Writing the Operational Intelligence Assessment
Write a time-sensitive assessment that communicates current scope, leading explanations, likely next actions, confidence, alternatives, and decision implications.
In this lesson, you will learn to:
- Write a decision-centered operational assessment with bounded key judgments, likelihood and confidence, current scope, alternatives, warning indicators, implications, information cutoff, and update triggers.
Writing the Operational Intelligence Assessment
Structure operational products around bounded key judgments, diagnostic evidence, current gaps, warning indicators, defensive options, information cutoffs, and explicit update triggers.
Structure a decision-centered operational assessment
An operational intelligence assessment communicates what is happening, how far it may extend, what may happen next, and which decision is required while the answer can still matter. It must be fast enough for operations and rigorous enough for consumers to distinguish evidence, judgment, uncertainty, and options.
A useful assessment opens with:
- the consumer and open decision;
- the principal judgment;
- likelihood and confidence;
- confirmed, suspected, and unknown scope;
- immediate implication;
- the information cutoff;
- the next update trigger.
Example:
Decision: Whether to broaden containment beyond Hosts A and B before restoring finance access at 14:00 UTC.
Bottom line: We assess Hosts A and B were likely affected by one coordinated malicious operation, with moderate confidence. Matching delivery and execution evidence supports a common cause. Host C is unlikely to be related after approved-package validation. The relationship between credential-store access and a later payment-account sign-in remains unresolved. Current evidence supports targeted identity containment and a bounded finance-wide search rather than finance-segment isolation.
Information cutoff: 13:20 UTC.
Immediate update triggers: A full-sequence match on another host, direct session linkage, critical-service access, or evidence that the observed script was authorized.
The reader can act without first reading a chronology.
Use a fixed operational frame
A consistent structure improves speed and review:
- Identifier, version, publication time, and information cutoff
- Consumer, requirement, and decision deadline
- Bottom line
- Key judgments
- Current scope
- Evidence and strongest alternatives
- Likely next actions and warning indicators
- Implications, options, and trade-offs
- Priority gaps and collection status
- Handling, distribution, and next update
Consistency does not mean every product has the same length. A ten-minute incident update may fit on one page. A campaign assessment may include technical annexes.
Write bounded key judgments
Each key judgment should include:
- subject;
- behavior or outcome;
- scope;
- time horizon;
- likelihood;
- confidence and rationale;
- implication;
- change condition.
Weak:
The campaign will probably continue.
Stronger:
During the next two weeks, Lantern-related operators are likely to continue seeking payment-connected identities through archive or cloud-link delivery, with moderate confidence. Recurrence across two independent incidents and stable target dependencies support the judgment; shared tooling and limited partner coverage constrain confidence. Appearance of the validated delivery-to-identity sequence would strengthen the assessment, while adequate cross-partner visibility without recurrence would lower it.
The stronger judgment can be reviewed and operationalized.
Separate facts, assumptions, judgments, and options
| Type | Project Lantern example |
|---|---|
| Observed fact | Endpoint records show Script S-1 launched on Hosts A and B. |
| Reported claim | A partner reports a related sequence in Incident P-2. |
| Assumption | Endpoint clocks are comparable within the documented correction range. |
| Judgment | Hosts A and B likely share one malicious cause. |
| Implication | Investigation limited to one host could miss related identity activity. |
| Option | Run a bounded finance-wide behavior search before broader isolation. |
| Recommendation | Use the bounded search because it is reversible and can change containment scope before 14:00. |
Do not present a recommended action as though it were evidence that the judgment is true.
Attach confidence to propositions
A single confidence level for the entire product hides important differences:
| Proposition | Likelihood and confidence |
|---|---|
| Hosts A and B share a related script lineage | Very likely, high confidence |
| Their activity was malicious | Likely, moderate confidence |
| Credential access succeeded | Roughly even chance, low confidence |
| The payment sign-in used credentials from Host A | Possible, low confidence |
| The activity belongs to the Lantern Campaign | Likely, moderate confidence |
| A named operator controlled the activity | Not assessed; insufficient identity evidence |
Keep these distinctions visible in key judgments and technical annexes.
State current scope precisely
Use categories:
- confirmed affected;
- suspected affected;
- exposed;
- related but not affected within defined visibility;
- cleared within defined behavior, period, and coverage;
- no match with limited visibility;
- unknown;
- out of scope.
Example:
Hosts A and B are confirmed affected by the assessed script activity. Payment account P-7 is suspected because a new-device sign-in followed relevant host behavior, but direct linkage is absent. Host D is related but shows no execution under complete endpoint coverage for 08:30–13:00. Twelve finance endpoints lack command-line coverage and remain unknown for the full sequence.
Avoid “only two hosts are affected” when coverage is incomplete.
Order evidence by diagnostic value
Lead with observations that distinguish the judgment from alternatives:
- Distinct raw host records show matching unusual execution after related messages.
- One host created a scheduled task referencing the extracted script.
- A validated package explains Host C’s partial match as authorized activity.
- Identity activity is temporally compatible but not directly linked.
- A domain was recently registered.
Domain age may be relevant, but it is less diagnostic than host and package evidence.
Represent alternatives fairly
A strong alternative statement explains why it remains plausible and what weighs against it:
Authorized administration could explain part of the process sequence. We assess it is unlikely for Hosts A and B because their scripts were extracted from related messages, no approved package matches the files, and task creation references the extracted paths. The alternative explained Host C and caused its removal from suspected scope.
An alternative that successfully explains one subset may support a mixed reconstruction.
Include information cutoffs and evidence freshness
State:
- event period assessed;
- information cutoff;
- publication time;
- volatile findings and last validation;
- evidence received too late for the current version;
- next update time or trigger.
A domain relationship validated at 10:00 may be stale by 16:00. An identity record collected after the cutoff belongs in the next version.
Use layered detail
Decision summary: Judgment, confidence, scope, implication, options, and trigger.
Operational body: Evidence, alternatives, timeline, warning indicators, collection status, and action dependencies.
Technical annex: Queries, event references, process relationships, infrastructure records, source evaluations, and coverage.
Protected annex: Sensitive provenance, identities, methods, partner restrictions, and legal or privacy controls.
All layers should map to the same version and judgment.
Write finding-based headings
Replace topic headings:
- Timeline
- Infrastructure
- Identity Activity
- Recommendations
with bounded findings:
- Matching execution after related messages supports a common cause
- Shared hosting limits address-level enforcement
- New-device sign-in may expand identity scope, but direct linkage is absent
- A bounded search offers the most reversible scope test before 14:00
Headings should preserve uncertainty and scope.
Distinguish preliminary from corrected products
Label status:
- initial notification;
- preliminary assessment;
- decision update;
- revised assessment;
- correction;
- closure or transition assessment.
A preliminary product still requires evidence and uncertainty discipline. A correction must identify the affected claim and operational consequence.
Operational assessment blueprint
Before drafting, complete:
| Field | Prompt |
|---|---|
| Decision | What must the consumer choose, and by when? |
| Information cutoff | Which validated evidence is included? |
| Bottom line | What is the principal bounded judgment? |
| Key judgments | Which distinct propositions matter most? |
| Scope | What is confirmed, suspected, exposed, cleared, limited, or unknown? |
| Evidence | Which observations are most diagnostic? |
| Alternatives | Which explanations remain, and why are they less favored? |
| Confidence | What strengthens and limits each judgment? |
| Warning | Which observations would indicate continuation, expansion, or change? |
| Options | Which actions are feasible, proportionate, and reversible? |
| Gaps | Which unknowns could change the decision? |
| Update | Which event or time causes a new version? |
| Handling | Who may receive which layer? |
Project Lantern key judgments
KJ-1 — Common cause
Hosts A and B were likely affected by one coordinated malicious operation, with moderate confidence. Related delivery and matching execution with distinct raw events support the judgment. Script analysis remains incomplete.
KJ-2 — Identity scope
Payment account P-7 may be related, with low confidence. Timing and account relevance support the hypothesis, but no token, device, or credential linkage establishes causation.
KJ-3 — Campaign relationship
The operation likely overlaps with Lantern Campaign Incident P-2, with moderate confidence. Tool lineage and an uncommon service path support a related tooling ecosystem. Common operator control is not established.
KJ-4 — Near-term behavior
Related activity is likely to reuse the delivery-to-script-to-identity pathway during the next two weeks, with moderate confidence. Operators may rotate artifacts or use signed utilities, so behavior-centered monitoring is more durable than domain-only blocking.
Assessment quality checklist
- Consumer, decision, deadline, product status, version, and information cutoff are visible.
- The bottom line communicates judgment, likelihood, confidence, scope, implication, and current option.
- Key judgments are distinct, bounded propositions.
- Facts, reports, assumptions, judgments, implications, options, and recommendations are distinguishable.
- Scope categories identify behavior, time, and visibility.
- Diagnostic evidence appears before weak contextual features.
- Alternatives and mixed explanations are treated fairly.
- Volatile evidence includes validation and expiration.
- Layered detail preserves one underlying assessment.
- Headings state findings without overstating certainty.
- Update and correction triggers are explicit.
Key takeaways
- Operational assessments lead with the open decision and a bounded bottom line.
- Use a fixed structure to accelerate drafting, review, delivery, and updating.
- Assign likelihood and confidence to distinct propositions rather than an entire narrative.
- Communicate confirmed, suspected, exposed, cleared, limited-visibility, and unknown scope precisely.
- Order evidence by diagnostic value and preserve credible alternatives.
- State information cutoffs, product status, volatile evidence, and update triggers.
- Layer the product so decision owners and technical reviewers share one assessment at suitable depth.
Analyst habit: If the consumer reads only the identifier, cutoff, bottom line, and key judgments, they should understand the decision, current scope, uncertainty, and next trigger accurately.
Write scope, warning, and action judgments under uncertainty
Operational assessments must help consumers decide under uncertainty without converting possibilities into facts. The analyst should write separate judgments about scope, current behavior, likely next actions, campaign continuity, warning indicators, and defensive options because each rests on different evidence.
Write a scope judgment
A scope judgment should state:
- affected population or entities;
- confirmed, suspected, exposed, cleared, limited, and unknown categories;
- assessed behaviors and time window;
- coverage basis;
- likelihood and confidence;
- expansion and narrowing conditions.
Example:
We assess malicious script activity is currently limited to Hosts A and B, with moderate confidence. Complete endpoint coverage found no matching execution on 92 of 104 in-scope finance endpoints. Twelve endpoints lack required command-line data and remain unknown. Host C’s partial match is explained by approved maintenance. A full-sequence match, related identity use, or evidence from an unobserved endpoint would expand scope; completion of alternate collection without matches would raise confidence in the current boundary.
“Limited to Hosts A and B” is explicitly constrained by the 12 unknown endpoints.
Write a likely-next-action judgment
Forecast behavior rather than intention when evidence is limited.
Weak:
The attacker will steal more money.
Stronger:
During the next 24 hours, the operator is likely to preserve or reuse payment-related identity access if the new-device session is connected to Project Lantern, with low confidence. The observed credential-store access and payment-account relevance support the judgment, but successful extraction and session linkage are unconfirmed. New token use, application consent, session persistence, or access to payment workflows would strengthen it.
The statement includes a condition, horizon, evidence, confidence, and warning indicators.
Distinguish capability, intent, and opportunity
| Concept | Question | Evidence example |
|---|---|---|
| Capability | Can the operator perform the action? | Tool functionality, observed execution, prior behavior |
| Intent | Does the operator seek the outcome? | Target selection, commands, communications, repeated objective behavior |
| Opportunity | Does the environment permit the action? | Account privileges, service exposure, weak controls, reachable systems |
A tool capable of credential access does not prove intent to use credentials. A likely objective does not prove the operator currently has the opportunity. Write each proposition separately.
Use conditional forecasts
Operational forecasts often depend on conditions:
If the payment-support session is related and remains active, the operator is likely to attempt discovery or access within connected services before the next account review.
Then identify:
- the condition;
- evidence that it holds;
- likelihood if it holds;
- indicators that the behavior is beginning;
- action window;
- what happens if the condition is false.
Conditional language should clarify logic, not avoid judgment.
Build warning judgments
A warning judgment states that a specified observation would change risk or decision posture.
| Warning condition | Interpretation | Operational response |
|---|---|---|
| Full behavior sequence on another host | Scope likely wider than confirmed | Preserve and triage host; reassess containment |
| New-device or token event tied to affected identity | Identity use more likely | Revoke relevant sessions; inspect connected services |
| Compatible replacement infrastructure after disruption | Campaign activity may continue | Expand bounded monitoring; validate before blocking |
| Signed utility launches related script behavior | Execution adaptation possible | Run tested analytic; review legitimate administration |
| Supplier administrator targeted through same sequence | Target expansion or subgroup possible | Coordinate with supplier-security owner and review campaign split |
| Validated package explains Hosts A and B | Malicious reconstruction weakens | Narrow containment and issue correction if required |
Each warning condition has both an analytic meaning and an action pathway.
Avoid vague warning language
Weak:
Threat activity may increase.
Stronger:
Receipt of similarly constructed cloud links by payment-connected users, followed within one hour by the validated script or identity sequence, would raise the likelihood of continued Lantern Campaign delivery and trigger an immediate scope update.
The stronger statement is observable and actionable.
Write options with consistent trade-offs
| Option | Evidence basis | Expected benefit | Cost or risk | Reversibility | Trigger to escalate or stop |
|---|---|---|---|---|---|
| Maintain containment of Hosts A and B | Confirmed relevant execution | Limits known host risk | User and evidence-access disruption | High | Restore after evidence preservation and validation |
| Conduct bounded finance search | Behavior is diagnostic enough for query | Tests wider scope | Analyst cost and partial benign matches | High | Escalate on full match; close after adequate coverage |
| Revoke selected payment sessions | Identity relationship remains plausible | Reduces potential account reuse | User disruption and loss of session evidence | Moderate | Apply after preservation; narrow if linkage disproved |
| Isolate finance segment | Wider active access not currently established | Broad pathway reduction | Severe business impact | Moderate | Reserve for lateral movement or critical-service evidence |
| Monitor replacement infrastructure | Campaign continuity plausible | Provides warning with low disruption | Noise and maintenance | High | Expire after review period without corroboration |
State which option the evidence best supports and which assumptions influence the recommendation.
Write recommendations proportionately
Recommendation:
Maintain containment of Hosts A and B, complete a bounded finance-wide behavioral search, and preserve then revoke high-risk sessions associated with P-7. Do not isolate the entire finance segment unless additional full-sequence activity, direct session linkage, lateral movement, or critical-service access appears.
Rationale:
These steps address confirmed and suspected scope, remain more reversible than segment isolation, and generate evidence capable of changing the decision.
The recommendation is not disguised as the only rational choice. The incident commander owns the action.
Communicate confidence limits
Confidence rationales should name the limiting dimension:
- coverage incomplete on 12 endpoints;
- payload analysis incomplete;
- partner reporting independent but sanitized;
- infrastructure shared;
- identity source lacks token lineage;
- tool available to several customers;
- strong evidence disagreement within the team;
- information cutoff precedes a late-arriving record.
Avoid “low confidence due to limited data” when the exact limitation can be stated.
Preserve material dissent
If analysts disagree in a decision-relevant way:
The lead assessment is that the payment sign-in is possibly related, with low confidence. The identity analyst assesses it is unlikely to be related because device registration predates Project Lantern. Resolving whether the device was reassigned and whether the session used a new token would distinguish the views.
Do not average disagreement into an unsupported middle. Explain the evidence and change condition.
Write volatile evidence with expiration
For infrastructure, indicators, and current sessions, include:
- first and last observed;
- last validated;
- intended use;
- confidence;
- benign or shared-service risk;
- expiration;
- revalidation trigger.
Example:
sync-example.invalidwas likely operationally related during 3–12 August, with moderate confidence. Use hostname and process context for hunting through 15 August. Current address-level blocking is not recommended because hosting is shared. Revalidate on resolution, certificate, ownership, or provider-status change.
Separate action urgency from analytic certainty
An urgent decision may justify a preliminary assessment. Write:
- what is confirmed;
- what is likely;
- what remains possible or unknown;
- why action cannot wait;
- which action is reversible;
- what evidence will trigger review.
Do not raise confidence because consequences are severe. Impact affects the decision, not the probability judgment.
Use consequences without sensationalism
Describe plausible consequences with conditions:
If P-7’s session is related and retains payment-support access, the operator could view or alter transaction-support data. Current evidence does not show such access or financial loss.
Avoid:
Attackers may steal millions.
unless a defensible scenario and evidence support it.
Include a change table
| Judgment | Current state | Would strengthen | Would weaken or overturn |
|---|---|---|---|
| Hosts A and B share malicious cause | Likely, moderate confidence | Related payload behavior or additional full-sequence match | Approved package or processing defect explaining complete sequence |
| P-7 sign-in is related | Possible, low confidence | Token, device, credential, or session linkage | Validated legitimate device history or unrelated access path |
| Lantern Campaign likely continues | Likely, moderate confidence | New delivery-to-identity sequence | Adequate visibility without recurrence and provider evidence of unrelated customers |
| Segment-wide containment needed | Not currently supported | Lateral movement, critical-service access, or wider full-sequence matches | Adequate bounded search with no expansion |
A change table turns uncertainty into collection and review priorities.
Draft a one-page operational assessment
Project Lantern Operational Assessment v1.2
Published: 13:35 UTC
Information cutoff: 13:20 UTC
Status: Preliminary decision update
Handling: Restricted incident distribution
Decision: Whether to broaden containment beyond Hosts A and B by 14:00.
Bottom line:
Hosts A and B were likely affected by one coordinated malicious operation, with moderate confidence. Host C is unlikely to be related after validation of approved maintenance. Payment account P-7 may be related, but direct linkage is absent. Current evidence supports targeted host and identity action plus a bounded finance search, not finance-segment isolation.
Scope:
- Confirmed affected: Hosts A and B
- Suspected: P-7 identity activity
- Related, not affected within defined visibility: Host D
- Cleared from malicious subset: Host C
- Limited visibility: 12 of 104 in-scope endpoints
Warnings:
- Full-sequence behavior on another host
- Related token or device activity
- Critical-service access
- Compatible replacement infrastructure with behavior context
Options:
- Maintain current containment and complete bounded search — recommended.
- Add targeted session revocation after evidence preservation — recommended if P-7 risk remains.
- Isolate finance segment — reserve for expansion triggers.
Next update: 16:00 or immediately on a warning trigger.
Judgment quality checklist
- Scope claims include population, behavior, period, and coverage.
- Forecasts distinguish capability, intent, and opportunity.
- Conditional judgments state the condition and observable indicators.
- Warnings connect observations to analytic and operational responses.
- Options use consistent evidence, benefit, risk, time, and reversibility criteria.
- Recommendations remain labeled and proportionate.
- Confidence limits name exact evidence or reasoning weaknesses.
- Material dissent and resolution evidence are preserved.
- Volatile findings have validity, expiration, and revalidation.
- Consequences are bounded and do not become unsupported claims of impact.
- Change conditions guide collection and updates.
Key takeaways
- Write separate judgments about scope, behavior, future action, campaign continuity, and intervention.
- Tie scope to explicit coverage and unknown populations.
- Separate capability, intent, and opportunity.
- Use conditional forecasts and observable warning triggers.
- Compare options consistently and preserve the decision owner’s authority.
- Urgency may require preliminary delivery but does not justify overstated confidence.
- Bound consequences and distinguish plausible exposure from established impact.
- State evidence that would strengthen, weaken, or overturn every material judgment.
Analyst habit: For every operational judgment, write the action it informs and the exact observation that would cause you to update it. If neither is clear, the judgment may not belong in the product.