Say How Sure.
Say How It Moves.
Two building blocks of writing and sharing CTI product: the ICD 203 Words of Estimative Probability that turn a gut feeling into a calibrated percentage band, and the STIX/TAXII pair that turns a paragraph of prose into structured objects a platform can actually ingest. One governs the language in the report. The other governs the data leaving your desk. Pair this with the Admiralty Code & TLP reference for the source-grading and sharing-marking half of the same workflow.
Words of Estimative Probability
ICD 203 (Intelligence Community Directive 203, "Analytic Standards") standardizes the language analysts use to express how likely something is, so "probably" means the same thing across every product and every analyst writing one. Each term maps to a percentage band, not a personal hunch, and CTI teams have informally adopted the same scale for the same reason: consistency across analysts. Analysts are directed not to mix terms from different rows in the same product, and each row offers two roughly interchangeable terms.
| Term | Probability Range | Example Usage |
|---|---|---|
| Almost No Chance | 01–05% | "There is almost no chance the actor retains access after the credential rotation completed." |
| Very Unlikely | 05–20% | "It is very unlikely this activity is unrelated to the phishing campaign reported last week." |
| Unlikely | 20–45% | "It is unlikely the actor pivoted to the finance segment before containment, based on available telemetry." |
| Roughly Even Chance | 45–55% | "There is roughly an even chance the second beacon shares infrastructure with the first, pending WHOIS corroboration." |
| Likely | 55–80% | "The intrusion set likely reused the loader observed in the March incident, based on shared code overlap." |
| Very Likely | 80–95% | "This domain is very likely part of the actor's known C2 infrastructure, given the registrar and TTP overlap." |
| Almost Certain(ly) | 95–99% | "The binary is almost certainly a variant of the malware family tracked in the prior campaign." |
Confidence In The Judgment ≠ Probability Of The Event
STIX & TAXII
Two complementary OASIS standards, currently STIX 2.1 and TAXII 2.1: STIX is the data format that describes threat intelligence as structured objects, TAXII is the transport protocol that moves those objects between platforms over HTTPS. STIX is transport-agnostic by design; TAXII is built specifically to carry it, and support for STIX 2.1 content is mandatory for any TAXII 2.1 implementation.
STIX Is The Format. TAXII Is The Pipe.
# the division of labor STIX 2.1 (data format) describes WHAT the intel is → indicator, malware, threat-actor, campaign, relationship, and other objects TAXII 2.1 (transport protocol) describes HOW it moves → HTTPS API, collections you subscribe to, mandatory STIX 2.1 support # a platform "pulling a feed" is a TAXII client polling a TAXII server's # collection endpoint and receiving STIX bundles back over HTTPS
| STIX Domain Object | What It Represents |
|---|---|
| Indicator | A pattern (hash, domain, IP, behavior signature) that can be used to detect suspicious or malicious cyber activity. |
| Malware | A type of TTP object representing malicious code, families, or capability characteristics. |
| Threat Actor | An individual, group, or organization believed to be operating with malicious intent. |
| Campaign | A grouping of adversarial behaviors describing a set of malicious activities or attacks over a period of time against a specific set of targets. |
| Intrusion Set | A grouped set of adversarial behaviors and resources with common properties believed to be orchestrated by a single organization. |
| Attack Pattern | A type of TTP object describing the ways adversaries attempt to compromise targets, commonly mapped to ATT&CK techniques. |
| Relationship | Links two STIX objects together to describe how they relate, e.g. an Indicator that "indicates" a Malware object. |
| Identity | An individual, organization, or group, or a class of them (e.g. "the finance sector"), referenced elsewhere in a bundle. |
| Report | A collection of threat intelligence focused on one or more topics, such as a threat actor, malware, or technique, bundling related objects with context. |
Where This Shows Up In Daily SOC/CTI Work
Both standards operate mostly in the background, one shaping how a report reads, the other shaping how a feed arrives, until something forces you to notice them.