Requirements, governing how sources are described and characterised in finished intelligence.
- Admiralty or NATO source grading, scoring source reliability and information credibility independently.
- UK Professional Head of Intelligence Assessment common analytical standards and probability yardstick.
- National Intelligence Model and equivalent policing intelligence management frameworks governing tasking and coordination.
- Traffic Light Protocol version 2.0 from FIRST, governing onward dissemination of shared assessments.
- Berkeley Protocol on Digital Open Source Investigations, setting verification and preservation standards for open source analysis.
- ISO 31000 risk management principles, where analytic output feeds organisational risk decisions.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Intelligence Community Directive 203, Analytic Standards — Office of the Director of National Intelligence. Governing standards for analytic rigour and estimative language.
- Psychology of Intelligence Analysis — CIA Center for the Study of Intelligence. Foundational text on cognitive bias and structured analytic technique.
- Authorised Professional Practice on intelligence management — College of Policing. United Kingdom professional guidance on intelligence grading and tasking.
- Berkeley Protocol on Digital Open Source Investigations — UN Office of the High Commissioner for Human Rights. Method standard for open source investigation and verification.
- Traffic Light Protocol version 2.0 — FIRST. Standard governing redistribution of shared information.
- Serious and Organised Crime Threat Assessment — Europol. Published strategic assessment with a documented methodology section.
- Research on forecasting and calibration — RAND Corporation. Empirical work on judgement accuracy and analytic method.
- GDELT global event dataset — The GDELT Project. Open coded media and event data used for baselining and trend detection.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: structures requirements, source grading and confidence so assessments stay testable and traceable to evidence. Explore the platform, or browse the rest of the library by following any tag above.