Intel Posting Guidelines

What is threat intelligence and what is “cyber news?” It isn’t always immediately obvious which is which. The heuristic we’ve discussed as a team is actionability: can the information be used by the community to actively improve their defenses? If so, it’s Threat Intel.

That could include:

  • Tactics, Techniques, and Procedures (TTPs)
  • Malware profiles/breakdowns
  • Reports of exploited 0-days
  • Atomic indicators of compromise (IPs, domains, URLs, file hashes, string patterns)

Other events, like new (unpexploited) CVEs, tech news, or reports of breaches/attacks without associated indicators belong in Cyber News.

Evaluating Intelligence

That’s for post categorization. Afterwards, we are going to use the Admiralty Code to determine how to respond to new intelligence. IFIN volunteers will evaluate the information and tag it with a credibility and reliability score. Broadly, this chart details how we’ll respond based on those evaluations.

Anything in the “Credible/Accept” region will be published to social media for further visibility. We usually want >1 source of information to meet that standard, unless the initial source is particularly reputable, or the nature of the information is independently verifiable.

Scores can change as new information comes in! That’s the point of the thread: to add context as time goes on for true enrichment of the intelligence.

A Developing Process

We’re still figuring out the best way to handle all these things, and we want to do so together. This category is meant for IFIN-specific feedback. If you have thoughts, please share them!

7 Likes