Module 2: Build an Evidence Base

Collect Evidence With a Plan

Use a collection plan to search deliberately instead of accumulating unstructured threat information.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Create a collection plan that maps intelligence questions to sources, search methods, and evidence records.

Collect Evidence With a Plan

This lesson turns collection into a controlled activity. You will map requirements to sources, choose search terms, record provenance, and stop collecting when the evidence is sufficient for the decision at hand.

Map Questions to Sources

Collection begins with the requirement, not with an interesting search result. For each question, write down the evidence that could answer it and the sources most likely to contain that evidence. A public advisory may describe exploitation and affected products. Vendor documentation may clarify a product version. Internal DNS, proxy, identity, or endpoint telemetry may reveal whether your own organization observed the activity.

Keep public and internal evidence distinct. Public reporting can explain what others observed, but it cannot prove that Northstar Freight was affected. Conversely, an absence of internal sightings is meaningful only when the relevant systems were monitored, the time window was covered, and the data was retained. Record those boundaries beside the result.

A collection plan can be a small table with five columns: requirement, source, query or method, time window, and expected output. Before searching, define terms and synonyms. During searching, record the original URL, publication date, access date, and the exact claim you are using. This makes later review faster and more honest.

Search Broadly, Record Narrowly

Public collection is often a search problem. Start broad enough to discover vocabulary, then narrow the search around the exact requirement. Search an advisory title, a product and version, a malware family, a domain, or a technique separately. Compare the results rather than copying the first page that confirms your expectation.

Record negative results carefully. “No evidence found” is not the same as “the activity did not occur.” A useful negative result states what was searched, where, for which period, with which limitations. Search engines change rankings, pages disappear, and public sources copy one another. Preserve the page title, URL, date, quoted claim, and a short note about why it matters.

Stay within authorization and applicable law. Do not bypass access controls, probe systems, create accounts to evade restrictions, or collect personal data that is not necessary for the requirement. Intelligence quality includes responsible handling: a technically clever collection method that creates avoidable legal or privacy risk is not a good method.

Resources

  • CISA Known Exploited Vulnerabilities Catalog — Practice recording a primary public source, publication context, and the difference between known exploitation and local exposure.
  • MITRE ATT&CK — Use ATT&CK as a behavior vocabulary and starting point for defensive research, not as proof that a named actor caused an event.