Structured analysis is what separates intelligence from informed opinion. The techniques in this lesson are required reading in every serious intelligence community — cyber included.
Analysis of Competing Hypotheses — Worked Example
SCENARIO:
Intrusion detected at a defense contractor. Evidence:
- Spearphishing with weaponized PDF targeting aerospace engineers
- Custom implant with no public detections
- C2 via steganography in images hosted on legitimate photo-sharing site
- Data staged in temporary directory then exfiltrated via HTTPS
- Active only during UTC+8 business hours
- Targets: CAD files for aircraft components
HYPOTHESES:
H1: Chinese nation-state (PRC government-sponsored espionage group)
H2: Russian nation-state (GRU/SVR-aligned group)
H3: Sophisticated criminal group conducting industrial espionage for hire
H4: North Korean group (financial motivation secondary to tasking)
EVIDENCE vs. HYPOTHESES TABLE:
Evidence | H1 China | H2 Russia | H3 Criminal | H4 DPRK
----------------------------------|----------|-----------|-------------|--------
UTC+8 business hours | + | - | neutral | -
Targeting: aircraft CAD files | + | + | + | -
Custom implant (no VirusTotal) | + | + | + | -
Steganographic C2 technique | neutral | + | - | neutral
No financial data targeted | + | neutral | - | -
Aerospace sector victim | + | + | neutral | -
CONTRADICTING EVIDENCE SCORE:
H1 China: 1 contradicting (UTC+8 alone doesn't confirm China — could be spoofing)
H2 Russia: 1 contradicting (UTC+8 inconsistent with Russian TZ)
H3 Criminal: 2 contradicting (no financial target, sophisticated custom tooling rare for hire)
H4 DPRK: 2 contradicting (UTC+8 inconsistent, no financial motivation match)
ASSESSMENT:
"We assess with MODERATE confidence that this intrusion is consistent with
Chinese nation-state espionage (H1) based on: victim sector (aerospace),
data targeted (aircraft component designs), and operational hours
(UTC+8 business hours).
H2 (Russia) cannot be eliminated — Russian groups conduct aerospace espionage
and would be capable of time-zone spoofing. The steganographic C2 technique
is more strongly associated with Russian groups in public reporting.
Confidence limited by: no malware sample overlap with attributed campaigns,
no infrastructure linkage to documented groups, possibility of deliberate
time-zone spoofing."
Confidence Language in Practice
CONFIDENCE CALIBRATION EXAMPLES
HIGH CONFIDENCE statements:
"We assess with high confidence that the spearphishing campaign is ongoing —
we have confirmed active C2 infrastructure and three victims reported in the
past 7 days from direct incident data."
"The malware sample almost certainly belongs to the SUNBURST malware family —
the YARA rule developed by Mandiant matches 14 of 14 indicators."
MODERATE CONFIDENCE statements:
"This activity probably represents targeted espionage rather than opportunistic
access — the targeting of specific personnel (engineers, not executives) and
data of no obvious financial value suggests a collection goal."
"The group is likely state-sponsored based on the sophistication of tooling
and the absence of monetization attempts despite 6 weeks of dwell time."
LOW CONFIDENCE statements:
"This may be the same group that targeted [other organization] last quarter,
based on a single shared infrastructure indicator that may indicate vendor
reuse rather than actor overlap."
"The attacker possibly has access to unpatched internal systems — we have not
confirmed lateral movement beyond the initial foothold."
NEVER USE (overclaims certainty):
"This is definitely APT41."
"It is clear that the attackers are Russian."
"We know for certain that..."