H3AD-REF / REFERENCES / ADMIRALTY CODE & TLP

Rate The Source.
Label The Sharing.

Two classification systems that show up in almost every intel report you'll write or read: the Admiralty Code for grading a source and the information it handed you, and the Traffic Light Protocol for marking how far that information is allowed to travel. Static definitions, worked examples, no ambiguity about what a letter, number, or color actually permits. Every indicator on the IOC vs IOA reference should carry a grade from this page before it gets actioned.

The Admiralty Code

A two-character grade, one letter and one number, first used by British naval intelligence and now standard across NATO, law enforcement fusion centers, and CTI shops. The letter rates the source. The number rates the specific piece of information in front of you. They are scored separately, then combined, such as B2 or F6.

SCALE

Source Reliability (A–F)

GradeLabelDescription
ACompletely reliableNo doubt of authenticity, trustworthiness, or competency; history of complete reliability.
BUsually reliableMinor doubt about authenticity, trustworthiness, or competency; history of valid information most of the time.
CFairly reliableDoubt of authenticity, trustworthiness, or competency, but has provided valid information in the past.
DNot usually reliableSignificant doubt about authenticity, trustworthiness, or competency, but has provided valid information in the past.
EUnreliableLacking in authenticity, trustworthiness, and competency; history of invalid information.
FReliability cannot be judgedNo basis exists for evaluating the reliability of the source.
SCALE

Information Credibility (1–6)

GradeLabelDescription
1ConfirmedConfirmed by other independent sources; logical in itself; consistent with other information on the subject.
2Probably trueNot confirmed; logical in itself; consistent with other information on the subject.
3Possibly trueNot confirmed; reasonably logical in itself; agrees with some other information on the subject.
4DoubtfulNot confirmed; possible but not logical in itself; no other information on the subject.
5ImprobableNot confirmed; not logical in itself; contradicted by other information on the subject.
6Cannot be judgedNo basis exists for evaluating the validity of the information.
WORKED EXAMPLE

B2 — A Trusted Feed, Not Yet Corroborated

The grade you'll write down most often in practice
A commercial threat feed with a solid track record reports a new C2 domain tied to a known actor. The feed itself has been right often enough to earn B, usually reliable. This specific domain hasn't been confirmed by a second independent source yet, but it's logical and fits the actor's known infrastructure pattern, so the information gets 2, probably true. Combined grade: B2. Actionable, worth blocking, still flagged as unconfirmed in the write-up.
WORKED EXAMPLE

F6 — An Unvetted Anonymous Tip

The grade that means "don't act on this alone"
An anonymous submission lands in a tip line with no prior history to judge and no way to verify who sent it: the source gets F, reliability cannot be judged. The claim inside it also has nothing to check it against, no corroboration, no known pattern to compare it to: the information gets 6, cannot be judged. F6 doesn't mean discard it, it means it needs independent verification before it drives any decision.

Applying It In Practice

The scale is simple. Using it correctly over time, across a team, is where most of the actual discipline lives. See SANS's Enhance Your Cyber Threat Intelligence With The Admiralty System for the source this section draws from.

PRACTICE

Grade The Source And The Claim Independently

Don't let one number infect the other
A source's letter grade and a claim's number grade are scored separately on purpose. A generally reliable source can still hand you an unconfirmed claim, and an unreliable source can occasionally be right. Grading them together produces a false sense of confidence, or a false dismissal, in either direction.
PRACTICE

Ratings Are Not Static

A source's track record changes, sometimes fast
A newly identified threat actor's reporting can move from an F6 to a B2 in a matter of days as corroboration accumulates. A source rated A on one subject is not automatically A on an unrelated one; reliability is per-topic, not a permanent label on the source itself.
PRACTICE

Don't Customize The Scale

Consistency is what makes it shareable
The Admiralty System is meant to mean the same thing everywhere it's used. Adjusting the criteria per team or per organization breaks compatibility the moment that intelligence gets shared externally. Define how a grade should change your team's response internally, without changing what the grade itself means.
PITFALL

An A1 Is Still Not A Guarantee

The highest grade reduces risk, it doesn't eliminate it
Even a source and claim graded A1 can be wrong. Treat a top grade as license to act with confidence, not as a reason to skip verification entirely when the stakes are high enough to justify a second check.

Traffic Light Protocol (TLP 2.0)

TLP marks how far a piece of shared information is allowed to travel, not how sensitive it is on its own. Five levels as of TLP 2.0 (FIRST.org, current standard): TLP:RED, TLP:AMBER+STRICT, TLP:AMBER, TLP:GREEN, TLP:CLEAR. TLP:CLEAR replaced the older TLP:WHITE, and AMBER+STRICT was added to give AMBER a tighter option.

LevelBadgeWho Can See ItTypical Use Case
TLP:RED RED Named recipients only, in the exchange it was shared in. No further disclosure. Active-compromise specifics shared live with an incident bridge, before containment is confirmed.
TLP:AMBER+STRICT AMBER+STRICT The recipient's own organization only. No client or partner sharing. Vendor-shared indicators under a contract that forbids re-sharing beyond your org.
TLP:AMBER AMBER The recipient's organization and its clients, need-to-know basis only. An MSSP advisory that needs to reach the client's own security team to be actioned.
TLP:GREEN GREEN Peers and partner organizations within the community, never public channels. ISAC bulletin or sector threat-sharing group post.
TLP:CLEAR CLEAR No restriction, subject to standard copyright. A published blog post, public CVE writeup, or conference talk.
HANDLING

TLP:RED Stays In The Room

No forwarding, no paraphrasing into a broader channel
TLP:RED means the named recipients and no one else, not even a summarized version dropped into a wider ticket or channel. If information can't be effectively acted on without real risk to privacy, reputation, or operations if it leaks, it's RED, full stop.
HANDLING

AMBER vs. AMBER+STRICT

The distinction that trips people up most
Plain TLP:AMBER allows sharing with your own organization and its clients, on a need-to-know basis. TLP:AMBER+STRICT removes the client clause entirely: it's restricted to the recipient's own organization only. When a vendor or partner marks something AMBER+STRICT, forwarding it to a client, even one who needs to know, is a violation of the marking.
HANDLING

TLP:CLEAR Has No Gate

The only level meant for public release
TLP:CLEAR is for information that carries minimal or no foreseeable risk of misuse and is meant for public release. It can be shared without restriction, subject to ordinary copyright, which is exactly why it's the wrong marking for anything still under active investigation.

Where This Shows Up In Daily SOC/CTI Work

Neither system is academic. Both get written down, every day, on the reports and feeds that leave your desk.

CTI

Rating An Intel Report Before Dissemination

The Admiralty grade an analyst attaches before it goes out
A finished intel product gets an Admiralty grade on every claim inside it, source letter plus information number, so the reader downstream knows exactly how much weight to put on each line without having to ask the analyst who wrote it.
FEED HYGIENE

Labeling A Shared IOC Feed

TLP travels with the indicators, not just the report
An IOC feed shared with a partner or an ISAC carries a TLP marking on the feed itself, and every consumer downstream is bound by it. Re-exporting AMBER indicators into a public feed is a policy breach even if the indicators themselves look harmless.
IR

Handling Instructions On An Incident Report

Where TLP and Admiralty sit side by side
A post-incident report commonly carries both: a TLP marking at the top setting who's allowed to read it, and Admiralty grades on the individual findings inside setting how much confidence to put in each one.