Skip to main content

Scoring Models

This project uses separate scores for source quality, claim quality, analyst confidence, threat priority, and detection readiness. These scores MUST NOT be collapsed into one generic risk number.

Source Reliability

Adapted from the NATO Admiralty Code (STANAG 2511). See also Sherman Kent's words-of-estimative-probability framework for the parallel information-credibility scale.

ScoreMeaningUse
AHighly reliable source with strong methodology or direct evidence.May anchor actor profiles, scenarios, and detection logic.
BGenerally reliable source or strong secondary synthesis.Useful for context and hypothesis development.
CMixed reliability, limited detail, or weak methodology.Watchlist only unless corroborated.
DUnknown reliability or unverified public claim.Lead only.
EKnown issues or weak sourcing.Do not use for decisions without independent evidence.
FUnreliable or deceptive.Exclude from decisions.

Information Credibility

ScoreMeaning
1Confirmed by local telemetry or multiple independent reliable sources.
2Probably true; strong single source or partial corroboration.
3Possibly true; plausible but limited support.
4Doubtful; weak, stale, or conflicting support.
5Improbable based on stronger contrary evidence.
6Cannot be judged with available evidence.

Analyst Confidence

LevelMinimum Criteria
HighDirect or well-corroborated evidence, current reporting, short inference chain, no material unresolved contradiction.
ModerateCredible but incomplete evidence, partial corroboration, or plausible alternatives.
LowThin, indirect, stale, weakly corroborated, or assumption-heavy evidence.

Threat Scenario Priority Score

Use a 1-5 scale for each dimension:

Threat Scenario Priority Score = Likelihood + Impact + Exposure + Detection Gap + Time Sensitivity
TotalPriorityRequired Treatment
21-25CriticalMUST have a hunt, detection, control, or telemetry remediation plan.
16-20HighSHOULD enter the detection backlog or active hunt plan.
11-15MediumTrack and schedule based on capacity.
5-10LowKeep as context unless conditions change.

Detection Readiness Level

DRLMeaning
DRL-0Idea only; no observable defined.
DRL-1Observable behavior defined.
DRL-2Required telemetry identified.
DRL-3Telemetry exists and required fields are confirmed.
DRL-4Hunt query or prototype detection drafted.
DRL-5Positive and negative test cases defined.
DRL-6Tested in lab or replay dataset.
DRL-7Pilot deployed with SOC review.
DRL-8Tuned with false-positive review and documented triage.
DRL-9Production deployed, monitored, and owner assigned.

Only DRL-9 detections MAY be described as production coverage.