Lesson 2 of 2 · 20 min read

Structured Analytic Techniques and Confidence Calibration

Structured analysis is what separates intelligence from informed opinion. The techniques in this lesson are required reading in every serious intelligence community — cyber included.


Analysis of Competing Hypotheses — Worked Example

SCENARIO: 
Intrusion detected at a defense contractor. Evidence:
- Spearphishing with weaponized PDF targeting aerospace engineers
- Custom implant with no public detections
- C2 via steganography in images hosted on legitimate photo-sharing site
- Data staged in temporary directory then exfiltrated via HTTPS
- Active only during UTC+8 business hours
- Targets: CAD files for aircraft components

HYPOTHESES:
H1: Chinese nation-state (PRC government-sponsored espionage group)
H2: Russian nation-state (GRU/SVR-aligned group)  
H3: Sophisticated criminal group conducting industrial espionage for hire
H4: North Korean group (financial motivation secondary to tasking)

EVIDENCE vs. HYPOTHESES TABLE:
Evidence                          | H1 China | H2 Russia | H3 Criminal | H4 DPRK
----------------------------------|----------|-----------|-------------|--------
UTC+8 business hours              |  +       |  -        |  neutral    |  -
Targeting: aircraft CAD files     |  +       |  +        |  +          |  -
Custom implant (no VirusTotal)    |  +       |  +        |  +          |  -
Steganographic C2 technique       |  neutral |  +        |  -          |  neutral
No financial data targeted        |  +       |  neutral  |  -          |  -
Aerospace sector victim           |  +       |  +        |  neutral    |  -

CONTRADICTING EVIDENCE SCORE:
H1 China:    1 contradicting (UTC+8 alone doesn't confirm China — could be spoofing)
H2 Russia:   1 contradicting (UTC+8 inconsistent with Russian TZ)
H3 Criminal: 2 contradicting (no financial target, sophisticated custom tooling rare for hire)
H4 DPRK:     2 contradicting (UTC+8 inconsistent, no financial motivation match)

ASSESSMENT:
"We assess with MODERATE confidence that this intrusion is consistent with 
Chinese nation-state espionage (H1) based on: victim sector (aerospace), 
data targeted (aircraft component designs), and operational hours 
(UTC+8 business hours).

H2 (Russia) cannot be eliminated — Russian groups conduct aerospace espionage 
and would be capable of time-zone spoofing. The steganographic C2 technique 
is more strongly associated with Russian groups in public reporting.

Confidence limited by: no malware sample overlap with attributed campaigns, 
no infrastructure linkage to documented groups, possibility of deliberate 
time-zone spoofing."

Confidence Language in Practice

CONFIDENCE CALIBRATION EXAMPLES

HIGH CONFIDENCE statements:
"We assess with high confidence that the spearphishing campaign is ongoing — 
 we have confirmed active C2 infrastructure and three victims reported in the 
 past 7 days from direct incident data."

"The malware sample almost certainly belongs to the SUNBURST malware family — 
 the YARA rule developed by Mandiant matches 14 of 14 indicators."

MODERATE CONFIDENCE statements:
"This activity probably represents targeted espionage rather than opportunistic 
 access — the targeting of specific personnel (engineers, not executives) and 
 data of no obvious financial value suggests a collection goal."

"The group is likely state-sponsored based on the sophistication of tooling 
 and the absence of monetization attempts despite 6 weeks of dwell time."

LOW CONFIDENCE statements:
"This may be the same group that targeted [other organization] last quarter, 
 based on a single shared infrastructure indicator that may indicate vendor 
 reuse rather than actor overlap."

"The attacker possibly has access to unpatched internal systems — we have not 
 confirmed lateral movement beyond the initial foothold."

NEVER USE (overclaims certainty):
"This is definitely APT41."
"It is clear that the attackers are Russian."
"We know for certain that..."