Intelligence-driven red teaming
Threat intelligence changes a red-team engagement only when it changes what is tested: the path, prerequisite, behavior, telemetry, or expected defensive decision. A report that never reaches a controlled test remains context, not validation.
Observe
Section titled “Observe”Name the campaign, infrastructure, malware behavior, cloud action, or tradecraft that produced the hypothesis. Preserve provenance and time bounds.
State prerequisites, confidence, competing explanations, and the defensive consequence that would follow if the model holds.
Emulate
Section titled “Emulate”Reproduce the smallest authorized behavior that can test the model. The goal is not theatrical realism; it is controlled evidence.
Validate
Section titled “Validate”Compare the expected and observed control response. Include negative controls where the harness itself could explain the result.
Publish
Section titled “Publish”Separate observation, reproduction, inference, and unknowns. Attach scope, limitations, artifacts, disclosure state, and a stable citation.