Actions on Objectives (KC Step 7) -
✔✔ANSW✔✔..👌Everything that happens after the
adversary has operational control of a system.
Activity Group - ✔✔ANSW✔✔..👌Set of events and
activity associated by similarities in their features and
weighted by confidence scoring; Clustering of intrusions
with weighting on the adversary, infrastructure, tradecraft,
and/or victim that meets some analytical requirement.
Adversary/Threat - ✔✔ANSW✔✔..👌Representation of the
human behind the keyboard; The entity involved in the
execution of an intrusion.
Analysis - ✔✔ANSW✔✔..👌A detailed examination of the
elements or structure of something.; Breaking something
down into its constituent parts to understand its operation.
Analysis and Production Stage - ✔✔ANSW✔✔..👌The
intelligence life cycle state in which using processes such
as SATs to evaluate processed information in order to fill
information gaps and meet requirements.
,Analysis of Competing Hypotheses - ✔✔ANSW✔✔..👌A
structured method to identify all potential hypotheses,
collect all evidence, compare the evidence with the
hypothesis, then rank hypothesis that do not make sense
and to identify any pitfalls in analysis and evidence that
exists.
Analytical Judgement - ✔✔ANSW✔✔..👌Going beyond
the facts to assess what the information signifies and how
it impacts whatever organization they are supporting. It is
made to meet a specific intelligence requirement and is
based off of available data and information while
acknowledging the information gaps and remaining
uncertainties.
Anchoring/Focusing - ✔✔ANSW✔✔..👌Beginning with an
assumption or assessment and then adjusting one's
assessment as new information becomes available, rather
than taking the information as a whole for an assessment.
Anecdotal Fallacy - ✔✔ANSW✔✔..👌Personal experience
is used over compelling evidence
Appeal to Probability - ✔✔ANSW✔✔..👌Making a
determination based on what's most likely the case
Appeal to the Stone - ✔✔ANSW✔✔..👌Identifying a claim
as absurd without any proof to dismiss it
, Argument from Repitition - ✔✔ANSW✔✔..👌Arguing so
much that eventually people access the conclusion to end
it.
Argument from Silence - ✔✔ANSW✔✔..👌Accepting a
conclusion due to lack of evidence against it
Burden of Proof - ✔✔ANSW✔✔..👌Requiring someone to
disprove someone else's claim instead of requiring proof
Campaign/Operation - ✔✔ANSW✔✔..👌The adversary's
mission focus.
Carbanak - ✔✔ANSW✔✔..👌A case study that showed
APT is a style, not a definitive category. Malware is a tool,
but the threat is human. Stole $1billion from banks.
Code Signing Certificate - ✔✔ANSW✔✔..👌Used to
ensure that code has not been changed or signed since
the code was signed.
Cognitive Biases - ✔✔ANSW✔✔..👌Constraints on how
we as analysts think that influence incorrect decisions and
assessments
Collection Management Framework -
✔✔ANSW✔✔..👌The plan for how you collect data, where
you collect it from, and what type of data you collect.