3. Collection, Sources, and Evidence

Collection Planning and Provenance

Select proportionate sources, document where evidence came from, and preserve the context required for later verification and lawful use.

In this lesson, you will learn to:

  • Create a lawful, ethical, and proportionate collection plan that maps information needs to sources while preserving provenance and handling requirements.

Collection Planning and Provenance

Plan collection from the requirement

Collection is purposeful acquisition of information that can address an intelligence requirement. It is not the accumulation of everything that might someday be useful. A collection plan translates each information need into bounded, lawful, ethical, and proportionate tasks.

The planning chain should remain visible:

Element Planning question Northbridge example
Decision What choice must the consumer make? Which recovery exercises should the resilience lead prioritize this quarter?
Requirement Which uncertainty must be reduced? Which plausible extortion scenarios could disrupt critical services?
Information need What evidence would help answer it? Current external exposure, privileged access paths, service dependencies, relevant incident history, and observed adversary behaviors
Source Where could that evidence be obtained responsibly? Asset inventory, identity records, service maps, incident tickets, security telemetry, trusted partner reporting, and credible public research
Collection task Who will obtain what, how, and by when? The identity team will provide a current list of privileged third-party access paths, with owners and review dates, by Friday.
Evaluation trigger When should the task change or stop? Stop when the scoped access paths are accounted for, or revise if records are incomplete.

A source is not a requirement, and access to a source does not justify collecting from it. Starting with “What feeds do we have?” encourages collection habits that consume time without reducing the uncertainty that matters.

Build a collection matrix

A practical collection matrix turns information needs into accountable work:

Information need Candidate source Contribution Limitations and risks Owner and timing
Internet-facing services supporting critical operations Asset inventory plus external exposure scan Identifies reachable systems and responsible teams Inventory may be stale; scanning requires authorization and can affect fragile systems Exposure-management lead; snapshot within two business days
Privileged third-party access Identity platform, contracts, and service owners Reveals trusted pathways and business purpose Records may omit shared or emergency access; includes sensitive personal and commercial data Identity lead; approved query by Friday
Relevant extortion behaviors Internal incident history and trusted external reporting Provides observed methods and conditions Reporting bias may favor visible incidents; external cases may not transfer to Northbridge CTI analyst; review period defined in advance
Recovery dependencies Service maps, continuity plans, and owner interviews Shows where disruption could create material harm Documentation may reflect intended rather than actual operations Resilience analyst; validate with service owners

For every task, record:

  • the requirement and information need it supports;
  • the precise data or observation sought;
  • the source, access method, and responsible owner;
  • the time period, systems, people, or regions in scope;
  • legal authority, organizational policy, consent, and contractual limits;
  • privacy, safety, operational, and disclosure risks;
  • expected format, frequency, deadline, and retention period;
  • validation criteria and known limitations;
  • a stop, review, or escalation condition.

The matrix is a living plan. If early evidence weakens one explanation and strengthens another, collection priorities should change. Continuing every original task after the question has shifted wastes resources and may create unnecessary risk.

Select sources by fitness, not familiarity

Different sources reveal different parts of a problem. Internal telemetry can show what occurred in the organization’s environment. External reporting can describe behaviors observed elsewhere. Human sources can explain business context that technical records omit. None provides a complete view by itself.

Evaluate a candidate source against the task:

  1. Relevance: Can it address the specific information need?
  2. Access and authority: May the organization lawfully and ethically obtain and use it?
  3. Timeliness: Will it arrive while the decision is still open?
  4. Coverage: Which systems, people, regions, behaviors, and time periods does it include or omit?
  5. Granularity: Is it detailed enough for the judgment without collecting unnecessary material?
  6. Reliability and limitations: How is the source produced, and what errors or biases are plausible?
  7. Safety and proportionality: Could acquisition harm people, systems, investigations, partners, or organizational trust?
  8. Cost: What money, analyst time, infrastructure, or opportunity cost does it require?
  9. Corroboration value: Does it provide an independent view, or merely repeat the same underlying report?

More sources do not automatically create stronger evidence. Ten articles repeating one anonymous claim constitute one evidentiary lineage, not ten independent confirmations. Conversely, disagreement between sources may be analytically valuable because it exposes differences in timing, access, definitions, or incentives.

Apply lawful, ethical, and proportionate collection

Technical possibility is not permission. Collection must comply with applicable law, policy, contracts, authorization, privacy obligations, and handling rules. Analysts should involve appropriate legal, privacy, compliance, or operational authorities when the boundary is unclear.

Use three tests before approving a task:

  • Necessity: Is the information meaningfully connected to the requirement?
  • Proportionality: Is the expected intelligence value sufficient to justify the intrusion, cost, and risk?
  • Minimization: Can the need be met with less sensitive data, narrower scope, fewer fields, shorter retention, aggregation, or an existing approved source?

Suppose Northbridge wants to understand whether finance staff received suspicious messages. Collecting every employee’s full mailbox indefinitely would be excessive. A more proportionate plan might use an authorized search for specific, evidence-based characteristics over a defined period, restrict access to trained personnel, retain only relevant results, and document escalation rules.

Public availability does not remove ethical obligations. Public records can contain personal, inaccurate, or context-sensitive information. Avoid collecting personal data merely because it is accessible. Do not bypass access controls, misrepresent identity, purchase unlawfully obtained material, or interact with suspected adversaries without explicit authority and a safety plan.

Design for gaps and change

A good collection plan does not promise complete visibility. It records gaps so analysts do not mistake absence of evidence for evidence of absence.

For each important gap, ask:

  • Is the relevant activity observable in principle?
  • Do we collect the necessary telemetry?
  • Is the source available for the required period?
  • Could processing or retention have removed the signal?
  • Would benign and malicious activity look similar?
  • Which alternative source could test the same proposition?
  • Would resolving the gap change the decision?

Prioritize gaps by decision impact. A missing log source that could distinguish between two materially different containment choices deserves more attention than a gap that would add interesting detail without changing action.

Worked example: from requirement to tasks

Northbridge must assess whether a third party creates a plausible privileged-access path to a critical payment service. The analyst decomposes the need:

  1. Identify third parties with current logical access to the service or its supporting systems.
  2. Determine the privileges, authentication controls, and access conditions.
  3. Establish whether the paths are monitored, reviewed, and revocable.
  4. Review internal incidents and credible external evidence about abuse of comparable access.
  5. Identify missing records that prevent a defensible judgment.

Collection tasks might include an approved identity query, review of remote-access configurations, confirmation with service owners, and examination of relevant incident records. The plan excludes unrelated employee activity and limits results to the systems and time window needed for the decision.

The analyst does not conclude that a third party is malicious. The task is to assess an exposure pathway and its conditions. This distinction prevents a risk question from becoming unjustified surveillance or attribution.

Analyst habit: For every requested field, complete the sentence: We need this information because it could change [specific judgment or decision]. If that connection is weak, narrow or remove the field.

Key takeaways
  • Collection begins with a decision-linked requirement, not an available feed.
  • A collection matrix connects information needs to sources, owners, timing, limitations, and stop conditions.
  • Source selection should reflect relevance, authority, coverage, timeliness, risk, cost, and independence.
  • Lawfulness, necessity, proportionality, and minimization are collection-quality requirements.
  • Visible gaps are more useful than false claims of complete coverage.

Preserve provenance, handling, and collection integrity

Collection produces material that other people must be able to interpret, evaluate, and handle correctly. Provenance is the documented history of where that material came from, when and how it was acquired, what happened to it afterward, and which limitations or controls apply.

Without provenance, a true observation may become unusable evidence. Consider the value 203.0.113.24. On its own, it does not reveal:

  • where it was observed;
  • whether it was a source, destination, relay, scanner, or shared service;
  • the relevant date and time zone;
  • which system or account was involved;
  • whether the value came from direct telemetry or a copied report;
  • how it was extracted, normalized, or enriched;
  • whether the source may be shared;
  • whether the address has since changed ownership or purpose.

A bare artifact invites overconfidence. A provenance-rich observation can be tested, compared, and used within defined limits.

Record the evidence lineage

For each collected item or dataset, preserve enough metadata to reconstruct its lineage:

Provenance element Questions to record
Origin Which person, organization, sensor, system, document, or dataset produced the material?
Acquisition Who collected it, by which authorized method, and under what request or requirement?
Time When did the underlying event occur, when was it observed, and when was it collected? Which time zone and clock assumptions apply?
Scope Which systems, users, regions, fields, filters, and time window were included or excluded?
Context During which incident, query, business process, or external report was it observed?
Transformation Was it parsed, translated, decoded, deduplicated, aggregated, filtered, enriched, or manually transcribed?
Integrity Was the original preserved? Are hashes, access logs, version identifiers, or other integrity checks available where appropriate?
Handling What sensitivity, privacy, contractual, legal, retention, or dissemination constraints apply?
Limitations Which gaps, errors, biases, ambiguities, or quality concerns are known?
Lineage Is this an independent observation or a repetition of another source’s claim?

Not every item requires forensic chain-of-custody procedures. The rigor should match its intended use and the consequences of error. A strategic trend assessment may rely on versioned datasets and documented methodology. An incident investigation may require preserved originals, cryptographic hashes, precise timestamps, and controlled access. Material that could support legal or disciplinary action should be handled under the organization’s formal evidence procedures.

Preserve originals and document transformations

Processing makes collected material usable, but it can also alter meaning. Common transformations include:

  • converting local time to Coordinated Universal Time;
  • parsing fields from logs or documents;
  • resolving domains or enriching addresses with ownership data;
  • translating text;
  • decoding files or network content;
  • deduplicating repeated events;
  • aggregating records into counts;
  • removing personal or sensitive fields;
  • labeling behavior with a framework or taxonomy.

Preserve the source material when authorized and necessary, and record the transformation logic. If a timestamp is corrected, retain both the original value and the basis for correction. If duplicates are removed, define what counted as a duplicate. If an automated system assigns a label, preserve the system version, relevant settings, and confidence or error information.

Transformations can introduce four common problems:

  1. Loss: Aggregation can hide sequence, outliers, or affected entities.
  2. Distortion: Translation or normalization can change nuance or precision.
  3. False independence: Deduplicated reports may still appear to corroborate one another even though they share an origin.
  4. Automation bias: A machine-generated classification may be treated as verified merely because it is structured.

Analysts should be able to distinguish what the source supplied from what their organization added.

Separate event time from knowledge time

CTI frequently involves several relevant timestamps:

Time Meaning
Event time When the underlying activity occurred
Observation time When a sensor or person recorded it
Collection time When the intelligence team acquired it
Publication time When a source released the report or claim
Enrichment time When contextual information was looked up
Assessment time When the analyst formed or updated a judgment

These times should not be collapsed. A domain may have resolved to an address when malicious activity occurred but resolve elsewhere when the analyst checks it later. A report published today may describe activity from months ago. An indicator may be accurate historically but no longer suitable for blocking.

Record time zones, daylight-saving assumptions, clock drift, and timestamp precision when they could affect sequence or causation. “09:12” is not precise evidence unless the date, zone, source clock, and meaning of the timestamp are understood.

Mark handling at the point of collection

Handling controls should travel with the information rather than being reconstructed just before dissemination. Depending on the organization and jurisdiction, relevant controls may include:

  • sensitivity or classification labels;
  • permitted recipients or communities;
  • restrictions on further sharing;
  • personal-data categories and lawful basis;
  • contractual or licensing conditions;
  • source-protection requirements;
  • retention and deletion schedules;
  • requirements for encryption, access logging, or secure storage;
  • restrictions on use in automated blocking or personnel decisions.

The most restrictive label is not automatically the safest choice. Excessive restriction can prevent defenders from acting, while insufficient restriction can expose people, methods, investigations, or partners. Apply the correct control, explain it clearly, and create sanitized or aggregated versions when broader use is necessary.

If the provenance of shared material is unclear, do not silently remove the ambiguity. Ask the provider, limit use, label the uncertainty, or decline to disseminate it.

Use source references without exposing sensitive origins

Analytic transparency does not require revealing every sensitive source to every consumer. A product can describe evidence in a way that supports evaluation while protecting identities and methods.

For example:

  • Too vague: “Sources say the activity is increasing.”
  • Too revealing: names a protected partner, individual, or collection method unnecessarily.
  • Better: “Two independent partners with direct visibility into incident response reported a similar access pattern during the past quarter; both datasets overrepresent larger organizations, so prevalence remains uncertain.”

The better formulation explains access, independence, timing, and limitation without disclosing details the audience does not need.

Maintain a protected internal reference that allows authorized reviewers to trace the statement to its underlying material. Sanitization should reduce disclosure risk without inventing certainty or changing meaning.

Worked example: reconstructing an observation

An analyst receives a spreadsheet stating that updates-example.invalid is malicious. Before using it, the analyst reconstructs the record:

  • Origin: A trusted sharing partner supplied the row through an approved community.
  • Underlying observation: The domain appeared as a download destination in two investigated intrusions.
  • Event window: The observations occurred between 3 and 7 May, in UTC.
  • Collection time: Northbridge received the report on 9 May.
  • Context: Both affected organizations saw a similar process sequence before the connection.
  • Transformation: The partner removed victim identifiers and normalized domains to lowercase.
  • Lineage: A public article repeats the same partner reporting and is not independent corroboration.
  • Limitation: Northbridge does not know whether the domain also served benign content.
  • Handling: The partner permits defensive use inside Northbridge but requires approval before public attribution.
  • Review trigger: Recheck resolution, ownership, and internal observations before blocking; expire the record unless renewed by evidence.

The result is not simply “malicious domain.” It is a time-bounded observation with behavioral context, sharing limits, and a defined validation step. A detection engineer can now decide whether to monitor, alert, or block with an understanding of possible false positives.

Protect integrity across handoffs

When evidence moves from collector to processor to analyst to consumer, use a compact handoff record:

  1. Requirement and information need
  2. Source reference and acquisition authority
  3. Event, observation, and collection times
  4. Scope and collection method
  5. Original location and integrity information
  6. Transformations and tool versions
  7. Handling and retention controls
  8. Known gaps, contradictions, and caveats
  9. Current owner and next action

Confirm that the recipient can interpret the format and controls. A handoff is incomplete if the file arrives but its meaning does not.

Analyst check: can another person audit the claim?

Before relying on collected material, ask:

  • Can an authorized reviewer find the underlying source?
  • Can they distinguish the original observation from later enrichment and judgment?
  • Are the relevant timestamps and scope unambiguous?
  • Are transformations reproducible or at least documented?
  • Is purported corroboration genuinely independent?
  • Are privacy, legal, contractual, and handling constraints attached?
  • Is the material still timely for the proposed use?
  • Are limitations visible where the judgment is made?

If the answer is no, lower the evidentiary weight, repair the record, seek corroboration, or exclude the material.

Key takeaways
  • Provenance makes evidence traceable, reviewable, and usable within appropriate limits.
  • Preserve origins, timestamps, scope, transformations, integrity information, lineage, handling, and limitations.
  • Event time, collection time, publication time, and enrichment time answer different questions.
  • Repetition is not independent corroboration when reports share one underlying source.
  • Handling controls should accompany information from collection through dissemination.
  • Preserve enough context for audit while protecting sensitive identities and methods.

Collection quality is not measured only by how much material enters the system. It is measured by whether the resulting evidence can support a defensible judgment without losing context, authority, integrity, or trust.