Assess And Explain Threat
Overview
Turn mixed evidence into a proportionate conclusion and advice the affected person can follow. Do not collapse signatures, reputation, scanner output, or unusual behavior into a binary safe/malicious verdict.
Read references/confidence-and-advice.md for conclusion vocabulary and the explanation shape.
Workflow
Restate the decision.
- Identify what the user must decide now and what can wait for more evidence.
Grade evidence by directness.
- Separate direct observations, reproducible behaviors, vendor or threat-intelligence claims, weak indicators, absence of findings, and speculation.
- Record contradicting evidence and coverage gaps.
Assess behavior and impact.
- State what access, execution, persistence, collection, credential use, network behavior, or data exposure is observed or technically plausible.
- Distinguish capability from intent and artifact presence from successful compromise.
Choose a calibrated classification.
- Use one classification from the reference and state confidence separately.
- Name the strongest supporting evidence and what would change the conclusion.
Give proportionate advice.
- Put urgent harm-reduction actions first.
- Separate containment, evidence preservation, recovery, credential actions, notification, and long-term hardening.
- Avoid destructive cleanup when evidence is weak and reversible isolation is available.
Give a plain-language explanation.
- Answer whether the concern is dangerous, what it appears to do, what is known versus inferred, what to do now, and when to escalate.
- Define specialist terms at first use and avoid fear-amplifying language.
Output
Return the conclusion, confidence, decisive evidence, contradictions/gaps, immediate actions, follow-up analysis, and a short non-specialist explanation.
1---2name: assess-and-explain-threat3description: Assess whether suspicious evidence indicates a real threat and explain it plainly. Use for confidence, protective actions, uncertainty, impact, and advice after artifact, endpoint, identity, or incident evidence.4---56# Assess And Explain Threat78## Overview910Turn mixed evidence into a proportionate conclusion and advice the affected person can follow. Do not collapse signatures, reputation, scanner output, or unusual behavior into a binary safe/malicious verdict.1112Read [references/confidence-and-advice.md](references/confidence-and-advice.md) for conclusion vocabulary and the explanation shape.1314## Workflow15161. Restate the decision.17 - Identify what the user must decide now and what can wait for more evidence.18192. Grade evidence by directness.20 - Separate direct observations, reproducible behaviors, vendor or threat-intelligence claims, weak indicators, absence of findings, and speculation.21 - Record contradicting evidence and coverage gaps.22233. Assess behavior and impact.24 - State what access, execution, persistence, collection, credential use, network behavior, or data exposure is observed or technically plausible.25 - Distinguish capability from intent and artifact presence from successful compromise.26274. Choose a calibrated classification.28 - Use one classification from the reference and state confidence separately.29 - Name the strongest supporting evidence and what would change the conclusion.30315. Give proportionate advice.32 - Put urgent harm-reduction actions first.33 - Separate containment, evidence preservation, recovery, credential actions, notification, and long-term hardening.34 - Avoid destructive cleanup when evidence is weak and reversible isolation is available.35366. Give a plain-language explanation.37 - Answer whether the concern is dangerous, what it appears to do, what is known versus inferred, what to do now, and when to escalate.38 - Define specialist terms at first use and avoid fear-amplifying language.3940## Output4142Return the conclusion, confidence, decisive evidence, contradictions/gaps, immediate actions, follow-up analysis, and a short non-specialist explanation.