CTI Report Writing
Most threat intelligence analysis never becomes finished intelligence because analysts do not know how to write for their audience. A technically rigorous analysis delivered in the wrong format to the wrong reader is wasted work. This chapter covers how to structure CTI products for the audiences that consume them, how to apply confidence language that is precise without being evasive, and how to measure whether your reports are actually being used.
Intelligence Products
An intelligence product is a finished deliverable that communicates analyzed intelligence to a specific consumer for a specific purpose. Different consumers need different product types. A product that works for a SOC analyst will not work for a CISO, and a product designed for a CISO will not give an IR team what they need to act. Matching product type to consumer is the first decision in any CTI production workflow.
Tactical bulletins are short, time-sensitive products covering active threats. A tactical bulletin might cover a newly observed phishing campaign: the lure type, the delivery mechanism, the payload family, and what to block or hunt for. Format is short: one to two pages, bullet-heavy, with an IOC appendix. Audience is SOC analysts and incident responders who need to act immediately. A tactical bulletin that takes longer than five minutes to act on has failed its format requirement.
Strategic assessments are longer-form products covering trends, actor landscape changes, or sector-level risk. They operate on quarterly or annual time horizons and are written for senior leadership. A strategic assessment might analyze how ransomware targeting patterns in the healthcare sector changed over 18 months and what that means for organizational risk posture going into the next year. Format is narrative with supporting data, clear key judgments at the front, and an executive summary that contains the conclusions rather than deferring to the body of the report.
Campaign reports cover a specific observed adversary campaign: who, what, when, and how. They include actor attribution (with confidence level), technique timeline, TTPs, IOCs, and defensive recommendations. Campaign reports bridge tactical and operational intelligence: they give analysts enough technical detail to act while giving management enough context to understand scope and impact. Format follows a consistent template: executive summary, actor assessment, campaign timeline, technical analysis, IOCs and YARA, and recommended mitigations.
Flash reports are the most urgent product type: one-paragraph notifications that something significant has happened, with enough information to enable immediate action and a commitment to follow-up detail. A flash report might cover a zero-day disclosure affecting a widely deployed product in your environment, a credible nation-state targeting alert from a government source, or an emerging ransomware campaign observed in your sector within the last 24 hours. Speed is the primary value here; depth comes in the follow-on report.
| Product Type | Time Horizon | Primary Audience | Length |
|---|---|---|---|
| Flash report | Hours | SOC, IR, management | One paragraph |
| Tactical bulletin | Days | SOC analysts, IR teams | 1-2 pages + IOC appendix |
| Campaign report | Weeks | SOC, IR, security managers | 5-10 pages |
| Strategic assessment | Months to years | CISO, executives, board | 10-20 pages |
PIRs, RFIs, and Stakeholder Alignment
Every intelligence product should trace to a requirement. Products that do not trace to a requirement are analytical exercises without guaranteed consumers. Before writing anything, identify: which PIR or SIR does this address? Who will receive it? What decision does it support? Answering these questions before writing ensures the product has a purpose and shapes every subsequent decision about what to include, what to omit, and how to structure the output.
Stakeholder alignment is the process of ensuring your intelligence products match what consumers actually need. The gap between what analysts think is important and what consumers need to act is one of the most common CTI program failure modes. An analyst who spent three weeks deeply analyzing a complex APT campaign may be surprised when the CISO asks for "just one sentence that tells me if we need to change our security posture." That sentence is not a failure of the CISO to appreciate complexity; it is a failure of the analyst to understand what their consumer needs.
Regular touchpoints with intelligence consumers prevent this misalignment from accumulating. A quarterly review of PIRs with the CISO and security team leadership ensures the requirements driving CTI production reflect current organizational priorities. A monthly debrief with SOC team leads ensures tactical products are providing value at the analyst level. Feedback from these sessions should directly update PIRs and product templates.
RFIs (Requests for Information) require a different workflow than PIR-driven production. An RFI arrives with urgency: an IR team on an active case, a manager responding to a board question, a compliance team preparing for a regulatory submission. Triage the RFI immediately: can it be answered from existing collection, or does it require new research? Set an expectation with the requester: "I can give you a preliminary response in 2 hours with what we know now, and a full analysis in 24 hours." Then deliver on that timeline. Late RFI responses are worse than no response because they created an expectation that was not met.
BLUF and Structured Intelligence Writing
BLUF (Bottom Line Up Front) is the most important structural principle in intelligence writing. In BLUF structure, the most important conclusion comes first, followed by the supporting analysis. This is the opposite of how most people learn to write academically, where you build to your conclusion at the end. Intelligence consumers do not have time to read to the end before deciding whether the report is relevant to them. If the conclusion is buried on page 5, most readers will not reach it.
A well-structured campaign report leads with a BLUF box: two to four sentences that state the actor, the campaign objective, the current threat level to the organization, and the most important recommended action. After the BLUF comes the executive summary (for reports longer than two pages): a narrative paragraph that expands on the BLUF with key supporting facts. The body of the report contains the full analysis. Appendices contain raw IOCs, YARA rules, and technical details that analysts need but that would interrupt the narrative for a management reader.
Key judgments are precise statements of assessed fact, clearly distinguished from speculative interpretation. A key judgment reads: "We assess with moderate confidence that this activity is attributable to APT29 based on toolset similarities, infrastructure overlap with previously attributed campaigns, and targeting pattern consistency with known APT29 collection objectives." That sentence contains: the assessment (attributable to APT29), the confidence level (moderate), the basis (three specific evidence types), and the reasoning (targeting consistency). Every element is explicit. No element is hidden in passive voice or buried in a subordinate clause.
Confidence language should be precise and consistent. The intelligence community uses a standardized vocabulary: "almost certainly" (90%+), "likely" (55-75%), "roughly even chance" (45-55%), "unlikely" (25-45%), "remote" (less than 10%). Using these terms consistently throughout your organization's CTI products means that readers can calibrate their response to the level of certainty expressed. An analyst who uses "likely" to mean 60% and "probably" to mean the same thing has introduced ambiguity that a reader cannot resolve without asking follow-up questions.
Executive vs Technical Reports
The same intelligence event should produce different products for different audiences. An IR manager needs the technical IOC list and behavioral indicators to direct the investigation. The CISO needs the business impact, the attribution confidence, and the recommended organizational response. A board member needs one paragraph on the nature of the threat and one paragraph on what is being done about it. None of these audiences reads the same document effectively.
Writing for executives requires the following adaptations. Eliminate technical jargon: "the actor used T1059.001 PowerShell IEX cradle to load a reflective DLL" becomes "the attacker used legitimate Windows scripting tools to execute malicious code in memory, bypassing traditional file-based detection." Quantify impact wherever possible: "five systems compromised" is more useful than "moderate intrusion scope." Lead with relevance: "This campaign is targeting companies with annual revenue above $500M in the US financial sector — we match both criteria" tells the CISO immediately why this matters to them.
Writing for technical audiences requires the opposite adaptations. Precision over simplicity: use ATT&CK technique IDs, specific tool names, exact command line patterns, and precise log source references. Include everything the analyst needs to search for the behavior: the exact SIEM query or its components, the specific Event IDs to check, the exact file paths and registry keys to examine. Do not summarize; include the raw data in appendices so analysts can work from primary sources rather than a filtered abstraction.
A practical structure for large campaign reports accommodates both audiences: executive summary (1 page, BLUF, business impact, recommended action), technical analysis (body of the report, full detail for technical audience), IOC appendix (CSV-formatted indicators ready for SIEM import), and detection appendix (Sigma rules, YARA rules, KQL queries). An executive reads the first page and skips to the conclusion. A SOC analyst skips the first page and goes directly to the appendices. Both get what they need from one document.
Dissemination and Metrics
A report is only intelligence if it reaches and is used by its intended consumer. Dissemination is the delivery step: the right format, through the right channel, to the right person, at the right time. Each variable matters. A technically correct report sent to an email distribution list that no one reads is not disseminated intelligence. A flash report delivered via Slack with a clear action item is.
Channel selection depends on urgency and audience. Automated SIEM integration (STIX/TAXII ingestion) is the fastest channel for technical IOCs. Slack or Teams for time-sensitive analyst alerts. Formal report delivery via email or a shared intelligence portal for campaign reports and strategic assessments. Verbal briefing for executive-level strategic intelligence, often more effective than a written document for an audience that reads email selectively.
Timing is a critical dimension. Intelligence delivered after the decision window has closed is worthless. A campaign report about an intrusion technique delivered after the actor has already been evicted from the environment is interesting but does not improve the organization's position. Building feedback loops with consumers helps calibrate timing: "When does the SOC shift change, so I can deliver tactical reports before the new shift starts?" "When is the CISO's monthly security review, so strategic assessments arrive with enough time for preparation?"
Measuring report quality requires consumer feedback, not just delivery confirmation. Metrics that matter include: Was the intelligence acted on? Did it change a decision? Did it produce a detection or a hunt that found something? Did it support an executive talking point that prevented a board escalation? These outcomes are harder to measure than delivery metrics but are the only ones that demonstrate CTI program value. Build a simple feedback mechanism into every report: a one-question form, a Slack reaction, a follow-up conversation. Track the answers. Use them to improve the next product.
Key Takeaways
- Intelligence products must match the consumer: flash reports (hours, everyone), tactical bulletins (days, SOC/IR), campaign reports (weeks, technical teams), strategic assessments (months, executives/CISO).
- Every product should trace to a PIR or RFI. Products without a mapped requirement have no guaranteed consumer and waste analytical resources.
- BLUF structure: conclusion first, support second. Key judgments are precise, stated with explicit confidence levels, with reasoning visible to the reader.
- Confidence language should be consistent and calibrated: "almost certainly," "likely," "roughly even chance," "unlikely," "remote." Hedging is not uncertainty expression — it avoids making any claim at all.
- Executive reports eliminate jargon, quantify impact, lead with relevance. Technical reports use precise ATT&CK language, exact log sources, and raw indicator appendices. Both can live in the same document with clear structure.
- Dissemination metrics that matter are outcomes: was it acted on, did it change a decision, did it produce a detection? Delivery confirmation is not a quality metric.
Knowledge Check
Click an answer to reveal the explanation.
You write a campaign report where the first two pages are methodology and data sources, and the conclusion appears on page 8. What is the primary problem with this structure?
A CTI analyst writes: "It is possible that this activity could potentially be associated with a nation-state actor." What is wrong with this statement?
A CISO asks what your CTI team's impact was last quarter. The most useful metric to provide is: