Skip to main content
Practitioner Field Manual · 10 Modules · 80+ Pages

CTI Analyst Field Manual

From collection requirements to defensible analytic judgment, hunting hypotheses, and detection-ready outputs. Evidence discipline, attribution methodology, infrastructure pivoting, and CTI-to-detection chain — structured for working analysts.

✦ Readiness Score 8.8 / 10
CTI Analyst Field Manual — module overview
80+Pages
10Modules
88Infographics
8.8Readiness Score
TLP:CLEARClassification

Practitioner tradecraft. Not a glossary.

This manual is built for analysts who need to move from intelligence requirements to evidence-controlled outputs. It emphasizes defensible reasoning, explicit uncertainty, reproducible workflows, and operational usefulness.

  • Define PIRs and SIRs before collecting anything
  • Rate every source on the A–F / 1–6 Admiralty scale
  • Extract claims and label evidence (Observed / Reported / Assessed)
  • Document assumptions, gaps, and alternative hypotheses
  • Map behavior to ATT&CK only when evidence supports it
  • Convert intelligence findings into telemetry requirements and detection candidates
  • Hand off to SOC with readiness level, replay guidance, and false-positive classes

Outputs, not just analysis.

Every module maps to concrete deliverables. The manual is organized around what analysts produce — not concepts they should know.

Source RegisterEvidence RegisterActor ProfileInfrastructure Pivot LogCollection Gap RegisterHunting HypothesisDetection Backlog ItemSOC Handoff NoteFinished Intelligence ReportDRL Coverage Score

10 Modules

Each module covers one area of CTI tradecraft in depth — from foundations through technical analysis to detection engineering and SOC integration. Use the role-based reading paths to navigate by analyst function.

Module 01

CTI Foundations

PIRs, SIRs, EEIs, evidence labels, source reliability (A–F / 1–6), confidence language, and finished intelligence discipline. The analytic foundation everything else depends on.

Open module →
Module 02

Analytic Discipline

Explicit assumptions, known gaps, alternative hypotheses, contradiction handling, and Sherman Kent–style probabilistic rigor. How to reason in the presence of incomplete information.

Open module →
Module 03

Frameworks

ATT&CK, Kill Chain, Diamond Model, and Pyramid of Pain as working analytic tools. How to apply each to real intelligence problems — not as compliance checkboxes.

Open module →
Module 04

Attribution

Weighting tooling, infrastructure, victimology, timing, language artifacts, and competing hypotheses. When you can assert attribution and when you cannot.

Open module →
Module 05

Infrastructure Pivoting

From single IOC to defensible cluster: passive DNS, certificate analysis, ASN pivoting, domain pattern recognition, and bounded-cluster reasoning with explicit limitations.

Open module →
Module 06

CTI to Detection

Convert intelligence into telemetry requirements, hunting hypotheses, detection logic, detection readiness levels (DRL), SOC handoff notes, and validated coverage scores.

Open module →
Module 07

AI-Assisted Workflows

Controlled AI integration for CTI tasks: prompt design, hallucination control, data classification, prohibited uses, review workflows, and task-control matrices.

Open module →
Module 08

Actor Research

Structured actor profiling, profile update workflows, alias tables, and worked examples anchored in the MuddyWater/Seedworm case study.

Open module →
Module 09

Telemetry Reference

Windows Event Log, Sysmon, EDR process events, DNS, proxy/web gateway, cloud audit logs, identity provider signals, and RMM abuse telemetry.

Open module →
Module 10

SOC Integration

SOC handoff notes, triage and response playbooks, and the full analyst workflow from collection requirements through finished intelligence to detection backlog.

Open module →

88 Workflow Infographics

Every major concept has a visual workflow companion — from intelligence cycle to evidence labels, from ATT&CK mapping to CTI-to-detection pipeline. Built for use as desk references and in team training.

What This Manual Is
What This Manual Is
Intelligence Cycle
Intelligence Cycle
Evidence Labels
Evidence Labels
CTI → Detection Workflow
CTI → Detection Workflow

Operating Principles

The manual applies a consistent analytic standard across all modules. These principles govern when to assert a finding, how to hedge it, and how to make the reasoning chain auditable.

CTI Analyst Field Manual — Operating Principles

CTI → Detection Chain

Module 06 covers the full translation from intelligence finding to detection-ready output: telemetry requirements, hunting hypotheses, DRL scoring, SOC handoff, and replay artifacts. This is the chain that makes CTI operationally useful.

Intelligence to Detection WorkflowDetection Readiness Level Scale Reference

Defensive. Public-source. TLP:CLEAR.

All material in this manual is public, defensive, and oriented toward blue-team practitioners. It excludes malware source code, exploit instructions, leaked data, credentials, victim-sensitive information, and operational guidance for unauthorized access. The manual does not provide definitive attribution — it provides a methodology for making analytic judgments with explicit confidence levels and documented limitations.