Practitioner tradecraft. Not a glossary.
This manual is built for analysts who need to move from intelligence requirements to evidence-controlled outputs. It emphasizes defensible reasoning, explicit uncertainty, reproducible workflows, and operational usefulness.
- Define PIRs and SIRs before collecting anything
- Rate every source on the A–F / 1–6 Admiralty scale
- Extract claims and label evidence (Observed / Reported / Assessed)
- Document assumptions, gaps, and alternative hypotheses
- Map behavior to ATT&CK only when evidence supports it
- Convert intelligence findings into telemetry requirements and detection candidates
- Hand off to SOC with readiness level, replay guidance, and false-positive classes
Outputs, not just analysis.
Every module maps to concrete deliverables. The manual is organized around what analysts produce — not concepts they should know.
10 Modules
Each module covers one area of CTI tradecraft in depth — from foundations through technical analysis to detection engineering and SOC integration. Use the role-based reading paths to navigate by analyst function.
CTI Foundations
PIRs, SIRs, EEIs, evidence labels, source reliability (A–F / 1–6), confidence language, and finished intelligence discipline. The analytic foundation everything else depends on.
Open module →Module 02Analytic Discipline
Explicit assumptions, known gaps, alternative hypotheses, contradiction handling, and Sherman Kent–style probabilistic rigor. How to reason in the presence of incomplete information.
Open module →Module 03Frameworks
ATT&CK, Kill Chain, Diamond Model, and Pyramid of Pain as working analytic tools. How to apply each to real intelligence problems — not as compliance checkboxes.
Open module →Module 04Attribution
Weighting tooling, infrastructure, victimology, timing, language artifacts, and competing hypotheses. When you can assert attribution and when you cannot.
Open module →Module 05Infrastructure Pivoting
From single IOC to defensible cluster: passive DNS, certificate analysis, ASN pivoting, domain pattern recognition, and bounded-cluster reasoning with explicit limitations.
Open module →Module 06CTI to Detection
Convert intelligence into telemetry requirements, hunting hypotheses, detection logic, detection readiness levels (DRL), SOC handoff notes, and validated coverage scores.
Open module →Module 07AI-Assisted Workflows
Controlled AI integration for CTI tasks: prompt design, hallucination control, data classification, prohibited uses, review workflows, and task-control matrices.
Open module →Module 08Actor Research
Structured actor profiling, profile update workflows, alias tables, and worked examples anchored in the MuddyWater/Seedworm case study.
Open module →Module 09Telemetry Reference
Windows Event Log, Sysmon, EDR process events, DNS, proxy/web gateway, cloud audit logs, identity provider signals, and RMM abuse telemetry.
Open module →Module 10SOC Integration
SOC handoff notes, triage and response playbooks, and the full analyst workflow from collection requirements through finished intelligence to detection backlog.
Open module →88 Workflow Infographics
Every major concept has a visual workflow companion — from intelligence cycle to evidence labels, from ATT&CK mapping to CTI-to-detection pipeline. Built for use as desk references and in team training.




Operating Principles
The manual applies a consistent analytic standard across all modules. These principles govern when to assert a finding, how to hedge it, and how to make the reasoning chain auditable.

CTI → Detection Chain
Module 06 covers the full translation from intelligence finding to detection-ready output: telemetry requirements, hunting hypotheses, DRL scoring, SOC handoff, and replay artifacts. This is the chain that makes CTI operationally useful.


Part of a Connected CTI Platform
This manual is the tradecraft standard. The ecosystem projects apply that standard in labs, case studies, customer deliveries, and a live OpenCTI platform.
Defensive. Public-source. TLP:CLEAR.
All material in this manual is public, defensive, and oriented toward blue-team practitioners. It excludes malware source code, exploit instructions, leaked data, credentials, victim-sensitive information, and operational guidance for unauthorized access. The manual does not provide definitive attribution — it provides a methodology for making analytic judgments with explicit confidence levels and documented limitations.
