H3AD-REF / REFERENCES / CTI ANALYST REFERENCE

Say How Sure.
Say How It Moves.

Two building blocks of writing and sharing CTI product: the ICD 203 Words of Estimative Probability that turn a gut feeling into a calibrated percentage band, and the STIX/TAXII pair that turns a paragraph of prose into structured objects a platform can actually ingest. One governs the language in the report. The other governs the data leaving your desk. Pair this with the Admiralty Code & TLP reference for the source-grading and sharing-marking half of the same workflow.

Words of Estimative Probability

ICD 203 (Intelligence Community Directive 203, "Analytic Standards") standardizes the language analysts use to express how likely something is, so "probably" means the same thing across every product and every analyst writing one. Each term maps to a percentage band, not a personal hunch, and CTI teams have informally adopted the same scale for the same reason: consistency across analysts. Analysts are directed not to mix terms from different rows in the same product, and each row offers two roughly interchangeable terms.

TermProbability RangeExample Usage
Almost No Chance01–05%"There is almost no chance the actor retains access after the credential rotation completed."
Very Unlikely05–20%"It is very unlikely this activity is unrelated to the phishing campaign reported last week."
Unlikely20–45%"It is unlikely the actor pivoted to the finance segment before containment, based on available telemetry."
Roughly Even Chance45–55%"There is roughly an even chance the second beacon shares infrastructure with the first, pending WHOIS corroboration."
Likely55–80%"The intrusion set likely reused the loader observed in the March incident, based on shared code overlap."
Very Likely80–95%"This domain is very likely part of the actor's known C2 infrastructure, given the registrar and TTP overlap."
Almost Certain(ly)95–99%"The binary is almost certainly a variant of the malware family tracked in the prior campaign."
ICD 203

Confidence In The Judgment ≠ Probability Of The Event

Two separate axes, never collapsed into one word
ICD 203 treats these as independent measurements. Likelihood is the words-of-estimative-probability term above, how probable the event itself is. Confidence is a separate low/moderate/high rating of how solid the evidentiary basis is: source reliability, corroboration, and the soundness of the analytic method. An analyst can hold high confidence in a low-likelihood judgment when the sources are strong and consistent even though the event itself remains improbable, or the reverse: an event assessed as likely, held with only moderate confidence because the reporting is thin. The standard for practitioners: don't combine a confidence level and a likelihood term in the same sentence, state them separately so the reader can weigh each on its own.

STIX & TAXII

Two complementary OASIS standards, currently STIX 2.1 and TAXII 2.1: STIX is the data format that describes threat intelligence as structured objects, TAXII is the transport protocol that moves those objects between platforms over HTTPS. STIX is transport-agnostic by design; TAXII is built specifically to carry it, and support for STIX 2.1 content is mandatory for any TAXII 2.1 implementation.

STIX Is The Format. TAXII Is The Pipe.

# the division of labor
STIX 2.1   (data format)    describes WHAT the intel is
             → indicator, malware, threat-actor, campaign, relationship, and other objects

TAXII 2.1  (transport protocol)   describes HOW it moves
             → HTTPS API, collections you subscribe to, mandatory STIX 2.1 support

# a platform "pulling a feed" is a TAXII client polling a TAXII server's
# collection endpoint and receiving STIX bundles back over HTTPS
STIX Domain ObjectWhat It Represents
IndicatorA pattern (hash, domain, IP, behavior signature) that can be used to detect suspicious or malicious cyber activity.
MalwareA type of TTP object representing malicious code, families, or capability characteristics.
Threat ActorAn individual, group, or organization believed to be operating with malicious intent.
CampaignA grouping of adversarial behaviors describing a set of malicious activities or attacks over a period of time against a specific set of targets.
Intrusion SetA grouped set of adversarial behaviors and resources with common properties believed to be orchestrated by a single organization.
Attack PatternA type of TTP object describing the ways adversaries attempt to compromise targets, commonly mapped to ATT&CK techniques.
RelationshipLinks two STIX objects together to describe how they relate, e.g. an Indicator that "indicates" a Malware object.
IdentityAn individual, organization, or group, or a class of them (e.g. "the finance sector"), referenced elsewhere in a bundle.
ReportA collection of threat intelligence focused on one or more topics, such as a threat actor, malware, or technique, bundling related objects with context.

Where This Shows Up In Daily SOC/CTI Work

Both standards operate mostly in the background, one shaping how a report reads, the other shaping how a feed arrives, until something forces you to notice them.

CTI

Reading A Vendor Report's Confidence Language Correctly

"Likely" and "high confidence" are not the same claim
A vendor report saying an actor "likely" compromised a host is making a probability statement, 55–80% on the ICD 203 scale. If the same report separately notes "high confidence," that's a statement about the evidence quality behind the judgment, not a stronger version of "likely." Reading the two together, correctly, changes how much weight the finding should carry in your own write-up.
TOOLING

Why Your Intel Platform Imports Bundles, Not A CSV

Structure survives the round trip, a spreadsheet doesn't
A STIX bundle keeps an indicator's relationships intact: which malware it indicates, which campaign that malware belongs to, which actor runs the campaign. Flatten that into a CSV and the relationships are gone, just isolated rows. That's why any platform doing real correlation asks for a STIX import rather than a spreadsheet of IOCs.
FEED HYGIENE

TAXII Is Why Your Feed "Just Updates"

Polling a collection, not refreshing a page
When a threat intel platform's feed updates itself with no manual export/import step, a TAXII client is polling a TAXII server's collection endpoint on a schedule and pulling new STIX bundles over HTTPS automatically. The "it just works" feeling is TAXII doing its one job quietly in the background.